<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	
	xmlns:georss="http://www.georss.org/georss"
	xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#"
	>

<channel>
	<title>MailboxAudit &#8211; Webbanshee</title>
	<atom:link href="https://webbanshee.net/tag/mailboxaudit/feed/" rel="self" type="application/rss+xml" />
	<link>https://webbanshee.net</link>
	<description>Your Exchange Server Blog</description>
	<lastBuildDate>Thu, 28 Apr 2022 07:43:07 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://webbanshee.net/wp-content/uploads/2017/01/WB_BL_RND-150x150.png</url>
	<title>MailboxAudit &#8211; Webbanshee</title>
	<link>https://webbanshee.net</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">122610384</site>	<item>
		<title>Mailbox Audit Logging &#8211; Enable and Search Logs</title>
		<link>https://webbanshee.net/mailbox-audit-logging/</link>
					<comments>https://webbanshee.net/mailbox-audit-logging/#respond</comments>
		
		<dc:creator><![CDATA[WebBanshee]]></dc:creator>
		<pubDate>Fri, 12 Mar 2021 07:21:35 +0000</pubDate>
				<category><![CDATA[Serverside]]></category>
		<category><![CDATA[2013]]></category>
		<category><![CDATA[2016]]></category>
		<category><![CDATA[2019]]></category>
		<category><![CDATA[Exchange]]></category>
		<category><![CDATA[MailboxAudit]]></category>
		<category><![CDATA[Powershell]]></category>
		<guid isPermaLink="false">https://webbanshee.net/?p=3656</guid>

					<description><![CDATA[<style>.key{background:#444444;padding-left: 5px;padding-right: 5px;padding-top: 2px;padding-bottom: 2px;color:#fefefe;border-radius: 3px;font-size: 14px;}</style>
<p><a class="ex-link" href="https://webbanshee.net/mailbox-audit-logging/"><img src="https://webbanshee.net/wp-content/uploads/2021/02/MailboxAuditLogging.svg"/><span class="exTeaser" style="width:70%;">Use Mailbox Audit Logging to gather insights about what happens in a certain mailbox. </span><br />
<span class="exText" style="width:70%;" >When a mail went missing without interaction of the mailbox owner Mailbox Audit Logging can provide useful information.<span style="font-size: 11px !Important; width: 10%; height: 5%; color: #993333; padding-left: 20px;">......read more</span></span></a></p>
<p>The post <a rel="nofollow" href="https://webbanshee.net/mailbox-audit-logging/">Mailbox Audit Logging &#8211; Enable and Search Logs</a> appeared first on <a rel="nofollow" href="https://webbanshee.net">Webbanshee</a>.</p>
]]></description>
										<content:encoded><![CDATA[<style>h2 {font-weight: bold;text-decoration:none;font-size: 22px!Important;}h3 {font-weight: bold;text-decoration:none;font-size: 18px!Important;}h4 {font-weight: bold;text-decoration:none;font-size: 16px!Important;}.wp-image-2045,.wp-image-2051,.wp-image-2050,.wp-image-2049,.wp-image-2056, .wp-image-2055 {margin-top:2px!Important;margin-right:6px;}.red{background:#E86275;padding-left: 5px;padding-right: 5px;padding-top: 2px;padding-bottom: 2px;color:#fefefe;border-radius: 3px;font-size: 14px;} .wpe-button-blue {background:#1072C1!Important; border: none!Important;} .txtred {color:#993333;font-weight:bold;} .txtbold {font-weight:bold;}</style>
<p style="text-align: justify;">Did you ever receive inquiries about strange mailbox behavior like users state that mails have been deleted without any interaction of the mailbox owner? In cases like this, you are happy to enable Mailbox Audit Logging on the affected mailbox.</p>
<p style="text-align: justify;">This post is about how to enable Mailbox Audit Logging on a certain mailbox and configure the auditing parameters to provide the most relevant insights. Let&#8217;s get to the point straight away:</p>
<p>&nbsp;</p>
<h2><img class="alignnone size-full wp-image-2045" src="https://webbanshee.net/wp-content/uploads/2019/01/round_1.svg" alt="1 -" />Enable Mailbox Audit Logging on a mailbox</h2>
<h3>Check the audit status on a certain mailbox:</h3>
<div class="wpe-box wpe-box-note3">
