Request for Guidance: Audit Visibility for Set-MailboxMessageConfiguration (Conversation Grouping) Changes

Naveed Hassan 0 Reputation points
2026-08-05T20:02:25.6833333+00:00

Hi Team,

We are investigating an issue for one of our end users where the Outlook setting "Group messages by branches within conversations" (Message List > Conversations) was found enabled, which caused newly delivered emails to be hidden/hard to locate in both Outlook Web Access and the desktop client, even though they had been successfully delivered to the mailbox.

We have confirmed the fix (switching to "Do not group messages") resolves the visible symptom. However, we have been unable to determine root cause - specifically, when or how this setting was originally enabled for the user.

We understand this setting is controlled via Set-MailboxMessageConfiguration. As part of our investigation we:

  1. Ran a Unified Audit Log (Purview) search across a 10-day window (21-31 July 2026) for the mailbox, covering ExchangeAdmin, ExchangeAggregatedOperation, ExchangeItem, ExchangeItemAggregated, ExchangeItemGroup, ExchangeSearch, and MipAutoLabelExchangeItem record types (2,690 records total).
  2. Found only one true configuration change event in that window: a Set-MailboxCalendarConfiguration change (WorkDays = "Weekdays"), made by the user himself via OWA - unrelated to message display/grouping.
  3. Ran Get-InboxRule -IncludeHidden and confirmed only the default Junk E-mail rule exists, with no forwarding, redirect, move, or delete actions.
  4. Confirmed sign-in logs show consistent location/IP for the user throughout the period.

Our question for Microsoft: Does the Unified Audit Log (or any other logging/telemetry source) capture Set-MailboxMessageConfiguration changes, including the "Group messages by branches within conversations" property specifically? If so, could you help us identify the correct record type(s), operation name(s), or search parameters to surface this event, since it did not appear in our searches using the record types listed above?

If this level of client-side/mailbox configuration change is not currently audited, we would also appreciate confirmation of that, along with any recommendations Microsoft has for improving visibility into this type of setting change going forward (e.g., via Intune, Outlook policies, or other telemetry).

We appreciate any guidance you can provide.

Kind regards, Naveed

Outlook | Web | Outlook on the web for business | Email
0 comments No comments

2 answers

Sort by: Most helpful
  1. Vasil Michev 127.5K Reputation points MVP Volunteer Moderator
    2026-08-06T06:19:06.3+00:00

    Set-MailboxMessageConfiguration only affects certain clients, and is intended to be used by admins. End users changing the corresponding settings within Outlook or OWA do not "execute" said cmdlet, so you will not find any audit entries for changes they made. Afaik, there is no way to audit Conversation Grouping changes that end users make.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments

  2. Hendrix 165 Reputation points Independent Advisor
    2026-08-05T21:09:19.5066667+00:00

    Hi Naveed,

    Greatly appreciate your time sharing the details about your situation.

    Based on your sharing, you have already resolved the situation: delivery confirmation, no hidden rules detected, sign-ins behavior is consistent, and switching to "Do not group messages" setting does fix the issue. The problem now is to find the root cause, whether the preference change was exposed to Purview as an auditable event or stayed as an Outlook/OWA mailbox preference update that is not consistently surfaced.

    For you to receive the best possible assistance, I strongly recommend submitting a support ticket directly to Microsoft for further investigation. This route ensures you can contact a support agent, who can conduct a remote session to review the issue in detail, validate backend configurations and run any required synchronization or diagnostic tools. If necessary, he/she can help escalate this situation to a specialized/high-tier team for more in‑depth analysis and resolution.

    I genuinely wish I could directly review the backend systems to diagnose and resolve this issue for you. However, as a forum user, I can only provide general guidance, sharing applicable resources, and directing you to the appropriate support channels so you can work with the right team to investigate further. That said, this option is the most effective approach I can provide so you can receive the most correct, specialized support for this situation.

    To create a support ticket:

    • Go to Microsoft 365 Admin Center > Support > Help & Support
    • Turn off the "Support Assistant" feature.    
    • Use the keyword "Support" to quickly bypass automated suggestions > Select Contact Support.  
    • In the ticket description, please clearly describe the issue, including any error messages and the steps you’ve already tried. You can also attach screenshots or screen recordings.  
    • Additionally, sharing your preferred contact times may help the support team handle the case more efficiently. 

    Thank you for your understanding and I truly hope your concern will be resolved soon.


    Note: Please follow the steps in the forum documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.