logo
search
Compliance Problems

How to Audit MailItemsAccessed for Shared Mailboxes in Microsoft 365

Rana GarciaRana Garcia Sep 30, 2026 868 views

Question details

Users need to retrieve MailItemsAccessed audit records for shared mailboxes in Microsoft 365 to monitor mailbox access.

How to Audit MailItemsAccessed for Shared Mailboxes in Microsoft 365
Product
Microsoft 365
Device & OS
not provided
Scenario
Administrators are attempting to query audit logs to verify who accessed specific shared mailboxes for compliance and security purposes.
Observed behavior
MailItemsAccessed audit logs are successfully returned for standard user mailboxes but appear to be missing or inaccessible for shared mailboxes.
Before you start

Ensure you have the necessary Exchange Online and compliance administrator permissions assigned, and verify that unified auditing is actively enabled for your Microsoft 365 tenant.

Solution 1Recommended

Verify Licensing and Run Unified Audit Log Search

Confirm the shared mailbox has the correct compliance licensing and use the Search-UnifiedAuditLog cmdlet instead of legacy commands.

The legacy Search-MailboxAuditLog cmdlet is deprecated and may not return accurate MailItemsAccessed events. Microsoft requires specific premium licenses to log these events, and all searches should now be conducted using the unified audit log.

1
Verify Compliance Licensing

Check the Microsoft 365 admin center to ensure the shared mailbox access is covered by an eligible Microsoft 365 E5, A5, G5, or a qualifying compliance add-on license.

2
Connect to Exchange Online

Open PowerShell as an administrator and connect to Exchange Online using the Connect-ExchangeOnline cmdlet with your admin credentials.

3
Execute Search-UnifiedAuditLog

Run the Search-UnifiedAuditLog cmdlet using ExchangeItem records. Specify the shared mailbox address, the required date range, and the applicable logon types.

4
Export and Review Results

Pipe the output of your unified audit log search to Export-Csv to save the MailItemsAccessed records locally for detailed compliance review.

Verify Licensing and Run Unified Audit Log Search
Audit Ingestion Delays: It can take several hours for new mailbox access events to be processed. Allow up to 24 hours for audit events to appear in the unified audit log.
Free Microsoft Office alternative

Simplify Your Daily Document Work with WPS Office

While managing Microsoft 365 compliance rules and audit logs can be highly complex, your standard document management doesn't have to be. WPS Office offers a lightweight, free, and highly compatible alternative to Microsoft Office applications.

  1. 1. Download the Installer: Visit the official WPS Office website and click the free download button for your operating system.
  2. 2. Install the Suite: Run the lightweight installer and follow the on-screen instructions to complete the setup in minutes.
  3. 3. Open Your Office Files: Launch WPS Office and directly open your existing Microsoft Office documents without worrying about formatting issues.
Fully compatible with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx)Lightweight design ensuring fast installation and rapid startup timesFamiliar user interface requiring zero learning curve for seamless migrationRobust built-in PDF editing, signing, and conversion tools
microsoft office alternative - wps office

Frequently Asked Questions

Why is the Search-MailboxAuditLog cmdlet returning empty results?

The Search-MailboxAuditLog cmdlet is deprecated by Microsoft. You must transition to using the Search-UnifiedAuditLog cmdlet to reliably retrieve current MailItemsAccessed and other mailbox audit records.

Do I need a special license to audit shared mailboxes?

Yes, to generate and log MailItemsAccessed events, the shared mailbox must be licensed with an eligible Microsoft 365 E5, A5, G5, or a specific advanced compliance add-on.

How long does it take for MailItemsAccessed events to show up?

Due to processing and ingestion times in Microsoft 365, audit events may experience a delay. It is recommended to wait up to 24 hours after the access occurred for the events to be fully searchable in the unified audit log.