<p><span style="font-weight: bold;">get-mailbox -Identity <span style="font-weight: bold; color: #993333;">MailboxName</span> | select PrimarySmtpAddress, *audit* | fl</span></p>
<p>In the following examples, I will use intern@testlab.local as <span style="font-weight: bold;">-Identity</span><br />
The output shows that Mailbox Audit Logging is not enabled on this mailbox:<br />
<a href="https://webbanshee.net/wp-content/uploads/2021/03/MailboxAuditLoggingDisabled.png"><img loading="lazy" class="aligncenter wp-image-3905 size-full" src="https://webbanshee.net/wp-content/uploads/2021/03/MailboxAuditLoggingDisabled.png" alt="Mailbo Audit Logging Disabled" width="1383" height="92" srcset="https://webbanshee.net/wp-content/uploads/2021/03/MailboxAuditLoggingDisabled.png 1383w, https://webbanshee.net/wp-content/uploads/2021/03/MailboxAuditLoggingDisabled-300x20.png 300w, https://webbanshee.net/wp-content/uploads/2021/03/MailboxAuditLoggingDisabled-1024x68.png 1024w, https://webbanshee.net/wp-content/uploads/2021/03/MailboxAuditLoggingDisabled-768x51.png 768w" sizes="(max-width: 1383px) 100vw, 1383px" /></a></p>
</div>
<h3>Enable Mailbox Audit Logging:</h3>
<div class="wpe-box wpe-box-note3">
<p><span style="font-weight: bold;">get-mailbox -Identity <span style="font-weight: bold; color: #993333;">MailboxName</span> | Set-Mailbox -AuditEnabled <span style="font-weight: bold; color: #993333;">$True</span></span></p>
<p>When you check the status again using the first command it will show AuditEnabled as True now.<br />
Operations audited by default are shown as well:<br />
<a href="https://webbanshee.net/wp-content/uploads/2021/03/MailboxAuditLoggingEnabled.png"><img loading="lazy" class="aligncenter size-full wp-image-3910" src="https://webbanshee.net/wp-content/uploads/2021/03/MailboxAuditLoggingEnabled.png" alt="Mailbox Audit Logging Enabled" width="1389" height="93" srcset="https://webbanshee.net/wp-content/uploads/2021/03/MailboxAuditLoggingEnabled.png 1389w, https://webbanshee.net/wp-content/uploads/2021/03/MailboxAuditLoggingEnabled-300x20.png 300w, https://webbanshee.net/wp-content/uploads/2021/03/MailboxAuditLoggingEnabled-1024x69.png 1024w, https://webbanshee.net/wp-content/uploads/2021/03/MailboxAuditLoggingEnabled-768x51.png 768w" sizes="(max-width: 1389px) 100vw, 1389px" /></a></p>
<p>If your output is truncated with ellipses (&#8230;) <a class="wpe-button wpe-button-blue" href="https://webbanshee.net/expand-powershell-output/" target="_blank" rel="noopener noreferrer">change the $FormatEnumerationLimit value.</a></p>
</div>
<h3>Define operations that should be audited:</h3>
<p>Depending on what circumstances make a mailbox audit logging necessary you can change the predefined audit operations to more relevant ones. Find a list of actions logged by mailbox audit logging <a style="font-weight: bold; color: #993333;" href="https://docs.microsoft.com/en-us/exchange/policy-and-compliance/mailbox-audit-logging/mailbox-audit-logging?view=exchserver-2019#mailbox-actions-logged-by-mailbox-audit-logging" target="_blank" rel="noopener noreferrer">here.</a></p>
<p>Usually, I completely change the actions for AuditOwner. <strong>AuditOwner = MailboxOwner</strong><br />
To do so use the following command:</p>
<div class="wpe-box wpe-box-note3"><span style="font-weight: bold;">Set-Mailbox <span style="font-weight: bold; color: #993333;">MailboxName</span> -Audit<span style="font-weight: bold; color: #993333;">Owner &#8220;Create, SoftDelete, HardDelete, Update, Move, MoveToDeletedItems,MailboxLogin&#8221;</span></span><br />
<a href="https://webbanshee.net/wp-content/uploads/2021/03/MailboxAuditLogging.png"><img loading="lazy" src="https://webbanshee.net/wp-content/uploads/2021/03/MailboxAuditLogging.png" alt="Mailbox Audit Loggint" width="1320" height="113" class="aligncenter size-full wp-image-3929" srcset="https://webbanshee.net/wp-content/uploads/2021/03/MailboxAuditLogging.png 1320w, https://webbanshee.net/wp-content/uploads/2021/03/MailboxAuditLogging-300x26.png 300w, https://webbanshee.net/wp-content/uploads/2021/03/MailboxAuditLogging-1024x88.png 1024w, https://webbanshee.net/wp-content/uploads/2021/03/MailboxAuditLogging-768x66.png 768w" sizes="(max-width: 1320px) 100vw, 1320px" /></a><br />
