WorkMail

eventNameDescriptionSampleRule
anyCatch-all entry for WorkMail rules that match the service but not a specific eventName.NN
AssociateDelegateToResourceAdds a member (user or group) to the resource's set of delegates.NN
AssociateMemberToGroupAdds a member (user or group) to the group's set.NN
AssumeImpersonationRoleAssumes an impersonation role for the given WorkMail organization.NN
CancelMailboxExportJobCancels a mailbox export job.NN
CreateAliasAdds an alias to the set of a given member (user or group) of WorkMail.NN
CreateAvailabilityConfigurationCreates an AvailabilityConfiguration for the given WorkMail organization and domain.NN
CreateGroupCreates a group that can be used in WorkMail by calling the RegisterToWorkMail operation.NY
CreateIdentityCenterApplicationCreates the WorkMail application in IAM Identity Center that can be used later in the WorkMail - IdC integration.NN
CreateImpersonationRoleCreates an impersonation role for the given WorkMail organization.NN
CreateMobileDeviceAccessRuleCreates a new mobile device access rule for the specified WorkMail organization.NN
CreateOrganizationCreates a new WorkMail organization.YY
CreateResourceCreates a new WorkMail resource.NN
CreateUserCreates a user who can be used in WorkMail by calling the RegisterToWorkMail operation.NY
DeleteAccessControlRuleDeletes an access control rule for the specified WorkMail organization.NN
DeleteAliasRemove one or more specified aliases from a set of aliases for a given user.NN
DeleteAvailabilityConfigurationDeletes the AvailabilityConfiguration for the given WorkMail organization and domain.NN
DeleteEmailMonitoringConfigurationDeletes the email monitoring configuration for a specified organization.NN
DeleteGroupDeletes a group from WorkMail.NY
DeleteIdentityCenterApplicationDeletes the IAM Identity Center application from WorkMail.NN
DeleteIdentityProviderConfigurationDisables the integration between IdC and WorkMail.NN
DeleteImpersonationRoleDeletes an impersonation role for the given WorkMail organization.NN
DeleteMailboxPermissionsDeletes permissions granted to a member (user or group).NN
DeleteMobileDeviceAccessOverrideDeletes the mobile device access override for the given WorkMail organization, user, and device.NN
DeleteMobileDeviceAccessRuleDeletes a mobile device access rule for the specified WorkMail organization.NN
DeleteOrganizationDeletes an WorkMail organization and all underlying AWS resources managed by WorkMail as part of the organization.NN
DeletePersonalAccessTokenDeletes the Personal Access Token from the provided WorkMail Organization.NN
DeleteResourceDeletes the specified resource.NN
DeleteRetentionPolicyDeletes the specified retention policy from the specified organization.NN
DeleteUserDeletes a user from WorkMail and all subsequent systems.NY
DeregisterFromWorkMailMark a user, group, or resource as no longer used in WorkMail.NN
DeregisterMailDomainRemoves a domain from WorkMail, stops email routing to WorkMail, and removes the authorization allowing WorkMail use.NN
DescribeEmailMonitoringConfigurationDescribes the current email monitoring configuration for a specified organization.NN
DescribeEntityReturns basic details about an entity in WorkMail.NN
DescribeGroupReturns the data available for the group.NN
DescribeIdentityProviderConfigurationReturns detailed information on the current IdC setup for the WorkMail organization.NN
DescribeInboundDmarcSettingsLists the settings in a DMARC policy for a specified organization.NN
DescribeMailboxExportJobDescribes the current status of a mailbox export job.NN
DescribeOrganizationProvides more information regarding a given organization based on its identifier.NN
DescribeResourceReturns the data available for the resource.NN
DescribeUserProvides information regarding the user.NN
DisassociateDelegateFromResourceRemoves a member from the resource's set of delegates.NN
DisassociateMemberFromGroupRemoves a member from a group.NN
GetAccessControlEffectGets the effects of an organization's access control rules as they apply to a specified IPv4 address, access protocol action, and user ID or impersonation role ID.NN
GetDefaultRetentionPolicyGets the default retention policy details for the specified organization.NN
GetImpersonationRoleGets the impersonation role details for the given WorkMail organization.NN
GetImpersonationRoleEffectTests whether the given impersonation role can impersonate a target user.NN
GetMailboxDetailsRequests a user's mailbox details for a specified organization and user.NN
