For Exchange Online, start in Microsoft Purview Audit: search the affected mailbox and incident window for MailItemsAccessed and other mailbox activity, then compare those events with Microsoft Entra sign-in logs. Check who performed each action, when it happened, whether it succeeded, and the available IP, client, device, location, and application details. A mailbox event can show access without proving a person read a message, and a blank search does not prove that no access occurred.
First confirm which Exchange environment you are investigating
The steps below focus on Exchange Online in Microsoft 365. If the mailbox is hosted on Exchange Server, use the applicable on-premises mailbox audit logging and audit search procedures; cloud Purview and Entra steps do not automatically describe that environment. Microsoft documents Exchange Server mailbox auditing separately in its Exchange Server mailbox audit logging guidance.
Before searching, note the mailbox address, whether it is a user or shared mailbox, the suspected time window, and any known suspicious sign-ins or changes. This helps avoid searching the wrong identity or a period outside the available logs.
Check mailbox activity in Microsoft Purview Audit
- Open the Microsoft Purview portal and go to Audit to search the audit log. Search the relevant date and time range and scope the search to the affected mailbox and relevant mailbox activities. Microsoft provides the current procedure in Search the audit log for mailbox activities in specific mailboxes.
- Search for
MailItemsAccessed, particularly when investigating possible email data exposure. Review other relevant mailbox operations in the incident window as well. - For each result, examine the actor, timestamp, operation, result, and any available logon type, IP address, client or protocol, device, location, and application details. Compare them with the mailbox owner’s normal activity and known delegates or administrators.
- Export or preserve relevant records and document the search scope and findings according to your incident-response process.
MailItemsAccessed is useful for scoping which mail data may have been accessed, including through protocols and clients. It is not proof that a person consciously read a message. Microsoft explains that Exchange Online can audit access to a mail item even when there is no indication the item was read in Use MailItemsAccessed to investigate compromised accounts.
#1 Best Overall
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
Review non-owner access to the mailbox
Use Exchange’s non-owner mailbox access report to identify activity by someone other than the mailbox owner. Microsoft’s report guidance describes information that can include who accessed the mailbox, when, what actions were performed, and whether those actions succeeded. Check whether the actor is an expected delegate or administrator; unexpected access should prompt a review of permissions and the circumstances around the event.
Follow Microsoft’s current instructions to run the non-owner mailbox access report. Its findings depend on available audit data and should be interpreted alongside Purview events and identity records.
Rank #2
- HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
- UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
- OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
- RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
- EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
Correlate mailbox events with Microsoft Entra sign-ins
Mailbox audit logs describe mailbox operations; Entra sign-in logs describe authentication context. Neither source alone answers every question. In Entra sign-in logs, compare the account, application, target resource, timestamp, IP address, location, device, user agent, and success or failure with the mailbox events and the user’s usual patterns. Microsoft explains the available sign-in records in its Microsoft Entra sign-in logs documentation.
| Evidence source | What it helps establish | Key interpretation limit |
|---|---|---|
| Purview and Exchange mailbox audit records | Recorded mailbox operations and, where available, actor and client context. | An access event does not establish that a person read a specific message. |
| Microsoft Entra sign-in logs | Authentication context, including application, resource, device, location, and sign-in result where available. | A sign-in does not prove that a particular mailbox or message was accessed. |
Correlate timestamps and identities rather than treating an unusual sign-in as proof of message access. Microsoft Entra ID Protection can provide additional risk investigation context; see Investigate risk with Microsoft Entra ID Protection.
Rank #3
- 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
- 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
- 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
- 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
- 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
Check for related account and mailbox changes
Access may be accompanied by persistence or follow-on activity. Review the same incident window for suspicious inbox rules or forwarding changes, unexpected sent messages, newly added authentication methods or devices, unfamiliar application consent, and privilege or permission changes. Microsoft’s response guidance for a compromised email account in Microsoft 365 covers related activity to investigate.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Understand why a search may return no results
A missing event is not conclusive evidence that access did not occur. First verify that the audit data is available for the mailbox and date range, that the search covers the correct mailbox and actor, and that your account has the required audit role. Microsoft identifies the Audit Logs or View-Only Audit Logs roles for searching Purview audit data. Follow Microsoft’s current verification steps for organization and mailbox audit configuration rather than relying on a single status property or command; see Microsoft’s mailbox activity search guidance.
Rank #4
- Runs UniFi Network for full-stack network management
- Manages 30+ UniFi Network devices and 300+ clients
- 1 Gbps routing with IDS/IPS
- Multi-WAN load balancing
- 0.96" LCM status display
- Permissions: Confirm that the investigator has an audit role that permits the search.
- Configuration and scope: Verify audit configuration and that the correct mailbox and event types are included.
- Retention: The Purview mailbox activity guidance describes a 180-day default retention period for the relevant audit data when no qualifying Audit Premium license or longer policy applies. The Exchange non-owner report guidance describes a 90-day default for its mailbox audit entries. These are different log surfaces; check your tenant’s licensing and retention policy before relying on historical availability.
- Mailbox geography: Microsoft documents an unsupported cross-geo mailbox auditing scenario for certain multi-geo shared-mailbox access. If an expected event is absent, check the mailbox geography and the applicable mailbox auditing guidance.
Contain the account if the evidence indicates compromise
If the activity appears unauthorized, follow your organization’s incident-response process and preserve relevant audit exports and case notes. Microsoft’s guidance includes blocking or disabling the account when appropriate, resetting credentials, revoking active sessions, reviewing authentication methods and devices, and removing suspicious application consent. Session revocation may not end every application session immediately because token lifetimes and application behavior vary. See Microsoft’s guidance to respond to a compromised email account and revoke user access in an emergency.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →

