MailItemsAccessed Woes: M365 Investigation Challenges
ID: adfec3a4-f0b6-501f-9790-ccba056bbd83
STIX ID: report--adfec3a4-f0b6-501f-9790-ccba056bbd83
Feed Name: TrustedSec blog
This report explains how Microsoft 365 audit data can — and cannot — reveal which emails an attacker accessed during an account compromise. It emphasizes that MailItemsAccessed events (which give direct evidence of accessed emails) are only available with Microsoft Purview Audit (Premium) licenses (E5 or equivalent add-ons), cannot be retroactively obtained, and that Mailbox Audit Logs provide limited, partial visibility through events like Create and Update; practical recommendations include assigning E5 to high-risk users and understanding audit limitations during investigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
