How to Audit When Exchange Online Mailbox Permissions Were Granted
Question details
Administrators need to generate a report detailing when Exchange Online mailbox permissions (Full Access, Send As, Send on Behalf) were granted, including the date, user, and mailbox.

- Product
- Exchange Online
- Device & OS
- not provided
- Scenario
- Tracking and auditing mailbox permission changes for compliance and security monitoring.
- Observed behavior
- Extracting specific timestamps and permission types from Exchange Online audit data using PowerShell commands.
Ensure you have Exchange Administrator credentials and verify that unified auditing is actively enabled for your Microsoft 365 tenant before attempting to run audit scripts.
Use Exchange Online PowerShell Audit Commands
Leverage Exchange Online PowerShell to search audit logs for specific mailbox permission changes.
Because exact audit commands depend heavily on your tenant configuration, auditing retention policies, and specific output requirements, utilizing specialized PowerShell cmdlets is the most effective approach for retrieving these records.
Open PowerShell as an administrator and connect to Exchange Online PowerShell using your admin credentials.
Run the `Search-UnifiedAuditLog` cmdlet, filtering for operations like 'Add-MailboxPermission' (for Full Access) or 'Add-RecipientPermission' (for Send As).
Pipe your results to display or export the creation date, the user who granted the permission, the target mailbox, and the specific permission type applied.
For exact scripting tailored to your date range, tenant environment, and required output fields, post your request in the Microsoft Q&A PowerShell community at https://learn.microsoft.com/en-us/answers/tags/426/powershell.

Looking for a Lightweight Alternative to Microsoft Office?
While managing Exchange Online requires Microsoft administration tools, your daily document and compliance reporting tasks don't have to be tied to expensive Office subscriptions. WPS Office provides a free, highly compatible, and lightweight suite for all your Word, Excel, and PowerPoint needs.
- 1. Download the Installer: Visit the official WPS Office website and click the free download button for your operating system.
- 2. Install the Suite: Run the downloaded executable file and follow the on-screen instructions to install the software.
- 3. Open Your Reports: Launch WPS Spreadsheet to instantly open and analyze your exported Exchange Online audit CSV files.

Frequently Asked Questions
Why can't I see older mailbox permission changes in my audit logs?
By default, Microsoft 365 retains audit logs for a limited time (often 90 to 180 days, depending on your licensing). If the permission was granted before this retention period, it will no longer appear in the audit search results.
Do I need special permissions to run Exchange Online audit scripts?
Yes, you must be assigned the View-Only Audit Logs or Audit Logs role in Exchange Online. These roles are typically granted to Global Administrators or Compliance Administrators by default.
What is the difference between Add-MailboxPermission and Add-RecipientPermission in the logs?
The 'Add-MailboxPermission' operation is generally used to log when Full Access rights are granted to a mailbox, whereas 'Add-RecipientPermission' is specifically logged when 'Send As' rights are assigned.




