Microsoft 365How-To & HardeningRetrospectives

How to Enable Expanded Audit Logging to Detect Mailbox Access

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from July 2023, written in 2026 with the benefit of hindsight.

Storm-0558 was detected because a customer had detailed mailbox access logs. Here is how to make sure your Microsoft 365 audit logging captures what you'd need in a similar investigation.

Step 1: Confirm the unified audit log is on

Connect-ExchangeOnline
Get-AdminAuditLogConfig | Format-List UnifiedAuditLogIngestionEnabled

It should be True. It's on by default in most tenants, but confirm.

Step 2: Confirm mailbox auditing

Mailbox auditing is on by default. Confirm it hasn't been disabled at the organization level:

Get-OrganizationConfig | Format-List AuditDisabled

AuditDisabled should be False.

Step 3: Check which mailbox actions are logged

Following Storm-0558, Microsoft expanded logging available to standard licenses, including MailItemsAccessed and other events previously limited to premium audit. Review the default audit actions for owner, delegate and admin access, and add actions you need (for example, MailItemsAccessed, Send, SearchQueryInitiated where available).

Step 4: Set retention

Standard audit retention is 180 days. Microsoft Purview Audit (Premium) offers one-year retention by default and longer with add-ons. Alternatively, export audit logs to Microsoft Sentinel or another SIEM with longer retention.

Step 5: Stream to your SIEM

Connect the Microsoft 365 (Office 365) data connector to Sentinel, plus Defender XDR's advanced hunting tables (CloudAppEvents) for richer detail.

Step 6: Practice using it

Run a test investigation: "Which mailboxes did this account access last week, from which IPs?" If you can't answer quickly, adjust logging or retention.

microsoft purview audit premiumStorm-05582023

More on this story