Avatar of Christian Hans
Christian HansFlag for United States of America

asked on 

Mailbox Audit Enabling by default in O365

Question, when moving mailboxes to Office 365 (Exchange Online), the mailboxes don't seem to have AuditEnabled $True on the mailboxes, although the Org. Config is set to enable it by default.  

Get-OrganizationConfig | Select AuditDisabled

AuditDisabled
-------------
        False

Any ideas as to why? we basically want AuditEnabled $True on by default as posted here: Link without us having to run the command manually after every mailbox is migrated.

Get-Mailbox -Identity Joe@contoso.com | FL *audit*

AuditEnabled     : False
AuditLogAgeLimit : 90.00:00:00

Thanks
Microsoft OfficeExchangeMicrosoft 365

Avatar of undefined
Last Comment
Vasil Michev (MVP)
Avatar of Vasil Michev (MVP)
Vasil Michev (MVP)
Flag of Bulgaria image

Most likely because they are being provisioned as mail users first, as part of the migration process. Let me ping few folks to confirm what is the expected behavior for migrated mailboxes.

Just in case, you do get audit enabled for any newly created cloud mailbox, right?
Avatar of Mahesh
Mahesh
Flag of India image

Mailbox auditing may be enabled at organization level but it is not enabled for mailboxes by default
U must enabled per mailbox if i recollect exactly
Avatar of Christian Hans
Christian Hans
Flag of United States of America image

ASKER

Vasil, I created a net new account in O365, and it looks like its disabled on new mailboxes also...

Get-Mailbox Fred.Flintstone@contoso.onmicrosoft.com | Select *Audit*

AuditEnabled     : False
AuditLogAgeLimit : 90.00:00:00

So it seems that although its set at the Org level, its not applying for some reason.
SOLUTION
Avatar of Vasil Michev (MVP)
Vasil Michev (MVP)
Flag of Bulgaria image

Blurred text
THIS SOLUTION IS ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
Avatar of Mahesh
Mahesh
Flag of India image

It not means that auditing is enabled at organization level is also enabled at mailbox level
When u enable auditing on mailbox, it add additional processing overheard per mailbox and hence Microsoft don't want to enable it by default
Organization level switch is entry point to decide whether you can use feature or not
Avatar of Christian Hans
Christian Hans
Flag of United States of America image

ASKER

I guess I am a little confused now...

My understanding, and I think its the same as Vasils, is that once we have AuditDisabled:$False set at the tenant Organizational level, it would be enabled for all mailboxes moving forward, for both new cloud only mailboxes as well as mailboxes that are Migrated in a Hybrid environment.  The difference being that perhaps its not rolled out or effective on all O365 tenants just yet', even if set at the org level.

Per your link, the confusing part is that its not really clear whether this HAS to be applied at a per mailbox level or whether the Org level change would suffice going forward.
 
" In Office 365, you can turn on mailbox audit logging to log mailbox access by mailbox owners, delegates, and administrators. By default, mailbox auditing in Office 365 isn't turned on. That means mailbox auditing events won't appear in the results when you search the Office 365 audit log for mailbox activity. But after you turn on mailbox audit logging for a user mailbox, you can search the audit log for mailbox activity. Additionally, when mailbox audit logging is turned on, some actions performed by administrators, delegates, and owners are logged by default. "
ASKER CERTIFIED SOLUTION
THIS SOLUTION IS ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
In addition, here's the Roadmap item: https://www.microsoft.com/en-us/microsoft-365/roadmap?filters=&searchterms=32224

Sadly, "launched" doesnt equal "rolled out completely" :)
Avatar of Mahesh
Mahesh
Flag of India image

Thanks for update
Avatar of Christian Hans
Christian Hans
Flag of United States of America image

ASKER

I just wanted to share another finding... If the mailbox has Audit Enabled = $True on-prem, when migrating the mailbox, the Audit Enabled flag remains enabled. So that's good... so basically as long as all mailboxes on-prem have Auditing enabled before migration, they will keep that setting. I think we are still waiting on our tenant to update as you mentioned Vasil, because net-new mailboxes created in Exchange Online don't have Auditing enabled by default yet.
Yup, I confirmed with the PG folks that the rollout has indeed not finished, as the Roadmap item would suggest. So you have to wait a bit.
Exchange
Exchange

Exchange is the server side of a collaborative application product that is part of the Microsoft Server infrastructure. Exchange's major features include email, calendaring, contacts and tasks, support for mobile and web-based access to information, and support for data storage.

213K
Questions
--
Followers
--
Top Experts
Get a personalized solution from industry experts
Ask the experts
Read over 600 more reviews

TRUSTED BY

IBM logoIntel logoMicrosoft logoUbisoft logoSAP logo
Qualcomm logoCitrix Systems logoWorkday logoErnst & Young logo
High performer badgeUsers love us badge
LinkedIn logoFacebook logoX logoInstagram logoTikTok logoYouTube logo