WorkMail
| eventName | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all entry for WorkMail rules that match the service but not a specific eventName. | N | N |
| Associate | Adds a member (user or group) to the resource's set of delegates. | N | N |
| Associate | Adds a member (user or group) to the group's set. | N | N |
| Assume | Assumes an impersonation role for the given WorkMail organization. | N | N |
| Cancel | Cancels a mailbox export job. | N | N |
| Create | Adds an alias to the set of a given member (user or group) of WorkMail. | N | N |
| Create | Creates an AvailabilityConfiguration for the given WorkMail organization and domain. | N | N |
| Create | Creates a group that can be used in WorkMail by calling the RegisterToWorkMail operation. | N | Y |
| Create | Creates the WorkMail application in IAM Identity Center that can be used later in the WorkMail - IdC integration. | N | N |
| Create | Creates an impersonation role for the given WorkMail organization. | N | N |
| Create | Creates a new mobile device access rule for the specified WorkMail organization. | N | N |
| Create | Creates a new WorkMail organization. | Y | Y |
| Create | Creates a new WorkMail resource. | N | N |
| Create | Creates a user who can be used in WorkMail by calling the RegisterToWorkMail operation. | N | Y |
| Delete | Deletes an access control rule for the specified WorkMail organization. | N | N |
| Delete | Remove one or more specified aliases from a set of aliases for a given user. | N | N |
| Delete | Deletes the AvailabilityConfiguration for the given WorkMail organization and domain. | N | N |
| Delete | Deletes the email monitoring configuration for a specified organization. | N | N |
| Delete | Deletes a group from WorkMail. | N | Y |
| Delete | Deletes the IAM Identity Center application from WorkMail. | N | N |
| Delete | Disables the integration between IdC and WorkMail. | N | N |
| Delete | Deletes an impersonation role for the given WorkMail organization. | N | N |
| Delete | Deletes permissions granted to a member (user or group). | N | N |
| Delete | Deletes the mobile device access override for the given WorkMail organization, user, and device. | N | N |
| Delete | Deletes a mobile device access rule for the specified WorkMail organization. | N | N |
| Delete | Deletes an WorkMail organization and all underlying AWS resources managed by WorkMail as part of the organization. | N | N |
| Delete | Deletes the Personal Access Token from the provided WorkMail Organization. | N | N |
| Delete | Deletes the specified resource. | N | N |
| Delete | Deletes the specified retention policy from the specified organization. | N | N |
| Delete | Deletes a user from WorkMail and all subsequent systems. | N | Y |
| Deregister | Mark a user, group, or resource as no longer used in WorkMail. | N | N |
| Deregister | Removes a domain from WorkMail, stops email routing to WorkMail, and removes the authorization allowing WorkMail use. | N | N |
| Describe | Describes the current email monitoring configuration for a specified organization. | N | N |
| Describe | Returns basic details about an entity in WorkMail. | N | N |
| Describe | Returns the data available for the group. | N | N |
| Describe | Returns detailed information on the current IdC setup for the WorkMail organization. | N | N |
| Describe | Lists the settings in a DMARC policy for a specified organization. | N | N |
| Describe | Describes the current status of a mailbox export job. | N | N |
| Describe | Provides more information regarding a given organization based on its identifier. | N | N |
| Describe | Returns the data available for the resource. | N | N |
| Describe | Provides information regarding the user. | N | N |
| Disassociate | Removes a member from the resource's set of delegates. | N | N |
| Disassociate | Removes a member from a group. | N | N |
| Get | Gets the effects of an organization's access control rules as they apply to a specified IPv4 address, access protocol action, and user ID or impersonation role ID. | N | N |
| Get | Gets the default retention policy details for the specified organization. | N | N |
| Get | Gets the impersonation role details for the given WorkMail organization. | N | N |
| Get | Tests whether the given impersonation role can impersonate a target user. | N | N |
| Get | Requests a user's mailbox details for a specified organization and user. | N | N |
| Get | Gets details for a mail domain, including domain records required to configure your domain with recommended security. | N | N |
| Get | Simulates the effect of the mobile device access rules for the given attributes of a sample access event. | N | N |
| Get | Gets the mobile device access override for the given WorkMail organization, user, and device. | N | N |
| Get | Requests details of a specific Personal Access Token within the WorkMail organization. | N | N |
| List | Lists the access control rules for the specified organization. | N | N |
| List | Creates a paginated call to list the aliases associated with a given entity. | N | N |
| List | List all the AvailabilityConfiguration's for the given WorkMail organization. | N | N |
| List | Returns an overview of the members of a group. | N | N |
| List | Returns summaries of the organization's groups. | N | N |
| List | Returns all the groups to which an entity belongs. | N | N |
| List | Lists all the impersonation roles for the given WorkMail organization. | N | N |
| List | Lists the mailbox export jobs started for the specified organization within the last seven days. | N | N |
