Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To find mailbox activity in Office 365, search Microsoft Purview Audit for the mailbox, relevant activity, and a UTC time range, then export the results. For manual or scripted retrieval, use Exchange Online PowerShell’s Search-UnifiedAuditLog; for recurring retrieval, Microsoft points administrators to the Office 365 Management Activity API. An empty search is not proof that nothing happened: verify audit coverage, permissions and scope, filters, retention, and—in Exchange cmdlet investigations—possible delay.

What mailbox audit reports can show

Mailbox auditing records supported actions performed by mailbox owners, delegates, and administrators. It can help investigate questions such as who deleted an email or what happened in a shared mailbox, but it is not a record of every possible interaction with a mailbox. Check Microsoft’s audit activity reference to identify the operation relevant to the event you are investigating.

Microsoft says mailbox audit logging is on by default in all organizations. Supported mailbox types include user, shared, and Microsoft 365 Group mailboxes; coverage differs for resource and public-folder mailboxes, so do not assume the same defaults apply to every Exchange mailbox type. For shared mailboxes, behavior can depend on whether an action was performed as owner, delegate, or administrator. Microsoft also documents a cross-geo limitation for some actions by users granted access to a shared mailbox in another geo. See Manage mailbox auditing.

Choose a way to retrieve the report

Method Best suited to What to account for
Microsoft Purview Audit portal Interactive investigations and exporting search results. Audit permissions, administrative-unit scope, and correctly chosen filters. See Search the audit log.
Exchange Online PowerShell: Search-UnifiedAuditLog Manual or scripted searches, including broader investigation workflows. Correct operation names, permissions, time range, and result handling. Microsoft documents a PowerShell script for searching the audit log.
Office 365 Management Activity API Regular or programmatic retrieval of audit logs. Microsoft suggests this approach for regular retrieval. The cited guidance does not provide a cost or performance comparison with portal and PowerShell searches; consult current API documentation for implementation details.

How to search mailbox activity in Purview

  1. Collect the investigation details. Identify the mailbox address and type, suspected action, approximate date and time, and the mailbox’s license. These details affect search filters and whether older records may be available.
  2. Open Purview Audit. Go to the audit search experience in Microsoft Purview. Confirm that your account has an appropriate audit role before starting; access and scope are discussed below.
  3. Set the time range in UTC. Convert local times to UTC before searching. Microsoft states, “Audit timestamps are always in UTC.”
  4. Choose the mailbox filter for its type. For a user mailbox, search the affected user and the relevant activity. For a shared mailbox, put its primary SMTP address or Exchange GUID in Keywords, rather than entering that address under Users.
  5. Choose activity filters that fit the event. Select the relevant operation or operations, not one assumed to cover every possible cause. For a suspected deletion, Microsoft lists Move, MoveToDeletedItems, Create, SoftDelete, and HardDelete among possible operations. Check the activity reference for the exact operation name.
  6. Run the search and export the results. Review the matching records and export the result set for analysis. The available fields and export behavior can depend on the current portal and tenant; follow the portal’s current instructions rather than assuming a particular layout.

For PowerShell searches, preserve operation names exactly. In particular, names containing periods must retain the period in searches and policy configuration. Microsoft’s activity reference lists operations; its search-script guide explains a PowerShell retrieval approach. For portal-specific search guidance, see Search the audit log for mailbox activities in specific mailboxes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
The Microsoft Office 365 Bible: The Most Updated and Complete Guide to Excel, Word, PowerPoint, Outlook, OneNote, OneDrive, Teams, Access, and Publisher from Beginners to Advanced
  • The Microsoft Office 365 Bible: The Most Updated and Complete Guide to Excel, Word, PowerPoint, Outlook, OneNote, OneDrive, Teams, Access, and Publisher from Beginners to Advanced
  • ABIS BOOK

Verify auditing and search permissions

Check the effective audit configuration

Although mailbox audit logging is on by default, check the organization and mailbox configuration when investigating a suspected gap. Microsoft warns that the mailbox-level AuditEnabled property alone can be misleading as proof of effective auditing. Use the Exchange Online PowerShell verification approach in Microsoft’s mailbox auditing guidance.

Check role membership and administrative-unit scope

Microsoft’s mailbox-search guidance says to verify that the administrator belongs to the View-Only Audit Logs or Audit Logs role group. Search permissions can also be restricted by administrative-unit scope: an administrator with a limited scope can search and export only within that scope. Microsoft describes role routes and least-privilege considerations in its Defender portal audit-search guidance. Assign only the role and scope needed for the investigation.

How far back can you search?

Retention depends on when the record was generated and on your tenant’s license and retention policies. Microsoft documents these default Audit (Standard) periods:

Record generation date Documented default Audit (Standard) retention
On or after October 17, 2023 180 days
Before October 17, 2023 90 days

These are documented defaults, not a guarantee of the lookback available in a particular tenant. Older records may depend on Audit (Premium) licensing or a configured retention policy. Check your actual license and tenant retention settings before concluding that a historical record never existed. See Microsoft’s audit activity and retention guidance and mailbox search guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why mailbox audit results may be missing

Before treating an empty result as evidence that no activity occurred, check the likely failure points:

  • Wrong mailbox filter: For a shared mailbox, search its SMTP address or Exchange GUID in Keywords, not Users.
  • Wrong time zone or range: Audit timestamps are UTC; convert the suspected local time and widen the range if the event time is approximate.
  • Wrong operation: The chosen filter may not match the action. Confirm the exact activity name and consider related operations where appropriate.
  • Coverage or configuration: The action may not be an audited event for the relevant mailbox type or sign-in type. Verify effective mailbox and organization auditing settings.
  • Retention: The record may fall outside the tenant’s applicable retention period or policy.
  • Permissions or scope: The operator may lack an audit role or may be scoped away from the mailbox.
  • Ingestion delay: Microsoft says a corresponding audit entry for an Exchange cmdlet can take up to 30 minutes to appear in search results. See its activity guidance.

Microsoft also provides examples for diagnosing common audit-search problems in Search the audit log to investigate common support issues.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When to automate retrieval

Use the Purview portal for an interactive investigation and PowerShell when you need a manual or scripted search. If your process requires regular log retrieval, Microsoft identifies the Office 365 Management Activity API as an option. The right method depends on whether the work is an occasional investigation or a recurring retrieval pipeline; the cited Microsoft guidance does not establish a comparative cost or performance winner.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.