Why Exchange Online ForwardCount Values Change Between Reports
Question details
Users notice that ForwardCount values in Exchange Online mail-forwarding reports change when the exact same report is generated at different times.

- Product
- Exchange Online
- Device & OS
- not provided
- Scenario
- Generating and comparing mail-forwarding reports for security auditing or administrative management in Microsoft 365.
- Observed behavior
- The ForwardCount metrics for identical time periods fluctuate or show discrepancies depending on the exact time the report is executed.
Verify that you are using the exact same filters, parameters, and time ranges when comparing multiple Exchange Online reports.
Account for Microsoft 365 Data Processing Delays
Standardize your reporting procedures and allow sufficient time for background data to consolidate across Microsoft 365 servers.
Microsoft 365 reporting systems collect log data from multiple distributed servers. Because this data is processed and refreshed at different intervals, reports executed at different times may capture different stages of this data consolidation, leading to minor variations in counts.
Ensure you are applying identical date ranges, user filters, and report parameters each time you generate the mail-forwarding report.
Record the exact timestamp of when each report was generated to easily track and account for Microsoft 365's rolling data refresh cycles.
Explain to management and auditors that small differences are standard reporting-timing variations caused by backend processing delays, rather than actual data errors.

Escalate Persistent Discrepancies to Microsoft Support
If report values continue to show massive or persistent variations across identical timeframes after 48 hours, request a tenant-specific backend investigation.
Analyze Exchange Online Reports with WPS Office
If you are exporting mail-forwarding reports from Microsoft 365 for offline analysis, WPS Office provides a free, lightweight, and highly compatible alternative to Microsoft Excel for opening, filtering, and comparing your CSV report data.
- 1. Export Admin Data: Download your Exchange mail-forwarding report from the Microsoft 365 Admin Center as a CSV file.
- 2. Open with WPS: Launch WPS Spreadsheet and open the exported report to safely review your offline data.
- 3. Analyze and Compare: Use built-in data filters and comparison formulas to track ForwardCount differences.

Frequently Asked Questions
How long does it take for Microsoft 365 reporting data to fully process?
Microsoft 365 reporting data can take anywhere from 24 to 48 hours to be fully collected, processed, and consolidated. Reports generated before this window may show incomplete or fluctuating data.
Why do my ForwardCount values keep changing for past dates?
Data processing in Exchange Online is continuous. If background processes were momentarily delayed, older server logs might be added to the database later, causing counts for past dates to increase upon refreshing the report.
Is there a more immediate way to check email forwarding activity?
Yes. For near real-time data, administrators can use Exchange Online PowerShell to run message trace commands, which bypasses the standard admin center dashboard reporting delays.




