Reference

Mailbox Audit Bypass

Accounts excluded from mailbox audit logging. Bypassed service accounts can read mail invisibly — high-signal finding most products miss.

Part of the Exchange inventory.

Scan settings

Default scanning intervalAllowed scanning intervalsData removal during incremental scan
WeeklyDaily, Weekly, Bi-Weekly, Monthly, Never, InitialYes

Properties

Property Type Description Automation placeholder
Account String {{MailboxAuditBypass.AccountName}}
Account Type String User, ServiceAccount, or Computer. {{MailboxAuditBypass.AccountType}}
Audit Bypass Enabled Boolean When true, mailbox audit logging is bypassed for this account. {{MailboxAuditBypass.AuditBypassEnabled}}
Initially Scanned DateTime Shows when this object was initially found in a scan. {{MailboxAuditBypass.CreatedTime}}
Identity String {{MailboxAuditBypass.DisplayName}}
Last scan update DateTime Shows when this object was last updated in a scan. If an object is found during a scan but no property has been changed this date will not change. {{MailboxAuditBypass.LastModifiedTime}}
Risk Score Int32 Stores risk score {{MailboxAuditBypass.RiskScore}}
Risk Score Update DateTime Stores risk score update {{MailboxAuditBypass.RiskScoreLastUpdate}}
Risk Score Value String Stores risk score value like Low_Low {{MailboxAuditBypass.RiskScoreValue}}
User User {{MailboxAuditBypass.User}}
User name String {{MailboxAuditBypass.UserName}}

Relations

Relation Service Description
User Microsoft 365 All users registered in your tenant (internal, external)

Segments

Segment Description
Audit-bypassed accounts Accounts excluded from mailbox audit logging.

Actions

This object does currently not have any actions.

Policy Severity Description
Account excluded from mailbox audit High Detects accounts whose mailbox activity is excluded from audit logging.

Last updated: 7/19/2026