Fix Add-MailboxPermission Audit TargetUser Showing Object ID in Microsoft 365
Question details
Microsoft 365 audit events for Add-MailboxPermission are displaying the TargetUser value as an Object ID rather than a readable username.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Reviewing security alerts and investigating audit events related to Microsoft 365 mailbox permissions.
- Observed behavior
- The TargetUser value in the audit log is outputting a cryptic Object ID rather than the expected User Principal Name (UPN), making investigation and alert review difficult.
Ensure you have administrative access to your Microsoft 365 tenant and the Microsoft Entra ID (formerly Azure AD) portal to manually cross-reference Object IDs with user accounts.
Map Object IDs Manually and Consult Microsoft Graph Support
Because this behavior stems from how the Microsoft Graph API logs target users internally, the most effective approach is to manually resolve the ID in Entra ID and report the specific API details to the Microsoft Graph support community.
Audit logs rely on backend Graph API data. In some scenarios involving automated scripts or specific endpoint queries, the API prioritizes the immutable Object ID over the mutable username. This requires a manual lookup to decipher who was targeted by the permission change.
Copy the exact Object ID string listed under the TargetUser field in your Microsoft 365 audit event log.
Navigate to the Microsoft Entra admin center, go to 'Users', and paste the Object ID into the search bar to identify the actual username (UPN).
Document the exact format of the audit event and the relevant Graph API endpoint used when the Add-MailboxPermission action occurred. Redact any sensitive tenant information.
Visit the official Microsoft Graph Q&A forum (https://learn.microsoft.com/en-us/answers/tags/161/ms-graph) and submit your findings to get specific API and programming scenario support directly from Microsoft engineers.

Manage IT Documentation Seamlessly with WPS Office
While troubleshooting complex Microsoft 365 API and audit log issues, you need a reliable suite to document your findings, compile scripts, and share reports. WPS Office provides a free, lightweight, and highly compatible alternative to Microsoft Office.
- 1. Download the Installer: Visit the official WPS Office website and click the free download button.
- 2. Install WPS Office: Run the installer file and follow the quick on-screen instructions to set up the lightweight suite.
- 3. Open Your IT Reports: Double-click any existing Microsoft Office document to instantly open and edit it in WPS Office's familiar interface.

Frequently Asked Questions
Why does Microsoft 365 log an Object ID instead of a username?
This often occurs because the underlying Microsoft Graph API or Exchange Online PowerShell commands identify user entities by their immutable Object IDs to prevent conflicts. Occasionally, the frontend UI or audit log compiler fails to resolve this back to a readable User Principal Name (UPN).
How can I convert a TargetUser Object ID back to a username?
You can copy the Object ID from the audit log and search for it in the Microsoft Entra ID (Azure AD) admin center under 'Users', or use the Exchange Online PowerShell command Get-User -Identity <ObjectID> to find the corresponding account.
Does this Object ID issue affect all Microsoft 365 audit logs?
Not necessarily. It is primarily observed in specific administrative events like Add-MailboxPermission, especially when the actions are triggered via certain Graph API endpoints, third-party integrations, or automated scripts rather than the standard admin center GUI.




