How to Audit Azure Application Mailbox Access in Exchange Online
Question details
The user needs to track and audit which user mailboxes an Azure-registered application has accessed over the last 24 to 48 hours and locate where these logs are stored.

- Product
- Microsoft Azure / Exchange Online
- Device & OS
- not provided
- Scenario
- Monitoring application permissions and verifying specific mailbox access events for security and compliance purposes.
- Observed behavior
- Seeking the exact storage location and query method for logs showing applications accessing mailboxes (rather than users accessing applications).
Ensure you have the appropriate administrative roles, such as Global Administrator or Compliance Administrator, and verify that mailbox auditing is enabled across your Microsoft 365 tenant.
Review Microsoft Purview Audit and Entra ID Sign-in Logs
Track application-based mailbox access by querying the unified audit log in Microsoft Purview and cross-referencing workload identities in Microsoft Entra.
To view events where an application accessed a user's mailbox, you must utilize Microsoft 365's unified auditing tools rather than standard user sign-in logs.
Navigate to the Microsoft Purview compliance portal and log in with your global or compliance administrator credentials.
Go to the Audit section from the left-hand navigation pane. Set the date and time range for the previous 24 to 48 hours.
In the 'Activities' dropdown, select Exchange mailbox activities. You can further filter the results by inputting the specific Azure application's App ID or Object ID to isolate its actions.
Open the Microsoft Entra admin center, go to 'Sign-in logs', and switch to the 'Service principal sign-ins' tab. This will confirm when the application authenticated and acquired a token to access Exchange Online.

Consult the Azure Microsoft Q&A Community
If standard audit logs do not provide the necessary granularity for your specific application permissions, reach out to specialized Azure support engineers.
Looking for a Simpler, Lighter Office Suite? Try WPS Office
Managing Microsoft 365, Azure, and Exchange compliance can be highly complex and resource-intensive. If you need a straightforward, fast, and free productivity suite for your daily document tasks without the enterprise overhead, WPS Office is an excellent alternative.
- 1. Download WPS Office: Visit the official WPS Office website and click the free download button for your operating system.
- 2. Install the Suite: Run the installer and follow the on-screen prompts to complete the lightweight installation process.
- 3. Open Your Office Files: Launch WPS Office and seamlessly open any existing Microsoft Word, Excel, or PowerPoint files without losing formatting.

Frequently Asked Questions
Why can't I see mailbox access logs for my Azure application in Purview?
You must ensure that mailbox auditing is enabled by default in Exchange Online. Additionally, specific actions (such as MailboxLogin or ItemBind) must be configured to be logged for the target mailboxes; otherwise, the application's access events will not be recorded.
Are application sign-in logs the same as mailbox access logs?
No. Microsoft Entra service principal sign-in logs only show when the application successfully authenticated to Azure AD to get an access token. They do not show which specific mailboxes or emails the application interacted with using that token. For that, you need the Purview unified audit logs.
Can I query application mailbox access directly using Azure Log Analytics?
Yes, but only if you have proactively configured diagnostic settings to route your Microsoft Entra workload identity logs and your Microsoft 365 audit logs into your Log Analytics workspace. Once routed, you can use Kusto Query Language (KQL) to filter for specific app access events.