Adjust the logged actions according to the list by Microsoft mentioned above.<br />
Use <span style="font-weight: bold;">-AuditAdmin</span> or <span style="font-weight: bold;">-AuditDelegate</span> instead of <span style="font-weight: bold;">-AuditOwner</span> to change logged operations for Admin or Delegates.</p>
</div>
<h2><img class="alignnone size-full wp-image-2051" src="https://webbanshee.net/wp-content/uploads/2019/01/round_2.svg" alt="2 -" />Search Mailbox Audit Logs</h2>
<h3>Define your query:</h3>
<p>The <span style="font-weight: bold;">Search-MailboxAuditLog</span> CMDlet seems only to work out of an Exchange Management Shell. Out of an ISE loaded with an Exchange PS-Snapin, I always get an error. </p>
<p style="text-align: justify;">Undoubtedly the filter for date ranges in connection with the Search-MailboxAuditLog CMDlet is somewhat imprecise. If you want to query a range from 3 days ago until today for instance I recommend setting the end date of the query to the date of tomorrow. Otherwise, it can happen that no results will be shown for the current day or even the day before.</p>
<div class="wpe-box wpe-box-alert5">
<div class="wpe-box wpe-box-note3" style="overflow-x: auto;">
<span style="font-weight: bold;">Search-MailboxAuditLog -Identity <span style="font-weight: bold; color: #993333;">MailboName</span> -StartDate <span style="font-weight: bold; color: #993333;">&#8220;MM/DD/YYYY&#8221;</span> -EndDate <span style="font-weight: bold; color: #993333;">&#8220;MM/DD/YYYY&#8221;</span> -LogonTypes <span style="font-weight: bold; color: #993333;">Owner</span> -ShowDetails | select <span style="font-weight: bold; color: #993333;">lastaccessed, operation, logontype ,logonuserdisplayname,folderpathname,ClientIPAddress,ClientInfoString,ClientMachineName,ClientProcessName,MailboxOwnerUPN,DelegateUserDisplayName,MailboxResolvedOwnerName,SourceItemSubjectslist</span> | sort <span style="font-weight: bold; color: #993333;">lastaccessed</span> |ft -autosize</span>
</div>
<h3>Some notes to the query above:</h3>
<p><span style="font-weight: bold; color:#993333;">-StartDate/-EndDate:</span> The date format can vary depending on the regional settings of your system!<br />
<span style="font-weight: bold; color:#993333;">-LogonTypes:</span> Narrow down your query to logon types you are interested in.</p>
<h3>Selectors:</h3>
<p><span style="font-weight: bold; color:#993333;">Operation:</span> Displays the logged action.<br />
<span style="font-weight: bold; color:#993333;">ClientIpAddress:</span> Shows the IP address of the client respectively the source network outgoing IP address.<br />
<span style="font-weight: bold; color:#993333;">ClientInfoString:</span> Shows client connection types like RPC, ActiveSync, OWA<br />
<span style="font-weight: bold; color:#993333;">ClientProcessName:</span> For example OUTLOOK.exe<br />
<span style="font-weight: bold; color:#993333;">SourceItemSubjectslist:</span> The subject of mails where an action has been logged with.</p>
<p><span style="font-weight: bold;">I recommend to use only relevant selectors when searching an audit log.<br />
Displaying all selectors can make the output confusing or will not fit in at all.</span>
</div>
<p>Stay safe folks!<br />
&nbsp;</p>
<p>The post <a rel="nofollow" href="https://webbanshee.net/mailbox-audit-logging/">Mailbox Audit Logging &#8211; Enable and Search Logs</a> appeared first on <a rel="nofollow" href="https://webbanshee.net">Webbanshee</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://webbanshee.net/mailbox-audit-logging/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">3656</post-id>	</item>
	</channel>
</rss>
