Exchange mailbox item operations (aggregated)

OperationDescriptionSampleRule
anyCatch-all for M365-ExchangeItemAggregated rules matching the RecordType but no specific Operation.NN
MailItemsAccessedA mail client or application accessed mailbox items via MAPI, EWS, ActiveSync, IMAP, POP3, or REST. Exchange Online records both bind access (an individual message opened or previewed) and sync access (a desktop Outlook client bulk-downloading a mail folder) under this single operation; the two carry different forensic weight (see the community note). Part of Purview Audit Standard: enabled by default for any mailbox on an Office 365 or Microsoft 365 E3 or E5 license, not gated behind Audit Premium.YY

any: Exchange mailbox item operations (aggregated) (catch-all)

#
RecordType
ExchangeItemAggregated

Description

Catch-all for M365-ExchangeItemAggregated rules matching the RecordType but no specific Operation.

MailItemsAccessed

#
RecordType
ExchangeItemAggregated

Description

A mail client or application accessed mailbox items via MAPI, EWS, ActiveSync, IMAP, POP3, or REST. Exchange Online records both bind access (an individual message opened or previewed) and sync access (a desktop Outlook client bulk-downloading a mail folder) under this single operation; the two carry different forensic weight (see the community note). Part of Purview Audit Standard: enabled by default for any mailbox on an Office 365 or Microsoft 365 E3 or E5 license, not gated behind Audit Premium.

