logo

MailItemsAccessed Woes: M365 Investigation Challenges

ID: adfec3a4-f0b6-501f-9790-ccba056bbd83

STIX ID: report--adfec3a4-f0b6-501f-9790-ccba056bbd83

Feed Name: TrustedSec blog

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This report explains how Microsoft 365 audit data can — and cannot — reveal which emails an attacker accessed during an account compromise. It emphasizes that MailItemsAccessed events (which give direct evidence of accessed emails) are only available with Microsoft Purview Audit (Premium) licenses (E5 or equivalent add-ons), cannot be retroactively obtained, and that Mailbox Audit Logs provide limited, partial visibility through events like Create and Update; practical recommendations include assigning E5 to high-risk users and understanding audit limitations during investigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.