How to Enable Expanded Audit Logging to Detect Mailbox Access
Retrospective: this article looks back at events from July 2023, written in 2026 with the benefit of hindsight.
Storm-0558 was detected because a customer had detailed mailbox access logs. Here is how to make sure your Microsoft 365 audit logging captures what you'd need in a similar investigation.
Step 1: Confirm the unified audit log is on
Connect-ExchangeOnline
Get-AdminAuditLogConfig | Format-List UnifiedAuditLogIngestionEnabled
It should be True. It's on by default in most tenants, but confirm.
Step 2: Confirm mailbox auditing
Mailbox auditing is on by default. Confirm it hasn't been disabled at the organization level:
Get-OrganizationConfig | Format-List AuditDisabled
AuditDisabled should be False.
Step 3: Check which mailbox actions are logged
Following Storm-0558, Microsoft expanded logging available to standard licenses, including MailItemsAccessed and other events previously limited to premium audit. Review the default audit actions for owner, delegate and admin access, and add actions you need (for example, MailItemsAccessed, Send, SearchQueryInitiated where available).
Step 4: Set retention
Standard audit retention is 180 days. Microsoft Purview Audit (Premium) offers one-year retention by default and longer with add-ons. Alternatively, export audit logs to Microsoft Sentinel or another SIEM with longer retention.
Step 5: Stream to your SIEM
Connect the Microsoft 365 (Office 365) data connector to Sentinel, plus Defender XDR's advanced hunting tables (CloudAppEvents) for richer detail.
Step 6: Practice using it
Run a test investigation: "Which mailboxes did this account access last week, from which IPs?" If you can't answer quickly, adjust logging or retention.