Exchange mailbox item operations (aggregated)
| Operation | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all for M365-ExchangeItemAggregated rules matching the RecordType but no specific Operation. | N | N |
| Mail | A mail client or application accessed mailbox items via MAPI, EWS, ActiveSync, IMAP, POP3, or REST. Exchange Online records both bind access (an individual message opened or previewed) and sync access (a desktop Outlook client bulk-downloading a mail folder) under this single operation; the two carry different forensic weight (see the community note). Part of Purview Audit Standard: enabled by default for any mailbox on an Office 365 or Microsoft 365 E3 or E5 license, not gated behind Audit Premium. | Y | Y |
any: Exchange mailbox item operations (aggregated) (catch-all)
#Description
Catch-all for M365-ExchangeItemAggregated rules matching the RecordType but no specific Operation.
MailItemsAccessed
#Description
A mail client or application accessed mailbox items via MAPI, EWS, ActiveSync, IMAP, POP3, or REST. Exchange Online records both bind access (an individual message opened or previewed) and sync access (a desktop Outlook client bulk-downloading a mail folder) under this single operation; the two carry different forensic weight (see the community note). Part of Purview Audit Standard: enabled by default for any mailbox on an Office 365 or Microsoft 365 E3 or E5 license, not gated behind Audit Premium.
Example Audit Record #
{
"ActorInfoString": "Client=REST;python-requests/2.34.2[AppId=22222222-2222-2222-2222-222222222222];",
"AppAccessContext": {
"AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
"APIId": "00000003-0000-0000-c000-000000000000",
"ClientAppId": "22222222-2222-2222-2222-222222222222",
"IssuedAtTime": "2026-07-04T15:04:45Z",
"UniqueTokenId": "pO6tpCIhWEeDjtm8HsIAAA"
},
"AppId": "00000003-0000-0000-c000-000000000000",
"ClientAppId": "22222222-2222-2222-2222-222222222222",
"ClientIPAddress": "203.0.113.10",
"ClientInfoString": "Client=REST;;",
"CreationTime": "2026-07-04T15:09:46Z",
"ExternalAccess": false,
"Folders": [
{
"FolderItems": [
{
"ClientRequestId": "5d087be8-e4a2-4baf-8fe6-a0028785ba80",
"CreationTime": "2026-07-04T15:09:46Z",
"Id": "RgAAAAAXRoXzP5fNR6PyEo/HqixABwA7mE7t4w9CSqNKCbVE7kkMAAAAAAEMAAA7mE7t4w9CSqNKCbVE7kkMAABt2MNkAAAJ",
"ImmutableId": "LgAAAAAdhAMRqmYRzZvIAKoAL8RaDQA7mE7t4w9CSqNKCbVE7kkMAABt2aCMAAAJ",
"InternetMessageId": "<8a371e55-4547-4103-8c74-f318c885ec1c@az.eastus2.microsoft.com>",
"SizeInBytes": 116791,
"Subject": "Important update: Eligibility for Quota Tier upgrade"
},
{
"ClientRequestId": "a8f67618-d72d-4ee4-9254-3d76e714c9bc",
"CreationTime": "2026-07-04T15:09:46Z",
"Id": "RgAAAAAXRoXzP5fNR6PyEo/HqixABwA7mE7t4w9CSqNKCbVE7kkMAAAAAAEMAAA7mE7t4w9CSqNKCbVE7kkMAABt2MNjAAAJ",
"ImmutableId": "LgAAAAAdhAMRqmYRzZvIAKoAL8RaDQA7mE7t4w9CSqNKCbVE7kkMAABt2ZyvAAAJ",
"InternetMessageId": "<110d5626-7b26-42fa-b19f-59c1521258c6@DS7NAM13BG0406.eop-nam13.prod.protection.outlook.com>",
"SizeInBytes": 46995,
"Subject": "Informational-severity alert: Creation of forwarding/redirect rule"
},
{
"ClientRequestId": "3d84b554-0f01-4a4d-b356-555243466c23",
"CreationTime": "2026-07-04T15:09:46Z",
"Id": "RgAAAAAXRoXzP5fNR6PyEo/HqixABwA7mE7t4w9CSqNKCbVE7kkMAAAAAAEMAAA7mE7t4w9CSqNKCbVE7kkMAABt2MNhAAAJ",
"ImmutableId": "LgAAAAAdhAMRqmYRzZvIAKoAL8RaDQA7mE7t4w9CSqNKCbVE7kkMAABt2ZynAAAJ",
"InternetMessageId": "<e1ca3064-3921-4736-a666-6b647c8eb2d2@DS7NAM13BG0406.eop-nam13.prod.protection.outlook.com>",
"SizeInBytes": 46980,
"Subject": "Informational-severity alert: Creation of forwarding/redirect rule"
}
],
"Id": "LgAAAAAXRoXzP5fNR6PyEo/HqixAAQA7mE7t4w9CSqNKCbVE7kkMAAAAAAEMAAAB",
"Path": "\\Inbox"
},
{
"FolderItems": [
{
"ClientRequestId": "bed4e0d2-27de-413c-b4e8-256185f88517",
"CreationTime": "2026-07-04T15:09:47Z",
"Id": "RgAAAAAXRoXzP5fNR6PyEo/HqixABwA7mE7t4w9CSqNKCbVE7kkMAAAAAAEPAAA7mE7t4w9CSqNKCbVE7kkMAABt2TLSAAAJ",
"ImmutableId": "LgAAAAAdhAMRqmYRzZvIAKoAL8RaDQA7mE7t4w9CSqNKCbVE7kkMAABt2ebqAAAJ",
