How can I determine who accessed a shared mailbox calendar?

0
0
Asked By MellowPine42 On

While reviewing the sharing settings for a departmental shared mailbox, we found that the default calendar permission for people in the organization had been changed from "Can view when I'm busy" to "Can view all details." Because staff sometimes include personally identifiable information in calendar entries, this may represent a privacy exposure. I tried searching Microsoft Purview audit logs with the mailbox address in the Users field, but that mainly shows activity performed by the mailbox itself. How can I identify other employee accounts that accessed the mailbox or calendar during the available 180-day audit window? The mailbox has a Microsoft 365 E3 license.

2 Answers

Answered By QuartzHarbor19 On

You should run a separate search for the account that changed the calendar permissions. Folder permission changes and the corresponding Exchange admin cmdlets may be audited, so search for operations such as AddFolderPermissions, ModifyFolderPermissions, RemoveFolderPermissions, Add-MailboxFolderPermission, Set-MailboxFolderPermission, and Remove-MailboxFolderPermission. Leave the Users filter blank and search the returned AuditData for the mailbox address. You can also check the mailbox audit configuration with `Get-Mailbox [email protected] | Select-Object AuditEnabled,AuditOwner,AuditDelegate,AuditAdmin`. Keep in mind that a person who merely opened a calendar through the organization-wide Default permission may not appear in the audit records. FolderBind can show folder access, but audit logs may not establish exactly which calendar item was viewed. Restore the Default permission to free/busy, check the Anonymous setting, and preserve any results now by exporting them in smaller date ranges if the search approaches the 5,000-record limit.

MellowPine42 -

Auditing appears to be enabled, but the permission change itself seems to be older than the 180-day retention window. We are continuing to remove unnecessary permissions and will document that the available logs cannot verify activity before that period.

Answered By CopperVale7 On

The Users filter is probably being used in the wrong way here. Searching for the shared mailbox in that field asks what that mailbox account did; it does not necessarily show who accessed the mailbox. Search for activity involving the mailbox, then inspect UserId and AuditData to identify the actor. You can use the mailbox’s Exchange GUID with Search-UnifiedAuditLog, for example: `Search-UnifiedAuditLog -StartDate (Get-Date).AddDays(-180) -EndDate (Get-Date) -FreeText (Get-Mailbox [email protected]).ExchangeGuid -ResultSize 5000`. Review operations such as FolderBind, MailItemsAccessed, SendAs, SendOnBehalf, Move, and SoftDelete. MailItemsAccessed is more useful for investigating actual message access, while FolderBind generally indicates that a folder was opened and does not prove that a particular calendar item was viewed. Also compare the results with the permissions that should exist by checking `Get-MailboxPermission`, `Get-RecipientPermission`, and `Get-MailboxFolderPermission [email protected]:Calendar`. Export the results promptly because the available audit-retention period may be limited to 180 days.

MellowPine42 -

Using the mailbox Exchange GUID produced useful results. It looks like 180 days is the maximum historical window available to us without additional licensing, so older activity may not be recoverable. I also tried searching for FolderBind with the GUID and received no results, which may be a positive sign, although I understand that an empty result does not conclusively prove nobody viewed the calendar.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.