logo
search
Compliance Problems

How to Audit Exchange Public Folders and Compliance Mailboxes

Nimra MalikNimra Malik Sep 30, 2026 868 views

Question details

The user needs to know how to properly configure and run audit logs for Exchange public folders and compliance mailboxes to track administrative and user actions.

How to Audit Exchange Public Folders and Compliance Mailboxes
Product
Microsoft Exchange / Microsoft Purview
Device & OS
not provided
Scenario
Tracking reads, writes, and deletions in Exchange public folders and compliance mailboxes for security, administrative, or compliance auditing purposes.
Observed behavior
Audit results may appear missing or empty if logging is disabled, specific actions are not configured, user permissions are insufficient, or the search range excludes the events.
Before you start

Ensure you have the necessary administrator permissions in the Microsoft Purview Compliance portal and that your Exchange server is fully updated before attempting to configure audit logs.

Solution 1Recommended

Enable and Configure Audit Logging in Microsoft Purview

The primary method to track activities in Exchange public folders and compliance mailboxes is by enabling organization-wide audit logging and defining specific actions to track.

By default, some auditing features might be disabled or not configured to track specific actions like reads or deletions. You must manually define these parameters in the Microsoft Purview portal for both public folders and individual compliance mailboxes.

1
Enable organization-wide audit logging

Log in to the Microsoft Purview Compliance portal, navigate to the Audit section, and verify that organization-wide auditing is turned on to begin capturing event data.

2
Configure public-folder actions

Select the target public folders in your Exchange admin center or via PowerShell, and configure the audit properties to track specific actions such as folder reads, writes, and deletions.

3
Configure compliance mailboxes

Apply the necessary audit settings separately for each individual compliance mailbox that requires monitoring, as global settings may not automatically apply granular tracking to these specific mailboxes.

4
Run audit reports

Return to the Audit search tool in Microsoft Purview, specify the correct date range, select the relevant activities or folders, and run the search to view the generated logs.

Enable and Configure Audit Logging in Microsoft Purview
Permission Check: If results are missing, verify that your administrator account possesses the required Exchange Role-Based Access Control (RBAC) permissions to view audit logs.
Free Microsoft Office alternative

Looking for a Lightweight Office Suite Alternative?

While Microsoft Exchange handles complex server and compliance tasks, managing your daily documents doesn't have to be complicated. WPS Office provides a free, highly compatible, and lightweight alternative to Microsoft Office for creating, editing, and sharing documents effortlessly.

  1. 1. Download WPS Office: Visit the official WPS website and download the free installation package for your operating system.
  2. 2. Install the Software: Run the installer and follow the on-screen instructions to quickly set up the office suite on your device.
  3. 3. Open Your Files: Double-click any existing Microsoft Word, Excel, or PowerPoint files to open and edit them seamlessly in WPS Office.
Fully compatible with Microsoft Office formats including .docx, .xlsx, and .pptx.Free and lightweight, consuming minimal system resources.Familiar user interface for seamless and immediate migration.Built-in PDF editor and comprehensive document management tools.
microsoft office alternative - wps office

Frequently Asked Questions

Why are my Exchange audit log search results completely empty?

This usually happens if organization-wide auditing is disabled, the specific public-folder actions (like reads or writes) haven't been configured, or the selected date range excludes the events you are trying to find.

Do I need to configure auditing for each compliance mailbox individually?

Yes, to ensure accurate and granular tracking, audit settings must be configured separately for each specific compliance mailbox that requires monitoring.

What permissions are required to run audit reports in Microsoft Purview?

You must be assigned the appropriate Role-Based Access Control (RBAC) permissions, such as the View-Only Audit Logs or Audit Logs role in Exchange Online, to search and view audit reports.