Example Audit Record #

{
  "ActorInfoString": "Client=REST;python-requests/2.34.2[AppId=22222222-2222-2222-2222-222222222222];",
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "APIId": "00000003-0000-0000-c000-000000000000",
    "ClientAppId": "22222222-2222-2222-2222-222222222222",
    "IssuedAtTime": "2026-07-04T15:04:45Z",
    "UniqueTokenId": "pO6tpCIhWEeDjtm8HsIAAA"
  },
  "AppId": "00000003-0000-0000-c000-000000000000",
  "ClientAppId": "22222222-2222-2222-2222-222222222222",
  "ClientIPAddress": "203.0.113.10",
  "ClientInfoString": "Client=REST;;",
  "CreationTime": "2026-07-04T15:09:46Z",
  "ExternalAccess": false,
  "Folders": [
    {
      "FolderItems": [
        {
          "ClientRequestId": "5d087be8-e4a2-4baf-8fe6-a0028785ba80",
          "CreationTime": "2026-07-04T15:09:46Z",
          "Id": "RgAAAAAXRoXzP5fNR6PyEo/HqixABwA7mE7t4w9CSqNKCbVE7kkMAAAAAAEMAAA7mE7t4w9CSqNKCbVE7kkMAABt2MNkAAAJ",
          "ImmutableId": "LgAAAAAdhAMRqmYRzZvIAKoAL8RaDQA7mE7t4w9CSqNKCbVE7kkMAABt2aCMAAAJ",
          "InternetMessageId": "<8a371e55-4547-4103-8c74-f318c885ec1c@az.eastus2.microsoft.com>",
          "SizeInBytes": 116791,
          "Subject": "Important update: Eligibility for Quota Tier upgrade"
        },
        {
          "ClientRequestId": "a8f67618-d72d-4ee4-9254-3d76e714c9bc",
          "CreationTime": "2026-07-04T15:09:46Z",
          "Id": "RgAAAAAXRoXzP5fNR6PyEo/HqixABwA7mE7t4w9CSqNKCbVE7kkMAAAAAAEMAAA7mE7t4w9CSqNKCbVE7kkMAABt2MNjAAAJ",
          "ImmutableId": "LgAAAAAdhAMRqmYRzZvIAKoAL8RaDQA7mE7t4w9CSqNKCbVE7kkMAABt2ZyvAAAJ",
          "InternetMessageId": "<110d5626-7b26-42fa-b19f-59c1521258c6@DS7NAM13BG0406.eop-nam13.prod.protection.outlook.com>",
          "SizeInBytes": 46995,
          "Subject": "Informational-severity alert: Creation of forwarding/redirect rule"
        },
        {
          "ClientRequestId": "3d84b554-0f01-4a4d-b356-555243466c23",
          "CreationTime": "2026-07-04T15:09:46Z",
          "Id": "RgAAAAAXRoXzP5fNR6PyEo/HqixABwA7mE7t4w9CSqNKCbVE7kkMAAAAAAEMAAA7mE7t4w9CSqNKCbVE7kkMAABt2MNhAAAJ",
          "ImmutableId": "LgAAAAAdhAMRqmYRzZvIAKoAL8RaDQA7mE7t4w9CSqNKCbVE7kkMAABt2ZynAAAJ",
          "InternetMessageId": "<e1ca3064-3921-4736-a666-6b647c8eb2d2@DS7NAM13BG0406.eop-nam13.prod.protection.outlook.com>",
          "SizeInBytes": 46980,
          "Subject": "Informational-severity alert: Creation of forwarding/redirect rule"
        }
      ],
      "Id": "LgAAAAAXRoXzP5fNR6PyEo/HqixAAQA7mE7t4w9CSqNKCbVE7kkMAAAAAAEMAAAB",
      "Path": "\\Inbox"
    },
    {
      "FolderItems": [
        {
          "ClientRequestId": "bed4e0d2-27de-413c-b4e8-256185f88517",
          "CreationTime": "2026-07-04T15:09:47Z",
          "Id": "RgAAAAAXRoXzP5fNR6PyEo/HqixABwA7mE7t4w9CSqNKCbVE7kkMAAAAAAEPAAA7mE7t4w9CSqNKCbVE7kkMAABt2TLSAAAJ",
          "ImmutableId": "LgAAAAAdhAMRqmYRzZvIAKoAL8RaDQA7mE7t4w9CSqNKCbVE7kkMAABt2ebqAAAJ",
          "InternetMessageId": "<SA1PR16MB4707170FA34E36D37A414A30A2F32@SA1PR16MB4707.namprd16.prod.outlook.com>",
          "SizeInBytes": 2898,
          "Subject": "dw-harness-afc127f4 draft (updated)"
        }
      ],
      "Id": "LgAAAAAXRoXzP5fNR6PyEo/HqixAAQA7mE7t4w9CSqNKCbVE7kkMAAAAAAEPAAAB",
      "Path": "\\Drafts"
    }
  ],
  "Id": "2ef22bac-e5c8-4c6d-8089-54c12098fc5b",
  "InternalLogonType": 0,
  "LogonType": 0,
  "LogonUserSid": "S-1-5-21-2202824495-2635967380-1894632064-31996139",
  "MailboxGuid": "2bc72b5a-02f0-45d2-97a2-5f0152098603",
  "MailboxOwnerSid": "S-1-5-21-2202824495-2635967380-1894632064-31996139",
  "MailboxOwnerUPN": "adminuser@example.onmicrosoft.com",
  "Operation": "MailItemsAccessed",
  "OperationCount": 4,
  "OperationProperties": [
    {
      "Name": "MailAccessType",
      "Value": "Bind"
    }
  ],
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.20.4200.000)\r\n",
  "RecordType": 50,
  "ResultStatus": "Succeeded",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "10000000AAAAAAAA",
  "UserType": 0,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
AppId (splunk rule field)eq*3 rulessplunk
AppId (splunk rule field)eq00000003-0000-0000-c000-0000000000002 rulessplunk
ClientAppId (splunk rule field)eq*2 rulessplunk
EventType (elastic rule field)eqmailitemsaccessed2 ruleselastic
Provider_Name (elastic rule field)eqexchange2 ruleselastic
ResultStatus (kusto rule field)eqsucceeded1 rulekusto
anomalies (kusto rule field)gt01 rulekusto
m365::UserType (elastic rule field)in01 ruleelastic
m365::UserType (elastic rule field)in101 ruleelastic
m365::UserType (elastic rule field)in21 ruleelastic
m365::UserType (elastic rule field)in31 ruleelastic
m365::Workload (kusto rule field)eqexchange1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • M365 or Entra ID Identity Sign-in from a Suspicious Source source high: This rule correlate Entra-ID or Microsoft 365 mail successful sign-in events with network security alerts by source address. Adversaries may trigger some network security alerts such as reputation or other anomalies before accessing cloud resources.T1078
  • M365 Exchange Mailbox Items Accessed Excessively source medium: Identifies an excessive number of Microsoft 365 mailbox items accessed by a user either via aggregated counts or throttling. Microsoft audits mailbox access via the MailItemsAccessed event, which is triggered when a user accesses mailbox items. If more than 1000 mailbox items are accessed within a 24-hour period, it is then throttled. Excessive mailbox access may indicate an adversary attempting to exfiltrate sensitive information or perform reconnaissance on a target's mailbox. This rule detects both the throttled and unthrottled events with a high threshold.T1114, T1114.002
  • M365 Exchange Mailbox Accessed by Unusual Client source medium: Identifies suspicious Microsoft 365 mail access by ClientAppId. This rule detects when a user accesses their mailbox using a client application that is not typically used by the user, which may indicate potential compromise or unauthorized access attempts. Adversaries may use custom or third-party applications to access mailboxes, bypassing standard security controls. First-party Microsoft applications are also abused after OAuth tokens are compromised, allowing adversaries to access mailboxes without raising suspicion.T1114, T1114.002

