Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In August 2019, Microsoft announced that Exchange Online’s PowerShell Get-MailboxStatistics cmdlet would return new properties covering email and calendar activity. The announcement summary does not identify those properties or define them, so their names and meanings cannot be stated reliably here. It also cautioned that LastLogon was not a definitive measure of a user’s most recent mailbox sign-in.

What the Exchange Online update established

The Microsoft Community Hub result for “Exchange Online Exposes New Mailbox Activity Data” is dated August 15, 2019. It describes an update to Get-MailboxStatistics that added mailbox activity properties related to email and calendar activity. The available summary does not provide the property names, definitions, or the exact conditions under which values are recorded. See the Microsoft Community Hub announcement.

That limitation matters for administrators: the announcement supports the existence and broad subject of the properties, but not a field-by-field explanation or a claim about the current cmdlet schema. Do not infer specific fields from the phrase “mailbox activity data.”

Why LastLogon is not a definitive sign-in timestamp

The announcement specifically warned that the LastLogon property problem remained and that additional work was needed to obtain accurate last-login information. The accessible summary does not describe that procedure. Therefore, LastLogon should not be treated on its own as proof of when a user last signed in, and the 2019 summary does not support a replacement command or calculation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Mailbox statistics, audit events, and active-user reports answer different questions

Data source What it represents Useful for Important limit
Get-MailboxStatistics activity properties announced in 2019 Mailbox properties broadly associated with email and calendar activity. Mailbox-level activity information, subject to the exact property definitions. The announcement summary does not name or define the properties; it does not establish a direct field-by-field comparison with audit or usage data.
Mailbox audit records Particular operations performed by mailbox owners, delegates, or administrators, when those actions are covered by the applicable configuration. Investigating whether a specified operation was recorded and by which sign-in type. Coverage depends on actor role, mailbox type, and action configuration; an absent event is not by itself proof that the activity did not happen.
Microsoft 365 active-user usage reports A user classification based on specified Exchange Online actions, such as marking a message read, sending a message, or specified meeting activity. Usage and adoption reporting under Microsoft’s active-user definition. Microsoft says this active-user metric does not represent calendar information and is not established as equivalent to the 2019 mailbox properties.

Microsoft’s current documentation describes mailbox audit actions such as MailItemsAccessed, Send, MoveToDeletedItems, UpdateInboxRules, and UpdateFolderPermissions. Those are event types, not names for the 2019 Get-MailboxStatistics properties. The actions and defaults vary by role and mailbox type. See Microsoft’s mailbox auditing documentation.

Microsoft defines an Exchange Online active user for Microsoft 365 usage reports through specified actions including reading or sending messages and certain meeting actions; the documentation says calendar information is not represented in this metric. That reporting definition should not be substituted for mailbox statistics or audit events. See Microsoft’s active users report documentation.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Check audit configuration before interpreting missing events

Microsoft says mailbox auditing is on by default at the organization level. Administrators can check the organization setting in Exchange Online PowerShell with:

Get-OrganizationConfig | Format-List AuditDisabled

For an investigation, confirm that the relevant action is audited for the relevant actor and mailbox type, rather than relying only on the organization-level setting. Mailbox action configuration can be managed with Set-Mailbox; consult Microsoft’s documentation for the supported settings and role-specific action lists.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A further caveat is important: if mailbox audit action lists were customized, Microsoft says those lists are preserved. New actions added to the defaults are not automatically added to mailboxes with customized lists. Consequently, a missing record can reflect configuration coverage rather than the absence of the underlying activity. See Microsoft’s mailbox auditing documentation.

Practical way to choose the right data

  • Need mailbox-level activity properties? Use the relevant Exchange Online statistics view, but verify the property names and definitions against current authoritative cmdlet documentation before relying on a particular field. The 2019 announcement summary does not supply them.
  • Need to investigate a particular operation? Use mailbox audit records and first verify that the operation, actor role, and mailbox type are covered by the mailbox’s configuration.
  • Need an adoption or usage classification? Use Microsoft 365 usage reports and apply Microsoft’s stated active-user definition, rather than treating the result as a calendar-activity record or a sign-in timestamp.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.