GetMailDomainGets details for a mail domain, including domain records required to configure your domain with recommended security.NN
GetMobileDeviceAccessEffectSimulates the effect of the mobile device access rules for the given attributes of a sample access event.NN
GetMobileDeviceAccessOverrideGets the mobile device access override for the given WorkMail organization, user, and device.NN
GetPersonalAccessTokenMetadataRequests details of a specific Personal Access Token within the WorkMail organization.NN
ListAccessControlRulesLists the access control rules for the specified organization.NN
ListAliasesCreates a paginated call to list the aliases associated with a given entity.NN
ListAvailabilityConfigurationsList all the AvailabilityConfiguration's for the given WorkMail organization.NN
ListGroupMembersReturns an overview of the members of a group.NN
ListGroupsReturns summaries of the organization's groups.NN
ListGroupsForEntityReturns all the groups to which an entity belongs.NN
ListImpersonationRolesLists all the impersonation roles for the given WorkMail organization.NN
ListMailboxExportJobsLists the mailbox export jobs started for the specified organization within the last seven days.NN
ListMailboxPermissionsLists the mailbox permissions associated with a user, group, or resource mailbox.NN
ListMailDomainsLists the mail domains in a given WorkMail organization.NN
ListMobileDeviceAccessOverridesLists all the mobile device access overrides for any given combination of WorkMail organization, user, or device.NN
ListMobileDeviceAccessRulesLists the mobile device access rules for the specified WorkMail organization.NN
ListOrganizationsReturns summaries of the customer's organizations.YN
ListPersonalAccessTokensReturns a summary of your Personal Access Tokens.NN
ListResourceDelegatesLists the delegates associated with a resource.NN
ListResourcesReturns summaries of the organization's resources.NN
ListTagsForResourceLists the tags applied to an WorkMail organization resource.NN
ListUsersReturns summaries of the organization's users.NN
PutAccessControlRuleAdds a new access control rule for the specified organization.NN
PutEmailMonitoringConfigurationCreates or updates the email monitoring configuration for a specified organization.NN
PutIdentityProviderConfigurationEnables integration between IAM Identity Center (IdC) and WorkMail to proxy authentication requests for mailbox users.NN
PutInboundDmarcSettingsEnables or disables a DMARC policy for a given organization.NN
PutMailboxPermissionsSets permissions for a user, group, or resource.NN
PutMobileDeviceAccessOverrideCreates or updates a mobile device access override for the given WorkMail organization, user, and device.NN
PutRetentionPolicyPuts a retention policy to the specified organization.NN
RegisterMailDomainRegisters a new domain in WorkMail and SES, and configures it for use by WorkMail.NN
RegisterToWorkMailRegisters an existing and disabled user, group, or resource for WorkMail use by associating a mailbox and calendaring capabilities.NY
ResetPasswordAllows the administrator to reset the password for a user.NY
StartMailboxExportJobStarts a mailbox export job to export MIME-format email messages and calendar items from the specified mailbox to the specified Amazon Simple Storage Service (Amazon S3) bucket.NN
TagResourceApplies the specified tags to the specified WorkMailorganization resource.NN
TestAvailabilityConfigurationPerforms a test on an availability provider to ensure that access is allowed.NN
UntagResourceUntags the specified tags from the specified WorkMail organization resource.NN
UpdateAvailabilityConfigurationUpdates an existing AvailabilityConfiguration for the given WorkMail organization and domain.NN
UpdateDefaultMailDomainUpdates the default mail domain for an organization.NN
UpdateGroupUpdates attributes in a group.NN
UpdateImpersonationRoleUpdates an impersonation role for the given WorkMail organization.NN
UpdateMailboxQuotaUpdates a user's current mailbox quota for a specified organization and user.NN
UpdateMobileDeviceAccessRuleUpdates a mobile device access rule for the specified WorkMail organization.NN
UpdatePrimaryEmailAddressUpdates the primary email for a user, group, or resource.NN
UpdateResourceUpdates data for the resource.NN
UpdateUserUpdates data for the user.NN

any: WorkMail (catch-all)

#
Service
workmail

Description

Catch-all entry for WorkMail rules that match the service but not a specific eventName.

