Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →To find mailbox activity in Office 365, search Microsoft Purview Audit for the mailbox, relevant activity, and a UTC time range, then export the results. For manual or scripted retrieval, use Exchange Online PowerShell’s Search-UnifiedAuditLog; for recurring retrieval, Microsoft points administrators to the Office 365 Management Activity API. An empty search is not proof that nothing happened: verify audit coverage, permissions and scope, filters, retention, and—in Exchange cmdlet investigations—possible delay.
What mailbox audit reports can show
Mailbox auditing records supported actions performed by mailbox owners, delegates, and administrators. It can help investigate questions such as who deleted an email or what happened in a shared mailbox, but it is not a record of every possible interaction with a mailbox. Check Microsoft’s audit activity reference to identify the operation relevant to the event you are investigating.
Microsoft says mailbox audit logging is on by default in all organizations. Supported mailbox types include user, shared, and Microsoft 365 Group mailboxes; coverage differs for resource and public-folder mailboxes, so do not assume the same defaults apply to every Exchange mailbox type. For shared mailboxes, behavior can depend on whether an action was performed as owner, delegate, or administrator. Microsoft also documents a cross-geo limitation for some actions by users granted access to a shared mailbox in another geo. See Manage mailbox auditing.
Choose a way to retrieve the report
| Method | Best suited to | What to account for |
|---|---|---|
| Microsoft Purview Audit portal | Interactive investigations and exporting search results. | Audit permissions, administrative-unit scope, and correctly chosen filters. See Search the audit log. |
Exchange Online PowerShell: Search-UnifiedAuditLog |
Manual or scripted searches, including broader investigation workflows. | Correct operation names, permissions, time range, and result handling. Microsoft documents a PowerShell script for searching the audit log. |
| Office 365 Management Activity API | Regular or programmatic retrieval of audit logs. | Microsoft suggests this approach for regular retrieval. The cited guidance does not provide a cost or performance comparison with portal and PowerShell searches; consult current API documentation for implementation details. |
How to search mailbox activity in Purview
- Collect the investigation details. Identify the mailbox address and type, suspected action, approximate date and time, and the mailbox’s license. These details affect search filters and whether older records may be available.
- Open Purview Audit. Go to the audit search experience in Microsoft Purview. Confirm that your account has an appropriate audit role before starting; access and scope are discussed below.
- Set the time range in UTC. Convert local times to UTC before searching. Microsoft states, “Audit timestamps are always in UTC.”
- Choose the mailbox filter for its type. For a user mailbox, search the affected user and the relevant activity. For a shared mailbox, put its primary SMTP address or Exchange GUID in Keywords, rather than entering that address under Users.
- Choose activity filters that fit the event. Select the relevant operation or operations, not one assumed to cover every possible cause. For a suspected deletion, Microsoft lists
Move,MoveToDeletedItems,Create,SoftDelete, andHardDeleteamong possible operations. Check the activity reference for the exact operation name. - Run the search and export the results. Review the matching records and export the result set for analysis. The available fields and export behavior can depend on the current portal and tenant; follow the portal’s current instructions rather than assuming a particular layout.
For PowerShell searches, preserve operation names exactly. In particular, names containing periods must retain the period in searches and policy configuration. Microsoft’s activity reference lists operations; its search-script guide explains a PowerShell retrieval approach. For portal-specific search guidance, see Search the audit log for mailbox activities in specific mailboxes.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
- The Microsoft Office 365 Bible: The Most Updated and Complete Guide to Excel, Word, PowerPoint, Outlook, OneNote, OneDrive, Teams, Access, and Publisher from Beginners to Advanced
- ABIS BOOK
Verify auditing and search permissions
Check the effective audit configuration
Although mailbox audit logging is on by default, check the organization and mailbox configuration when investigating a suspected gap. Microsoft warns that the mailbox-level AuditEnabled property alone can be misleading as proof of effective auditing. Use the Exchange Online PowerShell verification approach in Microsoft’s mailbox auditing guidance.
Check role membership and administrative-unit scope
Microsoft’s mailbox-search guidance says to verify that the administrator belongs to the View-Only Audit Logs or Audit Logs role group. Search permissions can also be restricted by administrative-unit scope: an administrator with a limited scope can search and export only within that scope. Microsoft describes role routes and least-privilege considerations in its Defender portal audit-search guidance. Assign only the role and scope needed for the investigation.
Rank #2
How far back can you search?
Retention depends on when the record was generated and on your tenant’s license and retention policies. Microsoft documents these default Audit (Standard) periods:
| Record generation date | Documented default Audit (Standard) retention |
|---|---|
| On or after October 17, 2023 | 180 days |
| Before October 17, 2023 | 90 days |
These are documented defaults, not a guarantee of the lookback available in a particular tenant. Older records may depend on Audit (Premium) licensing or a configured retention policy. Check your actual license and tenant retention settings before concluding that a historical record never existed. See Microsoft’s audit activity and retention guidance and mailbox search guidance.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchRank #3
Why mailbox audit results may be missing
Before treating an empty result as evidence that no activity occurred, check the likely failure points:
- Wrong mailbox filter: For a shared mailbox, search its SMTP address or Exchange GUID in Keywords, not Users.
- Wrong time zone or range: Audit timestamps are UTC; convert the suspected local time and widen the range if the event time is approximate.
- Wrong operation: The chosen filter may not match the action. Confirm the exact activity name and consider related operations where appropriate.
- Coverage or configuration: The action may not be an audited event for the relevant mailbox type or sign-in type. Verify effective mailbox and organization auditing settings.
- Retention: The record may fall outside the tenant’s applicable retention period or policy.
- Permissions or scope: The operator may lack an audit role or may be scoped away from the mailbox.
- Ingestion delay: Microsoft says a corresponding audit entry for an Exchange cmdlet can take up to 30 minutes to appear in search results. See its activity guidance.
Microsoft also provides examples for diagnosing common audit-search problems in Search the audit log to investigate common support issues.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.When to automate retrieval
Use the Purview portal for an interactive investigation and PowerShell when you need a manual or scripted search. If your process requires regular log retrieval, Microsoft identifies the Office 365 Management Activity API as an option. The right method depends on whether the work is an occasional investigation or a recurring retrieval pipeline; the cited Microsoft guidance does not establish a comparative cost or performance winner.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

