Start by identifying the affected mailbox and investigation time window, then check what mailbox actions were actually audited before searching the available records. On-premises Exchange Server provides mailbox audit searches and EAC reports, but missing events—especially owner actions—do not rule out access or compromise. Keep mailbox-access records separate from administrator audit logs, and do not use Exchange Online commands as if they were on-premises Exchange procedures.
1. Define the investigation scope and time window
List the mailbox or mailboxes in scope and set the earliest plausible time of suspicious activity. Record the time bounds and why you chose them; this makes it possible to interpret search results and preserve the basis for later review. If the incident is ongoing, include activity through the completion of remediation in your review. Microsoft describes that approach in guidance for Microsoft 365 accounts, so treat it as a general scoping principle—not an on-premises Exchange command or procedure.
2. Check what each mailbox was configured to audit
Exchange Server mailbox auditing is configured per mailbox. Exchange logs some administrator and delegate actions by default, but mailbox owner actions are not logged by default. Before interpreting an empty search, establish which actions and logon types were enabled for the mailbox during the relevant period. A lack of owner-action entries does not show that the owner did not access the mailbox, or that the mailbox was not compromised.
3. Search mailbox audit records
Microsoft documents three ways to review mailbox audit activity. Choose based on the number of mailboxes, whether you need an interactive result or an asynchronous search, and the audit settings and time window relevant to the case. The documentation does not identify one method as universally best.
Recommended Free Tools
#1 Best Overall
| Method | Best suited to | What to expect |
|---|---|---|
Search-MailboxAuditLog |
A synchronous search of one mailbox | Search results for the selected mailbox; findings depend on the actions and logon types configured for auditing. |
New-MailboxAuditLogSearch |
An asynchronous search of one or more mailboxes | An asynchronous search workflow for the selected mailboxes; findings depend on their audit configuration. |
| Exchange admin center (EAC), Auditing tab | A non-owner mailbox access report or export of non-owner entries | A report or export of available non-owner audit entries; this does not replace owner-action auditing when those actions were not configured. |
Use the Exchange Management Shell or EAC experience appropriate to the Exchange Server version and deployment. The documented procedures do not establish a single set of search parameters that fits every version and incident, so confirm the available options in the environment before running a search.
4. Evaluate the fields in each entry
Review entries in the context of known legitimate activity rather than relying on a universal anomaly threshold; Microsoft’s cited on-premises documentation does not prescribe one. Relevant documented fields include:
Rank #2
- Server 2022 Standard 16 Core
- Operation and operation result: what action was recorded and its outcome.
- Logon type: whether the entry is attributed to an Owner, Delegate, or Admin.
- Client details: client IP address, client machine name, client process name, and client information string.
- Folder information: the folder involved; for move operations, the entry can include the destination folder.
Compare these details with the mailbox’s expected users, delegates, administrators, client applications, and access patterns. An IP address or client name alone is not a finding of compromise; interpret it alongside the operation, result, logon type, and incident timeline.
5. Review administrator audit logs as a separate evidence stream
Mailbox audit entries describe mailbox activity. Administrator audit logging records Exchange Management Shell cmdlets, so review it separately for relevant changes during the incident window—particularly changes that could affect access or mailbox configuration. Microsoft states that administrator audit logging is enabled by default in new Exchange Server installations. That default does not establish the setting or log availability on a particular server; confirm the deployment’s configuration.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteRank #3
6. Account for retention and preserve available records
On-premises mailbox audit logs are stored in the audited mailbox’s Recoverable Items Audits subfolder. Microsoft documents 90 days as the default retention period for mailbox audit entries; administrators can change the configured retention. Confirm the actual setting and preserve or export relevant records promptly, since entries beyond the configured period may no longer be available.
7. Keep Exchange Online evidence in scope only when it applies
Microsoft’s compromised-account procedure using MailItemsAccessed and Search-UnifiedAuditLog is for Exchange Online/Microsoft 365, not an established on-premises Exchange Server search procedure. Microsoft 365 sign-in logs, Defender audit logs, and message trace may be relevant in a hybrid or cloud-connected incident, but their availability and applicability depend on the environment. Confirm whether the deployment is hybrid before treating cloud-side evidence as part of the case.
Rank #4
What the available evidence can—and cannot—show
Mailbox and administrator audit records can help establish which configured actions were recorded, under which logon type, and with what client and folder details. Their absence is not proof that no access occurred: owner actions may not have been audited, retention may have expired, or the deployment may differ from default settings. These Exchange audit procedures are not a complete host-level forensic acquisition or containment playbook; server version, topology, configuration, and incident facts determine what additional investigation is needed.
Quick Recap
Best Value
- Used Book in Good Condition
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