AssociateDelegateToResource

#
Service
workmail

Description

Adds a member (user or group) to the resource's set of delegates.

AssociateMemberToGroup

#
Service
workmail

Description

Adds a member (user or group) to the group's set.

AssumeImpersonationRole

#
Service
workmail

Description

Assumes an impersonation role for the given WorkMail organization.

CancelMailboxExportJob

#
Service
workmail

Description

Cancels a mailbox export job.

CreateAlias

#
Service
workmail

Description

Adds an alias to the set of a given member (user or group) of WorkMail.

CreateAvailabilityConfiguration

#
Service
workmail

Description

Creates an AvailabilityConfiguration for the given WorkMail organization and domain.

CreateGroup

#
Service
workmail

Description

Creates a group that can be used in WorkMail by calling the RegisterToWorkMail operation.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

CreateIdentityCenterApplication

#
Service
workmail

Description

Creates the WorkMail application in IAM Identity Center that can be used later in the WorkMail - IdC integration.

CreateImpersonationRole

#
Service
workmail

Description

Creates an impersonation role for the given WorkMail organization.

CreateMobileDeviceAccessRule

#
Service
workmail

Description

Creates a new mobile device access rule for the specified WorkMail organization.

CreateOrganization

#
Service
workmail

Description

Creates a new WorkMail organization.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "LimitExceededException",
  "errorMessage": "On March 31, 2027, AWS will discontinue support for Amazon WorkMail. After April 30, 2026, new customers will no longer be able to create new Amazon WorkMail organizations. For more information, see https://docs.aws.amazon.com/workmail/latest/adminguide/workmail-end-of-support.html",
  "eventCategory": "Management",
  "eventID": "221bdfdd-a2ad-47e2-a7c7-47e50ce02ff2",
  "eventName": "CreateOrganization",
  "eventSource": "workmail.amazonaws.com",
  "eventTime": "2026-06-29T21:50:07Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "3fe91327-280e-4a21-8180-d3accadfa6b9",
  "requestParameters": {
    "alias": "dwfixwm82769806c5e3b6",
    "clientToken": "1a7b27f5-7dad-4a63-baed-f608105ffb24",
    "enableInteroperability": false
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "workmail.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

CreateResource

#
Service
workmail

Description

Creates a new WorkMail resource.

CreateUser

#
Service
workmail

Description

Creates a user who can be used in WorkMail by calling the RegisterToWorkMail operation.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

DeleteAccessControlRule

#
Service
workmail

Description

Deletes an access control rule for the specified WorkMail organization.

DeleteAlias

#
Service
workmail

Description

Remove one or more specified aliases from a set of aliases for a given user.

DeleteAvailabilityConfiguration

#
Service
workmail

Description

Deletes the AvailabilityConfiguration for the given WorkMail organization and domain.

DeleteEmailMonitoringConfiguration

#
Service
workmail

Description

Deletes the email monitoring configuration for a specified organization.

DeleteGroup

#
Service
workmail

Description

Deletes a group from WorkMail.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

DeleteIdentityCenterApplication

#
Service
workmail

Description

Deletes the IAM Identity Center application from WorkMail.

DeleteIdentityProviderConfiguration

#
Service
workmail

Description

Disables the integration between IdC and WorkMail.

DeleteImpersonationRole

#
Service
workmail

Description

Deletes an impersonation role for the given WorkMail organization.

DeleteMailboxPermissions

#
Service
workmail

Description

Deletes permissions granted to a member (user or group).

DeleteMobileDeviceAccessOverride

#
Service
workmail

Description

Deletes the mobile device access override for the given WorkMail organization, user, and device.

DeleteMobileDeviceAccessRule

#
Service
workmail

Description

Deletes a mobile device access rule for the specified WorkMail organization.

DeleteOrganization

#
Service
workmail

Description

Deletes an WorkMail organization and all underlying AWS resources managed by WorkMail as part of the organization.

