logo
search
Calendar Problems

How to Identify Who Modified a Shared Calendar Event in Microsoft 365

Maira MehtabMaira Mehtab Sep 24, 2026 869 views

Question details

The user needs to determine who altered recurring and one-time Teams meetings hosted in a shared mailbox, especially after standard audit searches yield no results.

Product
Microsoft 365
Device & OS
not provided
Scenario
Investigating unauthorized changes to shared calendar events and missing mailbox permissions.
Observed behavior
Teams meetings were unexpectedly altered, some mailbox permissions disappeared, and standard Microsoft 365 audit logs failed to identify the user or the exact changes made.
Before you start

Ensure you have already run a standard audit log search in the Microsoft Purview compliance portal and documented the exact dates and times the unexpected calendar changes occurred.

Solution 1Recommended

Escalate to Microsoft 365 Support for Backend Investigation

Use this solution when standard audit logs fail to reveal who changed shared calendar events or why mailbox permissions disappeared.

Because community support and standard tenant admin tools cannot access detailed backend logs, escalating the issue to official Microsoft Support is required to trace the exact source of the meeting changes and permission modifications.

1
Access the Admin Center

Log in to the Microsoft 365 admin center using your global administrator or support admin credentials.

2
Open a Support Ticket

Navigate to the 'Support' section in the left-hand menu and select 'Help & support' to open a new service request.

3
Provide Required Details

In your support ticket, clearly include the shared mailbox address, affected event names, exact timestamps of the modifications, and your preliminary audit search results.

4
Include Correlation IDs

If you received any error messages or request IDs during your own investigation, add these correlation IDs to help backend engineers locate the server logs faster.

Information Security: Only Microsoft backend support can access the tenant-level logs necessary for this type of deep investigation. Community forums do not have access to your data.
Free Microsoft Office alternative

Looking for a Reliable Office Suite? Try WPS Office

Complex backend issues and tenant management in Microsoft 365 can occasionally disrupt your workflow. If you need a lightweight, reliable, and highly compatible alternative for managing your daily documents, WPS Office is an excellent choice.

  1. 1. Download the Installer: Visit the official WPS Office website and download the installation package tailored for your operating system.
  2. 2. Install WPS Office: Run the downloaded installer and follow the simple on-screen instructions to set up the software.
  3. 3. Start Editing Seamlessly: Open your existing Microsoft Office files directly in WPS Office and start editing immediately without formatting loss.
Free and lightweight office suite for personal and professional useHigh compatibility with Microsoft Word, Excel, and PowerPoint formatsIntuitive interface with no steep learning curveSeamless offline document editing without complex tenant management
microsoft office alternative - wps office

Frequently Asked Questions

Why can't I find who changed the shared calendar event in the standard audit logs?

Sometimes standard audit logs in the Microsoft Purview portal do not capture specific backend synchronization events or automated updates made via particular Teams integrations. In these cases, deeper backend log analysis by Microsoft Support is required.

What specific details should I gather before contacting Microsoft Support?

You should prepare the shared mailbox email address, the names of the affected recurring or one-time events, the exact timestamps when the changes occurred, your initial audit search results, and any correlation IDs.

Can community forums resolve missing shared mailbox permissions?

No, community support members do not have access to your Microsoft 365 tenant data. Disappearing permissions combined with missing audit trails must be investigated directly by official Microsoft backend engineers.