Description:

Verifies that the Mailbox Auditing Default (org level) setting is enabled at the organization.

Why:

Available in the audit are actions performed by mailbox owners, delegates, and admins, and the corresponding mailbox audit records will be available when you search for them in the mailbox audit log.

Configured: Feature is in place.

Not Configured: Feature is not in place.

Scoring: Contributes up to 1 point to the Posture Recommendations score.

Category: General

Microsoft Licensing: Works with Basic licensing

Secure Score Impact: YES — Microsoft publishes the improvement action "Ensure mailbox auditing for all users is enabled".

Remediation in Augmentt: Configure directly in Augmentt (Configure tab)

Compliance Frameworks:

  • CISA SCuBA — MS.EXO.13.1

  • NIST CSF 2.0 — PR.PS-04

  • CIS Microsoft 365 Benchmark v6 (Level 1) — 6.1.2

  • CIS Microsoft 365 Benchmark v7 (Level 1) — 6.1.2

  • HIPAA Security Rule — 164.312(b), 164.308(a)(1)(ii)(D)

  • CMMC Level 2 — AU.L2-3.3.1, AU.L2-3.3.2

Microsoft documentation:


_KB status: already published as "Mailbox Auditing Default (org level)" — update the existing step in place._

_Source: Augmentt native check. Check ID mailboxaudit (module 20)._

Sourced for this page:

  • Secure Score — Microsoft Learn publishes the Secure Score improvement action "Ensure mailbox auditing for all users is enabled".


Draft metadata — apply these as Stonly tags in the console, then delete this block. The Stonly API cannot set tags, so they are recorded here instead.
Tags: posture-check · compliance-audit · Exchange Online · General · M365 Basic · CIS M365 v6 L1 · CIS M365 v7 L1 · NIST CSF 2.0 · HIPAA · CISA SCuBA · CMMC Level 2