| List | Lists the mailbox permissions associated with a user, group, or resource mailbox. | N | N |
| List | Lists the mail domains in a given WorkMail organization. | N | N |
| List | Lists all the mobile device access overrides for any given combination of WorkMail organization, user, or device. | N | N |
| List | Lists the mobile device access rules for the specified WorkMail organization. | N | N |
| List | Returns summaries of the customer's organizations. | Y | N |
| List | Returns a summary of your Personal Access Tokens. | N | N |
| List | Lists the delegates associated with a resource. | N | N |
| List | Returns summaries of the organization's resources. | N | N |
| List | Lists the tags applied to an WorkMail organization resource. | N | N |
| List | Returns summaries of the organization's users. | N | N |
| Put | Adds a new access control rule for the specified organization. | N | N |
| Put | Creates or updates the email monitoring configuration for a specified organization. | N | N |
| Put | Enables integration between IAM Identity Center (IdC) and WorkMail to proxy authentication requests for mailbox users. | N | N |
| Put | Enables or disables a DMARC policy for a given organization. | N | N |
| Put | Sets permissions for a user, group, or resource. | N | N |
| Put | Creates or updates a mobile device access override for the given WorkMail organization, user, and device. | N | N |
| Put | Puts a retention policy to the specified organization. | N | N |
| Register | Registers a new domain in WorkMail and SES, and configures it for use by WorkMail. | N | N |
| Register | Registers an existing and disabled user, group, or resource for WorkMail use by associating a mailbox and calendaring capabilities. | N | Y |
| Reset | Allows the administrator to reset the password for a user. | N | Y |
| Start | Starts a mailbox export job to export MIME-format email messages and calendar items from the specified mailbox to the specified Amazon Simple Storage Service (Amazon S3) bucket. | N | N |
| Tag | Applies the specified tags to the specified WorkMailorganization resource. | N | N |
| Test | Performs a test on an availability provider to ensure that access is allowed. | N | N |
| Untag | Untags the specified tags from the specified WorkMail organization resource. | N | N |
| Update | Updates an existing AvailabilityConfiguration for the given WorkMail organization and domain. | N | N |
| Update | Updates the default mail domain for an organization. | N | N |
| Update | Updates attributes in a group. | N | N |
| Update | Updates an impersonation role for the given WorkMail organization. | N | N |
| Update | Updates a user's current mailbox quota for a specified organization and user. | N | N |
| Update | Updates a mobile device access rule for the specified WorkMail organization. | N | N |
| Update | Updates the primary email for a user, group, or resource. | N | N |
| Update | Updates data for the resource. | N | N |
| Update | Updates data for the user. | N | N |
any: WorkMail (catch-all)
#Description
Catch-all entry for WorkMail rules that match the service but not a specific eventName.
AssociateDelegateToResource
#Description
Adds a member (user or group) to the resource's set of delegates.
AssociateMemberToGroup
#Description
Adds a member (user or group) to the group's set.
AssumeImpersonationRole
#Description
Assumes an impersonation role for the given WorkMail organization.
CancelMailboxExportJob
#Description
Cancels a mailbox export job.
CreateAlias
#Description
Adds an alias to the set of a given member (user or group) of WorkMail.
CreateAvailabilityConfiguration
#Description
Creates an AvailabilityConfiguration for the given WorkMail organization and domain.
CreateGroup
#Description
Creates a group that can be used in WorkMail by calling the RegisterToWorkMail operation.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1078, T1078.002, T1078.004, T1134↳ also matches CreateOrganization, CreateUser, DeleteGroup, DeleteUser, RegisterToWorkMail, ResetPassword
CreateIdentityCenterApplication
#Description
Creates the WorkMail application in IAM Identity Center that can be used later in the WorkMail - IdC integration.
CreateImpersonationRole
#Description
Creates an impersonation role for the given WorkMail organization.
CreateMobileDeviceAccessRule
#Description
Creates a new mobile device access rule for the specified WorkMail organization.
CreateOrganization
#Description
Creates a new WorkMail organization.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "LimitExceededException",
"errorMessage": "On March 31, 2027, AWS will discontinue support for Amazon WorkMail. After April 30, 2026, new customers will no longer be able to create new Amazon WorkMail organizations. For more information, see https://docs.aws.amazon.com/workmail/latest/adminguide/workmail-end-of-support.html",
"eventCategory": "Management",
"eventID": "221bdfdd-a2ad-47e2-a7c7-47e50ce02ff2",
"eventName": "CreateOrganization",
"eventSource": "workmail.amazonaws.com",
"eventTime": "2026-06-29T21:50:07Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "3fe91327-280e-4a21-8180-d3accadfa6b9",
"requestParameters": {
"alias": "dwfixwm82769806c5e3b6",
"clientToken": "1a7b27f5-7dad-4a63-baed-f608105ffb24",
"enableInteroperability": false
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "workmail.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1078, T1078.002, T1078.004, T1134↳ also matches CreateGroup, CreateUser, DeleteGroup, DeleteUser, RegisterToWorkMail, ResetPassword
CreateResource
#Description
Creates a new WorkMail resource.
