logo
search
Others

Why Exchange Online ForwardCount Values Change Between Reports

Huda QurayshiHuda Qurayshi Sep 27, 2026 869 views

Question details

Users notice that ForwardCount values in Exchange Online mail-forwarding reports change when the exact same report is generated at different times.

Why Exchange Online ForwardCount Values Change Between Reports
Product
Exchange Online
Device & OS
not provided
Scenario
Generating and comparing mail-forwarding reports for security auditing or administrative management in Microsoft 365.
Observed behavior
The ForwardCount metrics for identical time periods fluctuate or show discrepancies depending on the exact time the report is executed.
Before you start

Verify that you are using the exact same filters, parameters, and time ranges when comparing multiple Exchange Online reports.

Solution 1Recommended

Account for Microsoft 365 Data Processing Delays

Standardize your reporting procedures and allow sufficient time for background data to consolidate across Microsoft 365 servers.

Microsoft 365 reporting systems collect log data from multiple distributed servers. Because this data is processed and refreshed at different intervals, reports executed at different times may capture different stages of this data consolidation, leading to minor variations in counts.

1
Standardize report filters

Ensure you are applying identical date ranges, user filters, and report parameters each time you generate the mail-forwarding report.

2
Document generation times

Record the exact timestamp of when each report was generated to easily track and account for Microsoft 365's rolling data refresh cycles.

3
Communicate timing variations

Explain to management and auditors that small differences are standard reporting-timing variations caused by backend processing delays, rather than actual data errors.

Account for Microsoft 365 Data Processing Delays
Data Consolidation Time: It is highly recommended to wait at least 24 to 48 hours after the end of your targeted reporting period before generating final audit reports to ensure all data has settled.
Free Microsoft Office alternative

Analyze Exchange Online Reports with WPS Office

If you are exporting mail-forwarding reports from Microsoft 365 for offline analysis, WPS Office provides a free, lightweight, and highly compatible alternative to Microsoft Excel for opening, filtering, and comparing your CSV report data.

  1. 1. Export Admin Data: Download your Exchange mail-forwarding report from the Microsoft 365 Admin Center as a CSV file.
  2. 2. Open with WPS: Launch WPS Spreadsheet and open the exported report to safely review your offline data.
  3. 3. Analyze and Compare: Use built-in data filters and comparison formulas to track ForwardCount differences.
Fully compatible with Microsoft Excel formats (.xlsx, .csv) for analyzing exported Exchange reporting data.Free and lightweight comprehensive office suite including Spreadsheet, Writer, and Presentation tools.Familiar user interface requires no learning curve for seamless migration from Microsoft Office.Powerful data filtering and pivot table tools to easily spot ForwardCount discrepancies.
microsoft office alternative - wps office

Frequently Asked Questions

How long does it take for Microsoft 365 reporting data to fully process?

Microsoft 365 reporting data can take anywhere from 24 to 48 hours to be fully collected, processed, and consolidated. Reports generated before this window may show incomplete or fluctuating data.

Why do my ForwardCount values keep changing for past dates?

Data processing in Exchange Online is continuous. If background processes were momentarily delayed, older server logs might be added to the database later, causing counts for past dates to increase upon refreshing the report.

Is there a more immediate way to check email forwarding activity?

Yes. For near real-time data, administrators can use Exchange Online PowerShell to run message trace commands, which bypasses the standard admin center dashboard reporting delays.