Splunk #

  • O365 Multiple Mailboxes Accessed via API source: The following analytic detects when a high number of Office 365 Exchange mailboxes are accessed via API (Microsoft Graph API or Exchange Web Services) within a short timeframe. It leverages 'MailItemsAccessed' operations in Exchange, using…T1114, T1114.002
  • O365 OAuth App Mailbox Access via EWS source: The following analytic detects when emails are accessed in Office 365 Exchange via Exchange Web Services (EWS) using OAuth-authenticated applications. It leverages the ClientInfoString field to identify EWS interactions and aggregates…T1114, T1114.002
  • O365 OAuth App Mailbox Access via Graph API source: The following analytic detects when emails are accessed in Office 365 Exchange via the Microsoft Graph API using the client ID '00000003-0000-0000-c000-000000000000'. It leverages the 'MailItemsAccessed' operation within the Exchange…T1114, T1114.002

Kusto #

YARA-L #

References #

M365 audit records use different field names on each surface #

The same Unified Audit Log record uses different field names on each surface. A query built for one surface can silently miss on another. These pages document the Management Activity API JSON names, the same names Search-UnifiedAuditLog and the Office 365 Management Activity API return.

  • Purview CSV export flattens each record to four columns (CreationDate, UserIds, Operations, AuditData). The API field names live only inside the AuditData JSON blob. Expand it with ConvertFrom-Json. The wrapper columns are renamed too: CreationDate not CreationTime, UserIds not UserId, Operations not Operation.
  • Sentinel's OfficeActivity table renames several fields and turns two integer enum columns into strings. The table below maps them.
API JSON (event pages)OfficeActivity columnNote
IdOfficeIdRenamed.
WorkloadOfficeWorkloadRenamed.
ObjectIdOfficeObjectIdRenamed.
CreationTimeTimeGeneratedRenamed. OfficeActivity has no CreationTime column.
SiteUrlSite_UrlRenamed (SharePoint family).
RecordTypeRecordTypeSame name; the Int32 enum becomes its string enum name.
UserTypeUserTypeSame name; the Int32 enum becomes a string.
ClientIPClientIP, Client_IPAddressBoth columns present on OfficeActivity.
Scope(none)No OfficeActivity equivalent under any name. Recover it from the API JSON or the Purview AuditData blob.
Operation, UserId, ResultStatus, UserKey, AppAccessContext, OrganizationIdsame namesUnchanged. No _s / _d suffixes (a native table, not a custom log).

Mapping verified against the OfficeActivity table reference, the Management Activity API schema, and the Purview audit-record export format.