CreateUser
#Description
Creates a user who can be used in WorkMail by calling the RegisterToWorkMail operation.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1078, T1078.002, T1078.004, T1134↳ also matches CreateGroup, CreateOrganization, DeleteGroup, DeleteUser, RegisterToWorkMail, ResetPassword
DeleteAccessControlRule
#Description
Deletes an access control rule for the specified WorkMail organization.
DeleteAlias
#Description
Remove one or more specified aliases from a set of aliases for a given user.
DeleteAvailabilityConfiguration
#Description
Deletes the AvailabilityConfiguration for the given WorkMail organization and domain.
DeleteEmailMonitoringConfiguration
#Description
Deletes the email monitoring configuration for a specified organization.
DeleteGroup
#Description
Deletes a group from WorkMail.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1078, T1078.002, T1078.004, T1134↳ also matches CreateGroup, CreateOrganization, CreateUser, DeleteUser, RegisterToWorkMail, ResetPassword
DeleteIdentityCenterApplication
#Description
Deletes the IAM Identity Center application from WorkMail.
DeleteIdentityProviderConfiguration
#Description
Disables the integration between IdC and WorkMail.
DeleteImpersonationRole
#Description
Deletes an impersonation role for the given WorkMail organization.
DeleteMailboxPermissions
#Description
Deletes permissions granted to a member (user or group).
DeleteMobileDeviceAccessOverride
#Description
Deletes the mobile device access override for the given WorkMail organization, user, and device.
DeleteMobileDeviceAccessRule
#Description
Deletes a mobile device access rule for the specified WorkMail organization.
DeleteOrganization
#Description
Deletes an WorkMail organization and all underlying AWS resources managed by WorkMail as part of the organization.
DeletePersonalAccessToken
#Description
Deletes the Personal Access Token from the provided WorkMail Organization.
DeleteResource
#Description
Deletes the specified resource.
DeleteRetentionPolicy
#Description
Deletes the specified retention policy from the specified organization.
DeleteUser
#Description
Deletes a user from WorkMail and all subsequent systems.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1078, T1078.002, T1078.004, T1134↳ also matches CreateGroup, CreateOrganization, CreateUser, DeleteGroup, RegisterToWorkMail, ResetPassword
DeregisterFromWorkMail
#Description
Mark a user, group, or resource as no longer used in WorkMail.
DeregisterMailDomain
#Description
Removes a domain from WorkMail, stops email routing to WorkMail, and removes the authorization allowing WorkMail use.
DescribeEmailMonitoringConfiguration
#Description
Describes the current email monitoring configuration for a specified organization.
DescribeEntity
#Description
Returns basic details about an entity in WorkMail.
DescribeGroup
#Description
Returns the data available for the group.
DescribeIdentityProviderConfiguration
#Description
Returns detailed information on the current IdC setup for the WorkMail organization.
DescribeInboundDmarcSettings
#Description
Lists the settings in a DMARC policy for a specified organization.
DescribeMailboxExportJob
#Description
Describes the current status of a mailbox export job.
DescribeOrganization
#Description
Provides more information regarding a given organization based on its identifier.
DescribeResource
#Description
Returns the data available for the resource.
DescribeUser
#Description
Provides information regarding the user.
DisassociateDelegateFromResource
#Description
Removes a member from the resource's set of delegates.
DisassociateMemberFromGroup
#Description
Removes a member from a group.
GetAccessControlEffect
#Description
Gets the effects of an organization's access control rules as they apply to a specified IPv4 address, access protocol action, and user ID or impersonation role ID.
GetDefaultRetentionPolicy
#Description
Gets the default retention policy details for the specified organization.
GetImpersonationRole
#Description
Gets the impersonation role details for the given WorkMail organization.
GetImpersonationRoleEffect
#Description
Tests whether the given impersonation role can impersonate a target user.
GetMailboxDetails
#Description
Requests a user's mailbox details for a specified organization and user.
GetMailDomain
#Description
Gets details for a mail domain, including domain records required to configure your domain with recommended security.
GetMobileDeviceAccessEffect
#Description
Simulates the effect of the mobile device access rules for the given attributes of a sample access event.
GetMobileDeviceAccessOverride
#Description
Gets the mobile device access override for the given WorkMail organization, user, and device.
