In this video, I do a deep dive on Mailbox auditing within Microsoft 365. I show you what audit log data is collected by default and how can use powershell to customize your logs.
Highlights:
-on by default as as of Jan 2019
-Doesn't contain scope of all audit log activity you might want such as Mailbox login activity
-Mailbox option properties (These are the properties that allowed me to see the log data in the 365 audit log in the business tenant): https://docs.microsoft.com/en-us/micr...
-PS: search Mailbox Audit Cmdlets
Interactive Powershell to export logs: https://docs.microsoft.com/en-us/offi...
-My repo with Powershell scripts: https://github.com/msp4msps/Security