logo
search
list

Table of Content

Extracting Raw Data via Microsoft Graph API
Alternative Method: Exporting via Microsoft Purview eDiscovery
Analyzing and Documenting Your Output Using WPS Office
Frequently Asked Questions

How to Access MIME Content for Microsoft 365 Group Mailboxes

Posted by Kushani Nimanthika

calendar

2026-09-08

views

868

likes

59

Extracting raw message data from shared team environments requires specific API calls or administrative portal workflows. When you need to access MIME content for Microsoft 365 Group mailboxes, you are looking for the raw, unparsed email format that includes all routing headers, body text, and base64-encoded attachments. This format is heavily utilized for migration projects, compliance auditing, or deep diagnostic analysis of email routing. Microsoft structures group conversations as threads and posts rather than standard mailbox messages, meaning standard user email retrieval methods will fail. The workflows below detail the precise technical steps to extract this raw data stream successfully.

Extracting Raw Data via Microsoft Graph API

The most direct and programmatically supported method relies on the Microsoft Graph API. Because group messages are categorized as conversation posts rather than standard inbox messages, you must target the specific group, thread, and post identifiers. Modifying the standard API endpoint forces the system to return the raw text stream instead of a parsed JSON object.

Before executing the query, ensure your application or Graph Explorer session has the necessary permissions. You must grant and consent to the Group.Read.All or Group.ReadWrite.All delegated or application permissions in Microsoft Entra ID.

  • Step 1: Obtain the Group ID. Send a GET request to https://graph.microsoft.com/v1.0/groups. Scan the response and copy the alphanumeric object ID of the specific target group.
  • Step 2: Obtain the Thread ID. Send a GET request to https://graph.microsoft.com/v1.0/groups/{group-id}/threads. Locate the conversation thread containing the message you want and copy its ID string.
  • Step 3: Obtain the Post ID. Send a GET request to https://graph.microsoft.com/v1.0/groups/{group-id}/threads/{thread-id}/posts. Copy the specific post ID from the JSON response.
  • Step 4: Request the MIME Stream. Construct your final GET request using all three identifiers and append the specific value parameter: https://graph.microsoft.com/v1.0/groups/{group-id}/threads/{thread-id}/posts/{post-id}/$value.

When you execute this final request, the expected result is a plaintext response beginning with standard email headers (such as Return-Path, Received, and Message-ID) followed by the multipart body content. To verify the extraction was successful, check the HTTP response headers; the Content-Type should be returned as text/plain or message/rfc822, not application/json. Save this output directly as a .eml or .txt file.

Alternative Method: Exporting via Microsoft Purview eDiscovery

Illustrated steps for Accessing MIME Content for Microsoft 365 Group Mailboxes
Key actions for Accessing MIME Content for Microsoft 365 Group Mailboxes.

If you do not have developer access to the Graph API or need to extract raw messages in bulk across an entire group, the Microsoft Purview compliance portal provides a graphical alternative. This method relies on native eDiscovery features to package group mailbox data into downloadable EML files, which inherently contain the full MIME structure.

You must hold the eDiscovery Manager role within the Microsoft Purview compliance portal to perform this action.

  • Step 1: Navigate to the Microsoft Purview compliance portal and select eDiscovery > Standard from the left navigation menu.
  • Step 2: Click Create a case, name it appropriately, and open the new case.
  • Step 3: Navigate to the Searches tab and click New search. In the locations toggle, turn on Exchange mailboxes, click Choose users, groups, or teams, and add the specific Microsoft 365 Group.
  • Step 4: Submit the search and wait for the status to show as Completed. Click on the search name and select Export results.
  • Step 5: In the export options, specifically choose One PST file for each mailbox or select the option to export individual messages. Download the eDiscovery Export Tool, paste your export key, and download the data. If exported as a PST, you can extract individual items as EML files using standard archiving utilities to view the raw format.

Analyzing and Documenting Your Output Using WPS Office

WPS Office options related to Accessing MIME Content for Microsoft 365 Group Mailboxes
How WPS Office can support related document work.

Accessing the underlying mailbox infrastructure and exporting the data is entirely controlled by Microsoft accounts, tenant licensing, and Azure administration. WPS Office cannot change those Microsoft-side settings or directly execute Graph API calls against cloud services. However, once you successfully export the raw data as .txt or .eml files, WPS Office provides an excellent environment for analyzing, cleaning, and documenting this complex data.

Raw MIME data is notoriously difficult to read due to heavy base64 encoding and dense header blocks. You can open your exported .txt files directly in WPS Writer to format the output for compliance reports or development documentation. Utilize WPS Writer's robust Find and Replace features to quickly locate specific IP addresses in the Received headers or isolate the boundary markers separating plain text from HTML body parts.

If you are preparing this data for legal or compliance review, raw text files can easily be altered. Once you have pasted and formatted your extracted headers and routing data in WPS Writer, use the built-in PDF conversion tool. Navigate to the Tools tab and click Export to PDF. This secures the raw routing data into an immutable format, ensuring the diagnostic information remains intact and uneditable when shared with external auditors or network engineering teams.

WPS Writer app icon
WPS Presentation app icon
WPS Spreadsheets app icon
WPS PDF app icon
Use Word, Excel, and PPT for FREE

Frequently Asked Questions

Why does the Graph API return a standard JSON object instead of the raw message headers?

This occurs when the endpoint URL is incomplete. If you call the endpoint ending in /posts/{post-id}, Microsoft Graph defaults to returning the parsed properties of the message in JSON format. You must append /$value to the very end of your request URL. This specific parameter instructs the API to bypass JSON parsing and output the raw text stream of the message.

Can I extract specific attachments directly from the raw stream?

Yes, but it requires manual decoding. In the MIME format, attachments are embedded directly within the text as blocks of base64-encoded characters, separated by boundary strings defined in the Content-Type header. To extract an attachment from the raw output, you must copy the exact block of base64 text for that specific file part and run it through a base64 decoding script or utility to reconstruct the original file.

Do Exchange Web Services (EWS) still support retrieving group mailbox data?

EWS does include the IncludeMimeContent property within the GetItem operation, which historically retrieves raw formats. However, Microsoft 365 Groups are optimized for the Graph API, and Microsoft is actively deprecating EWS for Exchange Online. Attempting to bind to group mailboxes via EWS often results in routing errors or access denied exceptions. The Graph API is the only supported programmatic method for modern group infrastructure.

How do I read the base64 encoded body text if I only need the plain text message?

If the message content was sent using UTF-8 or complex HTML, the raw stream will often display the body as Content-Transfer-Encoding: base64. You cannot read this natively in a text editor. If your sole goal is to read the message body rather than audit the routing headers, you should remove the /$value parameter from your Graph API call. The standard JSON response automatically decodes the base64 content and presents the body text in a highly readable format.

Kushani Nimanthika

Office software expert with 15+ years of experience since 2009. I specialize in tech tutorials, productivity tools, and digital solutions for everyday users. Passionate about making technology simple and accessible for everyone.