GetPersonalAccessTokenMetadata
#Description
Requests details of a specific Personal Access Token within the WorkMail organization.
ListAccessControlRules
#Description
Lists the access control rules for the specified organization.
ListAliases
#Description
Creates a paginated call to list the aliases associated with a given entity.
ListAvailabilityConfigurations
#Description
List all the AvailabilityConfiguration's for the given WorkMail organization.
ListGroupMembers
#Description
Returns an overview of the members of a group.
ListGroups
#Description
Returns summaries of the organization's groups.
ListGroupsForEntity
#Description
Returns all the groups to which an entity belongs.
ListImpersonationRoles
#Description
Lists all the impersonation roles for the given WorkMail organization.
ListMailboxExportJobs
#Description
Lists the mailbox export jobs started for the specified organization within the last seven days.
ListMailboxPermissions
#Description
Lists the mailbox permissions associated with a user, group, or resource mailbox.
ListMailDomains
#Description
Lists the mail domains in a given WorkMail organization.
ListMobileDeviceAccessOverrides
#Description
Lists all the mobile device access overrides for any given combination of WorkMail organization, user, or device.
ListMobileDeviceAccessRules
#Description
Lists the mobile device access rules for the specified WorkMail organization.
ListOrganizations
#Description
Returns summaries of the customer's organizations.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: workmail:ListOrganizations",
"eventID": "8d484b26-053a-4ab5-a69f-3bbff8f26a76",
"eventName": "ListOrganizations",
"eventSource": "workmail.amazonaws.com",
"eventTime": "2019-03-07T21:20:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "cbdbe174-411e-11e9-83d2-197e7b1c9574",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "2.231.90.242",
"userAgent": "Boto3/1.7.4 Python/3.7.2+ Linux/4.4.0-01985-Microsoft Botocore/1.10.4",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
ListPersonalAccessTokens
#Description
Returns a summary of your Personal Access Tokens.
ListResourceDelegates
#Description
Lists the delegates associated with a resource.
ListResources
#Description
Returns summaries of the organization's resources.
ListUsers
#Description
Returns summaries of the organization's users.
PutAccessControlRule
#Description
Adds a new access control rule for the specified organization.
PutEmailMonitoringConfiguration
#Description
Creates or updates the email monitoring configuration for a specified organization.
PutIdentityProviderConfiguration
#Description
Enables integration between IAM Identity Center (IdC) and WorkMail to proxy authentication requests for mailbox users.
PutInboundDmarcSettings
#Description
Enables or disables a DMARC policy for a given organization.
PutMailboxPermissions
#Description
Sets permissions for a user, group, or resource.
PutMobileDeviceAccessOverride
#Description
Creates or updates a mobile device access override for the given WorkMail organization, user, and device.
PutRetentionPolicy
#Description
Puts a retention policy to the specified organization.
RegisterMailDomain
#Description
Registers a new domain in WorkMail and SES, and configures it for use by WorkMail.
RegisterToWorkMail
#Description
Registers an existing and disabled user, group, or resource for WorkMail use by associating a mailbox and calendaring capabilities.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1078, T1078.002, T1078.004, T1134↳ also matches CreateGroup, CreateOrganization, CreateUser, DeleteGroup, DeleteUser, ResetPassword
ResetPassword
#Description
Allows the administrator to reset the password for a user.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1078, T1078.002, T1078.004, T1134↳ also matches CreateGroup, CreateOrganization, CreateUser, DeleteGroup, DeleteUser, RegisterToWorkMail
StartMailboxExportJob
#Description
Starts a mailbox export job to export MIME-format email messages and calendar items from the specified mailbox to the specified Amazon Simple Storage Service (Amazon S3) bucket.
TagResource
#Description
Applies the specified tags to the specified WorkMailorganization resource.
TestAvailabilityConfiguration
#Description
Performs a test on an availability provider to ensure that access is allowed.
UntagResource
#Description
Untags the specified tags from the specified WorkMail organization resource.
UpdateAvailabilityConfiguration
#Description
Updates an existing AvailabilityConfiguration for the given WorkMail organization and domain.
UpdateDefaultMailDomain
#Description
Updates the default mail domain for an organization.
UpdateGroup
#Description
Updates attributes in a group.
UpdateImpersonationRole
#Description
Updates an impersonation role for the given WorkMail organization.
UpdateMailboxQuota
#Description
Updates a user's current mailbox quota for a specified organization and user.
UpdateMobileDeviceAccessRule
#Description
Updates a mobile device access rule for the specified WorkMail organization.
UpdatePrimaryEmailAddress
#Description
Updates the primary email for a user, group, or resource.
UpdateResource
#Description
Updates data for the resource.
UpdateUser
#Description
Updates data for the user.