DeletePersonalAccessToken

#
Service
workmail

Description

Deletes the Personal Access Token from the provided WorkMail Organization.

DeleteResource

#
Service
workmail

Description

Deletes the specified resource.

DeleteRetentionPolicy

#
Service
workmail

Description

Deletes the specified retention policy from the specified organization.

DeleteUser

#
Service
workmail

Description

Deletes a user from WorkMail and all subsequent systems.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

DeregisterFromWorkMail

#
Service
workmail

Description

Mark a user, group, or resource as no longer used in WorkMail.

DeregisterMailDomain

#
Service
workmail

Description

Removes a domain from WorkMail, stops email routing to WorkMail, and removes the authorization allowing WorkMail use.

DescribeEmailMonitoringConfiguration

#
Service
workmail

Description

Describes the current email monitoring configuration for a specified organization.

DescribeEntity

#
Service
workmail

Description

Returns basic details about an entity in WorkMail.

DescribeGroup

#
Service
workmail

Description

Returns the data available for the group.

DescribeIdentityProviderConfiguration

#
Service
workmail

Description

Returns detailed information on the current IdC setup for the WorkMail organization.

DescribeInboundDmarcSettings

#
Service
workmail

Description

Lists the settings in a DMARC policy for a specified organization.

DescribeMailboxExportJob

#
Service
workmail

Description

Describes the current status of a mailbox export job.

DescribeOrganization

#
Service
workmail

Description

Provides more information regarding a given organization based on its identifier.

DescribeResource

#
Service
workmail

Description

Returns the data available for the resource.

DescribeUser

#
Service
workmail

Description

Provides information regarding the user.

DisassociateDelegateFromResource

#
Service
workmail

Description

Removes a member from the resource's set of delegates.

DisassociateMemberFromGroup

#
Service
workmail

Description

Removes a member from a group.

GetAccessControlEffect

#
Service
workmail

Description

Gets the effects of an organization's access control rules as they apply to a specified IPv4 address, access protocol action, and user ID or impersonation role ID.

GetDefaultRetentionPolicy

#
Service
workmail

Description

Gets the default retention policy details for the specified organization.

GetImpersonationRole

#
Service
workmail

Description

Gets the impersonation role details for the given WorkMail organization.

GetImpersonationRoleEffect

#
Service
workmail

Description

Tests whether the given impersonation role can impersonate a target user.

GetMailboxDetails

#
Service
workmail

Description

Requests a user's mailbox details for a specified organization and user.

GetMailDomain

#
Service
workmail

Description

Gets details for a mail domain, including domain records required to configure your domain with recommended security.

GetMobileDeviceAccessEffect

#
Service
workmail

Description

Simulates the effect of the mobile device access rules for the given attributes of a sample access event.

GetMobileDeviceAccessOverride

#
Service
workmail

Description

Gets the mobile device access override for the given WorkMail organization, user, and device.

GetPersonalAccessTokenMetadata

#
Service
workmail

Description

Requests details of a specific Personal Access Token within the WorkMail organization.

ListAccessControlRules

#
Service
workmail

Description

Lists the access control rules for the specified organization.

ListAliases

#
Service
workmail

Description

Creates a paginated call to list the aliases associated with a given entity.

ListAvailabilityConfigurations

#
Service
workmail

Description

List all the AvailabilityConfiguration's for the given WorkMail organization.

ListGroupMembers

#
Service
workmail

Description

Returns an overview of the members of a group.

ListGroups

#
Service
workmail

Description

Returns summaries of the organization's groups.

ListGroupsForEntity

#
Service
workmail

Description

Returns all the groups to which an entity belongs.

ListImpersonationRoles

#
Service
workmail

Description

Lists all the impersonation roles for the given WorkMail organization.

ListMailboxExportJobs

#
Service
workmail

Description

Lists the mailbox export jobs started for the specified organization within the last seven days.

ListMailboxPermissions

#
Service
workmail

Description

Lists the mailbox permissions associated with a user, group, or resource mailbox.

ListMailDomains

#
Service
workmail

Description

Lists the mail domains in a given WorkMail organization.

