logo
search
Compliance Problems

How to Audit Azure Application Mailbox Access in Exchange Online

Kushani NimanthikaKushani Nimanthika Sep 28, 2026 868 views

Question details

The user needs to track and audit which user mailboxes an Azure-registered application has accessed over the last 24 to 48 hours and locate where these logs are stored.

How to Audit Azure Application Mailbox Access
Product
Microsoft Azure / Exchange Online
Device & OS
not provided
Scenario
Monitoring application permissions and verifying specific mailbox access events for security and compliance purposes.
Observed behavior
Seeking the exact storage location and query method for logs showing applications accessing mailboxes (rather than users accessing applications).
Before you start

Ensure you have the appropriate administrative roles, such as Global Administrator or Compliance Administrator, and verify that mailbox auditing is enabled across your Microsoft 365 tenant.

Solution 1Recommended

Review Microsoft Purview Audit and Entra ID Sign-in Logs

Track application-based mailbox access by querying the unified audit log in Microsoft Purview and cross-referencing workload identities in Microsoft Entra.

To view events where an application accessed a user's mailbox, you must utilize Microsoft 365's unified auditing tools rather than standard user sign-in logs.

1
Access Microsoft Purview

Navigate to the Microsoft Purview compliance portal and log in with your global or compliance administrator credentials.

2
Configure the Audit Search

Go to the Audit section from the left-hand navigation pane. Set the date and time range for the previous 24 to 48 hours.

3
Filter by Exchange Mailbox Activities

In the 'Activities' dropdown, select Exchange mailbox activities. You can further filter the results by inputting the specific Azure application's App ID or Object ID to isolate its actions.

4
Check Microsoft Entra Workload Logs

Open the Microsoft Entra admin center, go to 'Sign-in logs', and switch to the 'Service principal sign-ins' tab. This will confirm when the application authenticated and acquired a token to access Exchange Online.

Review Microsoft Purview Audit and Entra ID Sign-in Logs
Log Analytics Integration: If you have diagnostic settings configured, these workload sign-ins and Microsoft 365 audit events may be exported directly to an Azure Log Analytics workspace, where you can query them using Kusto Query Language (KQL).
Free Microsoft Office alternative

Looking for a Simpler, Lighter Office Suite? Try WPS Office

Managing Microsoft 365, Azure, and Exchange compliance can be highly complex and resource-intensive. If you need a straightforward, fast, and free productivity suite for your daily document tasks without the enterprise overhead, WPS Office is an excellent alternative.

  1. 1. Download WPS Office: Visit the official WPS Office website and click the free download button for your operating system.
  2. 2. Install the Suite: Run the installer and follow the on-screen prompts to complete the lightweight installation process.
  3. 3. Open Your Office Files: Launch WPS Office and seamlessly open any existing Microsoft Word, Excel, or PowerPoint files without losing formatting.
Fully compatible with Microsoft Word, Excel, and PowerPoint files (.docx, .xlsx, .pptx).Lightweight installation that consumes minimal system resources compared to full enterprise suites.All-in-one tabbed interface for Writer, Spreadsheets, Presentation, and PDF.Free to use for everyday document creation, editing, and sharing tasks.
microsoft office alternative - wps office

Frequently Asked Questions

Why can't I see mailbox access logs for my Azure application in Purview?

You must ensure that mailbox auditing is enabled by default in Exchange Online. Additionally, specific actions (such as MailboxLogin or ItemBind) must be configured to be logged for the target mailboxes; otherwise, the application's access events will not be recorded.

Are application sign-in logs the same as mailbox access logs?

No. Microsoft Entra service principal sign-in logs only show when the application successfully authenticated to Azure AD to get an access token. They do not show which specific mailboxes or emails the application interacted with using that token. For that, you need the Purview unified audit logs.

Can I query application mailbox access directly using Azure Log Analytics?

Yes, but only if you have proactively configured diagnostic settings to route your Microsoft Entra workload identity logs and your Microsoft 365 audit logs into your Log Analytics workspace. Once routed, you can use Kusto Query Language (KQL) to filter for specific app access events.