logo
search
Compliance Problems

How to Audit When Exchange Online Mailbox Permissions Were Granted

Ayan MasoodAyan Masood Oct 9, 2026 869 views

Question details

Administrators need to generate a report detailing when Exchange Online mailbox permissions (Full Access, Send As, Send on Behalf) were granted, including the date, user, and mailbox.

How to Audit When Exchange Online Mailbox Permissions Were Granted
Product
Exchange Online
Device & OS
not provided
Scenario
Tracking and auditing mailbox permission changes for compliance and security monitoring.
Observed behavior
Extracting specific timestamps and permission types from Exchange Online audit data using PowerShell commands.
Before you start

Ensure you have Exchange Administrator credentials and verify that unified auditing is actively enabled for your Microsoft 365 tenant before attempting to run audit scripts.

Solution 1Recommended

Use Exchange Online PowerShell Audit Commands

Leverage Exchange Online PowerShell to search audit logs for specific mailbox permission changes.

Because exact audit commands depend heavily on your tenant configuration, auditing retention policies, and specific output requirements, utilizing specialized PowerShell cmdlets is the most effective approach for retrieving these records.

1
Connect to PowerShell

Open PowerShell as an administrator and connect to Exchange Online PowerShell using your admin credentials.

2
Search the Unified Audit Log

Run the `Search-UnifiedAuditLog` cmdlet, filtering for operations like 'Add-MailboxPermission' (for Full Access) or 'Add-RecipientPermission' (for Send As).

3
Format the Report Output

Pipe your results to display or export the creation date, the user who granted the permission, the target mailbox, and the specific permission type applied.

4
Request Custom Script Assistance

For exact scripting tailored to your date range, tenant environment, and required output fields, post your request in the Microsoft Q&A PowerShell community at https://learn.microsoft.com/en-us/answers/tags/426/powershell.

Use Exchange Online PowerShell Audit Commands
Audit Log Retention Limits: Keep in mind that audit log entries are only available for the duration of your tenant's retention policy, which typically ranges from 90 days to 1 year depending on your Microsoft 365 licensing.
Free Microsoft Office alternative

Looking for a Lightweight Alternative to Microsoft Office?

While managing Exchange Online requires Microsoft administration tools, your daily document and compliance reporting tasks don't have to be tied to expensive Office subscriptions. WPS Office provides a free, highly compatible, and lightweight suite for all your Word, Excel, and PowerPoint needs.

  1. 1. Download the Installer: Visit the official WPS Office website and click the free download button for your operating system.
  2. 2. Install the Suite: Run the downloaded executable file and follow the on-screen instructions to install the software.
  3. 3. Open Your Reports: Launch WPS Spreadsheet to instantly open and analyze your exported Exchange Online audit CSV files.
Fully compatible with Microsoft Office formats like .docx, .xlsx, and .pptx.Easily format and analyze your exported PowerShell CSV audit reports using WPS Spreadsheet.Lightweight installation with a familiar, easy-to-use interface.Completely free core features, enabling seamless migration for individuals and enterprises.
microsoft office alternative - wps office

Frequently Asked Questions

Why can't I see older mailbox permission changes in my audit logs?

By default, Microsoft 365 retains audit logs for a limited time (often 90 to 180 days, depending on your licensing). If the permission was granted before this retention period, it will no longer appear in the audit search results.

Do I need special permissions to run Exchange Online audit scripts?

Yes, you must be assigned the View-Only Audit Logs or Audit Logs role in Exchange Online. These roles are typically granted to Global Administrators or Compliance Administrators by default.

What is the difference between Add-MailboxPermission and Add-RecipientPermission in the logs?

The 'Add-MailboxPermission' operation is generally used to log when Full Access rights are granted to a mailbox, whereas 'Add-RecipientPermission' is specifically logged when 'Send As' rights are assigned.