Getting to know Exchange 2019 - Part Thirty seven (2024)

Auditing in Microsoft Exchange 2019

Introduction: Auditing in Microsoft Exchange 2019 provides administrators with the capability to track and monitor various activities within the Exchange organization. This includes changes made by administrators as well as access to and modifications of individual mailboxes. Two primary auditing options are available: Administrator audit logging and Mailbox audit logging.

Administrator Audit Logging: Administrator audit logging enables the tracking of administrative changes within the Exchange organization. This includes who performed the action, what action was taken, and where the action occurred. By default, administrator audit logging is enabled and logs are stored in the Microsoft Exchange System Mailbox.

To disable administrator audit logging:

Set-AdminAuditLogConfig -AdminAuditLogEnabled $False

To enable administrator audit logging:

Set-AdminAuditLogConfig -AdminAuditLogEnabled $True

Customizing Administrator Audit Logging: Administrators can customize the logging settings to include or exclude specific cmdlets and parameters. For example, to limit logging to specific cmdlets:

Set-AdminAuditLogConfig –AdminAuditLogCmdlets “New-Mailbox”,”Remove-Mailbox”

To exclude certain cmdlets from logging:

Set-AdminAuditLogConfig -AdminAuditLogExcludedCmdlets "Set-Mailbox"

Additionally, specific parameters such as Name, Identity, Windows Email Address, and Email Address can be logged:

Set-AdminAuditLogConfig –AdminAuditLogParameters “Name”, “Identity”, “WindowsEmailAddress”, “EmailAddresses”

Mailbox Audit Logging: Mailbox audit logging allows tracking of access to and modifications of individual mailboxes. This is particularly useful for monitoring sensitive mailboxes. Audit logging for a specific mailbox can be enabled or disabled using EMS: To enable mailbox audit logging:

Set-Mailbox –Identity “MailboxName” –AuditEnabled $True

To disable mailbox audit logging:

Set-Mailbox –Identity “MailboxName” –AuditEnabled $False

Customizing Mailbox Audit Logging: Similar to administrator audit logging, mailbox audit logging can be customized based on the type of activity and the accessing account (Administrator, Delegate, or Owner). Specific activities can be included or excluded from logging based on cmdlets and parameters.

Conclusion: Auditing in Microsoft Exchange 2019 provides essential capabilities for tracking and monitoring administrative actions and mailbox access. By enabling and customizing audit logging, organizations can ensure security and compliance with regulatory requirements. Administrators should regularly review audit logs to identify and mitigate potential security risks.

Activity Types and Access Permissions in Mailbox Audit Logging

In mailbox audit logging, different types of activities are logged based on the access permissions of administrators, delegates, and owners. The following table outlines various activities and their corresponding permissions:

| Activity Type | Administrator | Delegate | Owner |

|----------------------------------------------------|---------------|----------|---------|

| Copying an Item to another folder | Yes | No | No |

| Creating an Item (excluding folder creation) | Yes | Yes | Yes |

| Accessing a folder | Yes | Yes | No |

| Permanent deletion of an Item (Hard Delete) | Yes | Yes | Yes |

| Accessing an Item | Yes | No | No |

| Moving an Item to another folder | Yes | Yes | Yes |

| Deleting an Item (Moved to Deleted Items folder) | Yes | Yes | Yes |

| Sending an email using Send As Permission | Yes | Yes | - |

| Sending an email using Send On Behalf Permission | Yes | Yes | - |

| Moving an Item from Deleted Items to Recoverable Items | Yes | Yes | Yes |

| Updating Item properties | Yes | Yes | Yes |

Note: "-" indicates that the action is not applicable to the Owner role.

These permissions dictate which actions are logged for each role in mailbox audit logging. By analyzing audit logs, administrators can track and monitor user activities to ensure compliance and security within the Exchange environment.

