Description:

Verifies that every user mailbox has mailbox auditing enabled and includes the CIS-required Owner, Delegate and Admin audit actions.

Why:

Ensure every user mailbox has mailbox auditing enabled and includes the CIS-required Owner, Delegate, and Admin audit actions.

Status detail shown in Augmentt: N of M user mailboxes are missing required mailbox audit configuration.

This check reports a count rather than a simple pass/fail. It is Configured when every in-scope item is compliant, Partially Configured when some are, and Not Configured when none are.

Scoring: Scored proportionally — the check contributes according to how many of the in-scope items are compliant, so a partially compliant tenant earns partial credit.

Category: Exchange

Microsoft Licensing: Works with Basic licensing

Secure Score Impact: YES — Microsoft publishes the improvement action "Ensure mailbox auditing for all users is enabled".

Remediation in Augmentt: Configure directly in Augmentt (Configure tab); Guided remediation steps (Instructions tab)

Compliance Frameworks:

  • CIS Microsoft 365 Benchmark v6 (Level 1) — 6.1.2

  • CIS Controls v8 — 8.2

Microsoft documentation:


_KB status: new — this check is not yet documented in the knowledge base._

_Source: Augmentt native check, aligned to the CIS Microsoft 365 Foundations Benchmark. Check ID AUG.CIS.M365.6.1.2 (module 1087)._

Sourced for this page:

  • Secure Score — Microsoft Learn publishes the Secure Score improvement action "Ensure mailbox auditing for all users is enabled".


Draft metadata — apply these as Stonly tags in the console, then delete this block. The Stonly API cannot set tags, so they are recorded here instead.
Tags: posture-check · compliance-audit · Exchange Online · Exchange · M365 Basic · CIS M365 v6 L1 · CIS v8