ListMobileDeviceAccessOverrides

#
Service
workmail

Description

Lists all the mobile device access overrides for any given combination of WorkMail organization, user, or device.

ListMobileDeviceAccessRules

#
Service
workmail

Description

Lists the mobile device access rules for the specified WorkMail organization.

ListOrganizations

#
Service
workmail

Description

Returns summaries of the customer's organizations.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: workmail:ListOrganizations",
  "eventID": "8d484b26-053a-4ab5-a69f-3bbff8f26a76",
  "eventName": "ListOrganizations",
  "eventSource": "workmail.amazonaws.com",
  "eventTime": "2019-03-07T21:20:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "cbdbe174-411e-11e9-83d2-197e7b1c9574",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "2.231.90.242",
  "userAgent": "Boto3/1.7.4 Python/3.7.2+ Linux/4.4.0-01985-Microsoft Botocore/1.10.4",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

ListPersonalAccessTokens

#
Service
workmail

Description

Returns a summary of your Personal Access Tokens.

ListResourceDelegates

#
Service
workmail

Description

Lists the delegates associated with a resource.

ListResources

#
Service
workmail

Description

Returns summaries of the organization's resources.

ListTagsForResource

#
Service
workmail

Description

Lists the tags applied to an WorkMail organization resource.

ListUsers

#
Service
workmail

Description

Returns summaries of the organization's users.

PutAccessControlRule

#
Service
workmail

Description

Adds a new access control rule for the specified organization.

PutEmailMonitoringConfiguration

#
Service
workmail

Description

Creates or updates the email monitoring configuration for a specified organization.

PutIdentityProviderConfiguration

#
Service
workmail

Description

Enables integration between IAM Identity Center (IdC) and WorkMail to proxy authentication requests for mailbox users.

PutInboundDmarcSettings

#
Service
workmail

Description

Enables or disables a DMARC policy for a given organization.

PutMailboxPermissions

#
Service
workmail

Description

Sets permissions for a user, group, or resource.

PutMobileDeviceAccessOverride

#
Service
workmail

Description

Creates or updates a mobile device access override for the given WorkMail organization, user, and device.

PutRetentionPolicy

#
Service
workmail

Description

Puts a retention policy to the specified organization.

RegisterMailDomain

#
Service
workmail

Description

Registers a new domain in WorkMail and SES, and configures it for use by WorkMail.

RegisterToWorkMail

#
Service
workmail

Description

Registers an existing and disabled user, group, or resource for WorkMail use by associating a mailbox and calendaring capabilities.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

ResetPassword

#
Service
workmail

Description

Allows the administrator to reset the password for a user.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

StartMailboxExportJob

#
Service
workmail

Description

Starts a mailbox export job to export MIME-format email messages and calendar items from the specified mailbox to the specified Amazon Simple Storage Service (Amazon S3) bucket.

TagResource

#
Service
workmail

Description

Applies the specified tags to the specified WorkMailorganization resource.

TestAvailabilityConfiguration

#
Service
workmail

Description

Performs a test on an availability provider to ensure that access is allowed.

UntagResource

#
Service
workmail

Description

Untags the specified tags from the specified WorkMail organization resource.

UpdateAvailabilityConfiguration

#
Service
workmail

Description

Updates an existing AvailabilityConfiguration for the given WorkMail organization and domain.

UpdateDefaultMailDomain

#
Service
workmail

Description

Updates the default mail domain for an organization.

UpdateGroup

#
Service
workmail

Description

Updates attributes in a group.

UpdateImpersonationRole

#
Service
workmail

Description

Updates an impersonation role for the given WorkMail organization.

UpdateMailboxQuota

#
Service
workmail

Description

Updates a user's current mailbox quota for a specified organization and user.

UpdateMobileDeviceAccessRule

#
Service
workmail

Description

Updates a mobile device access rule for the specified WorkMail organization.

UpdatePrimaryEmailAddress

#
Service
workmail

Description

Updates the primary email for a user, group, or resource.

UpdateResource

#
Service
workmail

Description

Updates data for the resource.

UpdateUser

#
Service
workmail

Description

Updates data for the user.