By default, mailbox auditing in Microsoft Exchange retains audit logs for up to 90 days. If you need to change this period (e.g., to 180 days) for a specific mailbox (e.g., "Info"), you can use the following cmdlet:

Set-Mailbox –Identity “Info” –AuditLogAgeLimit 180.00:00:00

Searching Mailbox Audit Logs: To access information recorded by mailbox audit logging:

  1. Go to EAC (Exchange Admin Center) -> Compliance management -> Auditing tab.
  2. Select either "Run a non-owner mailbox access report" or "Export mailbox audit logs."

Note on Running a Non-Owner Mailbox Access Report: The option "Run a non-owner mailbox access report" is used to create a report for cases where the login user is not the owner of the mailbox. If you need to create a report for cases where the login user is the owner, you must use Exchange Management Shell (EMS).

Note on External Users: If you select "External Users" after choosing the "Run a non-owner mailbox access report" option, it means an administrator in Exchange Online or Office 365.

Getting to know Exchange 2019 - Part Thirty seven (2024)
Top Articles
Are libraries still a thing? Why it will survive in a digital age - How To Be Books
Contact - How to Contact Us
Enrique Espinosa Melendez Obituary
What Happened To Dr Ray On Dr Pol
Gore Videos Uncensored
1movierulzhd.fun Reviews | scam, legit or safe check | Scamadviser
Top Financial Advisors in the U.S.
Melfme
Stream UFC Videos on Watch ESPN - ESPN
A.e.a.o.n.m.s
Chastity Brainwash
Evangeline Downs Racetrack Entries
Alaska: Lockruf der Wildnis
Calmspirits Clapper
Nwi Arrests Lake County
Teenleaks Discord
Find Such That The Following Matrix Is Singular.
Nick Pulos Height, Age, Net Worth, Girlfriend, Stunt Actor
Accuweather Mold Count
Ups Print Store Near Me
The Weather Channel Local Weather Forecast
Talk To Me Showtimes Near Marcus Valley Grand Cinema
Gina Wilson Angle Addition Postulate
Gen 50 Kjv
Aes Salt Lake City Showdown
4.231 Rounded To The Nearest Hundred
Taylored Services Hardeeville Sc
Bj's Tires Near Me
Math Minor Umn
Most popular Indian web series of 2022 (so far) as per IMDb: Rocket Boys, Panchayat, Mai in top 10
Tamilyogi Ponniyin Selvan
Asian Grocery Williamsburg Va
Craigs List Stockton
Überblick zum Barotrauma - Überblick zum Barotrauma - MSD Manual Profi-Ausgabe
Sun Tracker Pontoon Wiring Diagram
Best Restaurants West Bend
Alpha Labs Male Enhancement – Complete Reviews And Guide
Willkommen an der Uni Würzburg | WueStart
3367164101
Race Deepwoken
Online TikTok Voice Generator | Accurate & Realistic
Craigslist Free Cats Near Me
Diamond Desires Nyc
2000 Fortnite Symbols
28 Mm Zwart Spaanplaat Gemelamineerd (U999 ST9 Matte | RAL9005) Op Maat | Zagen Op Mm + ABS Kantenband
Frank 26 Forum
Bob Wright Yukon Accident
Saw X (2023) | Film, Trailer, Kritik
Honeybee: Classification, Morphology, Types, and Lifecycle
Supervisor-Managing Your Teams Risk – 3455 questions with correct answers
Latest Posts
Article information

Author: Kareem Mueller DO

Last Updated:

Views: 5854

Rating: 4.6 / 5 (66 voted)

Reviews: 89% of readers found this page helpful

Author information

Name: Kareem Mueller DO

Birthday: 1997-01-04

Address: Apt. 156 12935 Runolfsdottir Mission, Greenfort, MN 74384-6749

Phone: +16704982844747

Job: Corporate Administration Planner

Hobby: Mountain biking, Jewelry making, Stone skipping, Lacemaking, Knife making, Scrapbooking, Letterboxing

Introduction: My name is Kareem Mueller DO, I am a vivacious, super, thoughtful, excited, handsome, beautiful, combative person who loves writing and wants to share my knowledge and understanding with you.