Is it possible to fetch audit logs of disabled mailbox user in exchange server 2016

Mohammed Hashim 21 Reputation points
2021-07-07T18:09:53.72+00:00

Hi all,

One user account has been recently disabled. Audit logs has been enabled in our organization. Can we get the disabled mailbox user audit logs?. If yes kindly share the procedure.

We use exchange server 2016 cu19.

Regards,

Hashim

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,636 questions
Microsoft Exchange Hybrid Management
Microsoft Exchange Hybrid Management
Microsoft Exchange: Microsoft messaging and collaboration software.Hybrid Management: Organizing, handling, directing or controlling hybrid deployments.
2,105 questions
0 comments No comments
{count} votes

Accepted answer
  1. JeffYang-MSFT 6,241 Reputation points Microsoft Vendor
    2021-07-08T06:29:05.977+00:00

    Hi @Mohammed Hashim ,

    Can we get the disabled mailbox user audit logs?

    I tried a lot of tests in my Exchange 2016 but could not found any workarounds to get the audit logs of the disabled mailbox user.

    As I know, Mailbox audit log records are stored in a subfolder (named Audits) in the Recoverable Items folder in each user's mailbox. However, as this document says, we can't directly access an audit log record in the Recoverable Items folder; instead, Search-MailboxAuditLog cmdlet or search the audit log is needed. So, based on all the tests results, in order to get the disabled mailbox user audit logs, we need to connect to them firstly.

    By the way, what also need to be mentioned is that mailbox audit log entries are retained in the mailbox for 90 days and then deleted by default. And the disconnected mailbox is permanently deleted (purged) based on the MailboxRetention property value for the mailbox database (the default value is 30 days). Please remember to take necessary operations in time.

    Hope these could help.


    If an Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.