What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Search Microsoft Purview Audit for MailItemsAccessed across the suspected incident window, then interpret each result using its access type, actor, mailbox, client, IP address, protocol and session context. A record describes audited access—not proof that a person read a message. The distinction between folder-level Sync events and message-level Bind events determines what you should treat as potentially exposed.

1. Set the investigation scope and access

Before searching, record the affected mailbox or mailboxes, the suspected UTC time window, and the relevant sign-in or incident context. If the mailbox is shared, identify likely delegates and other possible actors as well as the mailbox address. Microsoft’s mailbox audit search guidance explains the available mailbox filters and search fields.

  • Use UTC for the search range and when comparing audit events with sign-in or incident timelines. Convert local incident times before searching.
  • Confirm that the investigator has the Microsoft Purview Audit Logs or View-Only Audit Logs role. Exchange Online PowerShell searches have their own role-assignment requirements; check the current Microsoft audit troubleshooting guidance.
  • Check tenant-level and mailbox-level audit configuration before treating an empty search as meaningful. Microsoft documents cases where mailbox events for non-E5 users may not appear in unified audit searches, and describes manual mailbox auditing as a workaround. Follow your tenant’s change-control procedures before changing audit settings.

Microsoft recommends using audit records for forensic investigation after the breach has been resolved and the bad actor evicted. If the incident is active, follow your incident-response process for containment and evidence preservation rather than delaying those actions to complete a log search.

2. Search for MailItemsAccessed

In Microsoft Purview Audit

  1. Open Microsoft Purview and go to Audit.
  2. Set the search’s start and end times to the incident window in UTC.
  3. For a user mailbox, enter the affected mailbox owner in Users.
  4. Select the MailItemsAccessed operation, run the search, and review the returned audit records and their details.

Purview search results depend on the filter used: the Users filter is an actor-oriented filter, not a universal way to identify every event whose target was a particular mailbox. For shared mailboxes and delegate activity, use the target-search approach in the next section.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

With Exchange Online PowerShell

Microsoft documents this representative command shape for searching audit records:

Search-UnifiedAuditLog -StartDate <start> -EndDate <end> -UserIds <user1,user2> -Operations MailItemsAccessed -ResultSize 1000

Replace the example placeholders with actual dates and identities, and verify supported parameter behavior in your current Exchange Online environment. The -UserIds parameter searches activity associated with the specified user identities; it should not be mistaken for a target-mailbox filter that necessarily returns every delegate action.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

3. Decide what Sync and Bind mean

MailItemsAccessed can record two materially different forms of access. Treat their scopes differently when assessing potential exposure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Access type What the record represents How to assess exposure
Sync A client, such as Outlook desktop for Windows or Mac, may have downloaded messages. The record can identify the folder containing synced items rather than creating one record per message. Assess all mail items in the identified folder as potentially compromised. Microsoft states, “All mail items in the synced folder are assumed to be compromised.” Use the event context to decide whether the sync aligns with suspicious activity.
Bind An individual message access, identified by its InternetMessageId. Multiple Bind operations may be aggregated into one record. Use the message IDs to identify potentially exposed messages and assess their contents and sensitivity. A logged access does not establish that a human read the message.

Microsoft notes that Exchange Online may audit access to a mail item even when there is no indication it was read: “When a cyberattacker gains access to a specific piece of mail, Exchange Online audits the event even though there’s no indication that the mail item was read.” The record supports an access investigation; it does not show what a person saw or prove a human read the item.

For a Sync event, later offline reading after a client has downloaded mail cannot be observed as subsequent mailbox interaction. The audit record may show the folder-level download context, not what happened on the device afterward. See Microsoft’s MailItemsAccessed investigation guidance for the event fields and behavior.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

4. Correlate each event with the incident

Do not classify an event as malicious or benign from a single field. Compare the audit record with known user behavior and the incident timeline using the available context:

  • Time: Does the UTC event time overlap the suspicious sign-in or other attacker activity?
  • Actor and mailbox role: Was the actor the mailbox owner, a delegate, or an administrator? Is that access expected for the actor’s role?
  • Client and protocol: Does ClientInfoString and the protocol context match a known client and expected use, or indicate unfamiliar access?
  • Network: Does ClientIPAddress align with the suspicious activity or with normal access context?
  • Session: Does SessionId connect the event to the suspected activity or distinguish it from routine use?
  • Access scope: Is the event a folder-level Sync or message-level Bind? What folder or message IDs are identified?
  • Related actions: Are there rule, forwarding, send-as or deletion events that help explain what happened?

These are comparison axes, not a universal scoring formula. Microsoft’s event documentation describes MailItemsAccessed fields, while its shared mailbox investigation guidance covers related mailbox activity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

5. Search shared mailboxes and delegate activity correctly

For a shared mailbox, search for the target mailbox using its primary SMTP address or Exchange GUID in the relevant keyword or free-text field. Search for likely actors separately. Searching a user identity finds activity performed by that user; it does not necessarily return every action against a target mailbox. Likewise, using the shared mailbox address as a user filter may not find a delegate’s actions.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

When investigating delegate access, correlate the actor identity with the target mailbox and confirm that the action is audited for the relevant access role and sign-in type. Microsoft documents mailbox search fields and role-related behavior in its mailbox activity search article and additional delegate-search limitations in its shared mailbox investigation guidance.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

6. Look for related mailbox changes

If the suspected activity involves more than opening or downloading messages, search the related operations that fit the hypothesis. The operation list is not a substitute for checking the event details and actor/target context.

  • FolderBind can provide relevant folder-access context.
  • SendAs can help investigate messages sent using the mailbox’s identity.
  • New-InboxRule and Set-InboxRule can reveal rules that route or hide messages.
  • Set-Mailbox can help investigate mailbox configuration changes, including forwarding settings.
  • SoftDelete and HardDelete can help investigate deletion activity.

Use the same incident window and correlate related events by actor, target, time and available session or network context. Microsoft lists these operations in its shared mailbox investigation guidance and audit troubleshooting guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

7. Check why a search returned no records

An empty result is not, by itself, evidence that mailbox access did not occur. Check these causes before drawing that conclusion:

  • Search scope: Confirm the UTC range, mailbox identity and operation. For a shared mailbox, check both target-mailbox and actor-oriented searches.
  • Permissions: Verify the investigator’s Purview audit role and, for PowerShell, the required Exchange Online role assignment.
  • Audit configuration: Check tenant and mailbox settings, including whether the relevant mailbox events are being audited.
  • License-related behavior: Microsoft documents that some non-E5 mailbox audit events may not appear in unified audit searches; consult its troubleshooting steps for the applicable configuration.
  • Retention: Determine whether the event would still be within the tenant’s effective retention period before interpreting absence.

8. Verify the applicable audit retention

Retention depends on the record date, audit capability, licensing and policy. The following figures are Microsoft’s documented defaults or available policy limits, not a guarantee that every tenant retains every record for that duration.

Audit context Documented retention Qualification
Audit Standard 180 days by default for applicable records generated on or after October 17, 2023 Microsoft says older Audit Standard records are retained for 90 days. Check the actual record date and tenant configuration.
Audit Premium Up to one year for specified Exchange, SharePoint, OneDrive and Microsoft Entra audit records under the documented default policy Applies to the specified services and depends on the applicable licensing and policy.
Audit Premium with the required add-on license Up to 10 years Requires the applicable add-on license and an appropriate retention policy; the longer period is not retroactive.

Microsoft’s Audit solutions overview describes these retention conditions. Confirm the affected user’s license and the tenant’s retention policy; a policy change cannot recover records that have already expired.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.