"InternetMessageId": "<SA1PR16MB4707170FA34E36D37A414A30A2F32@SA1PR16MB4707.namprd16.prod.outlook.com>",
"SizeInBytes": 2898,
"Subject": "dw-harness-afc127f4 draft (updated)"
}
],
"Id": "LgAAAAAXRoXzP5fNR6PyEo/HqixAAQA7mE7t4w9CSqNKCbVE7kkMAAAAAAEPAAAB",
"Path": "\\Drafts"
}
],
"Id": "2ef22bac-e5c8-4c6d-8089-54c12098fc5b",
"InternalLogonType": 0,
"LogonType": 0,
"LogonUserSid": "S-1-5-21-2202824495-2635967380-1894632064-31996139",
"MailboxGuid": "2bc72b5a-02f0-45d2-97a2-5f0152098603",
"MailboxOwnerSid": "S-1-5-21-2202824495-2635967380-1894632064-31996139",
"MailboxOwnerUPN": "adminuser@example.onmicrosoft.com",
"Operation": "MailItemsAccessed",
"OperationCount": 4,
"OperationProperties": [
{
"Name": "MailAccessType",
"Value": "Bind"
}
],
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"OrganizationName": "example.onmicrosoft.com",
"OriginatingServer": "SA1PR16MB4707 (15.20.4200.000)\r\n",
"RecordType": 50,
"ResultStatus": "Succeeded",
"SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
"TokenObjectId": "11111111-1111-1111-1111-111111111111",
"TokenTenantId": "00000000-0000-0000-0000-000000000001",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "10000000AAAAAAAA",
"UserType": 0,
"Version": 1,
"Workload": "Exchange"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
AppId (splunk rule field) | eq | * | 3 rules | splunk |
AppId (splunk rule field) | eq | 00000003-0000-0000-c000-000000000000 | 2 rules | splunk |
ClientAppId (splunk rule field) | eq | * | 2 rules | splunk |
EventType (elastic rule field) | eq | mailitemsaccessed | 2 rules | elastic |
Provider_Name (elastic rule field) | eq | exchange | 2 rules | elastic |
ResultStatus (kusto rule field) | eq | succeeded | 1 rule | kusto |
anomalies (kusto rule field) | gt | 0 | 1 rule | kusto |
m365::UserType (elastic rule field) | in | 0 | 1 rule | elastic |
m365::UserType (elastic rule field) | in | 10 | 1 rule | elastic |
m365::UserType (elastic rule field) | in | 2 | 1 rule | elastic |
m365::UserType (elastic rule field) | in | 3 | 1 rule | elastic |
m365::Workload (kusto rule field) | eq | exchange | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1078T1114, T1114.002T1114, T1114.002Splunk #
T1114, T1114.002T1114, T1114.002T1114, T1114.002Kusto #
T1114YARA-L #
References #
M365 audit records use different field names on each surface #
The same Unified Audit Log record uses different field names on each surface. A query built for one surface can silently miss on another. These pages document the Management Activity API JSON names, the same names Search-UnifiedAuditLog and the Office 365 Management Activity API return.
- Purview CSV export flattens each record to four columns (
CreationDate,UserIds,Operations,AuditData). The API field names live only inside theAuditDataJSON blob. Expand it withConvertFrom-Json. The wrapper columns are renamed too:CreationDatenotCreationTime,UserIdsnotUserId,OperationsnotOperation. - Sentinel's
OfficeActivitytable renames several fields and turns two integer enum columns into strings. The table below maps them.
| API JSON (event pages) | OfficeActivity column | Note |
|---|---|---|
Id | OfficeId | Renamed. |
Workload | OfficeWorkload | Renamed. |
ObjectId | OfficeObjectId | Renamed. |
CreationTime | TimeGenerated | Renamed. OfficeActivity has no CreationTime column. |
SiteUrl | Site_Url | Renamed (SharePoint family). |
RecordType | RecordType | Same name; the Int32 enum becomes its string enum name. |
UserType | UserType | Same name; the Int32 enum becomes a string. |
ClientIP | ClientIP, Client_IPAddress | Both columns present on OfficeActivity. |
Scope | (none) | No OfficeActivity equivalent under any name. Recover it from the API JSON or the Purview AuditData blob. |
Operation, UserId, ResultStatus, UserKey, AppAccessContext, OrganizationId | same names | Unchanged. No _s / _d suffixes (a native table, not a custom log). |
Mapping verified against the OfficeActivity table reference, the Management Activity API schema, and the Purview audit-record export format.