Description:
Verifies that every user mailbox has mailbox auditing enabled and includes the CIS-required Owner, Delegate and Admin audit actions.
Why:
Ensure every user mailbox has mailbox auditing enabled and includes the CIS-required Owner, Delegate, and Admin audit actions.
Status detail shown in Augmentt: N of M user mailboxes are missing required mailbox audit configuration.
This check reports a count rather than a simple pass/fail. It is Configured when every in-scope item is compliant, Partially Configured when some are, and Not Configured when none are.
Scoring: Scored proportionally — the check contributes according to how many of the in-scope items are compliant, so a partially compliant tenant earns partial credit.
Category: Exchange
Microsoft Licensing: Works with Basic licensing
Secure Score Impact: YES — Microsoft publishes the improvement action "Ensure mailbox auditing for all users is enabled".
Remediation in Augmentt: Configure directly in Augmentt (Configure tab); Guided remediation steps (Instructions tab)
Compliance Frameworks:
CIS Microsoft 365 Benchmark v6 (Level 1) — 6.1.2
CIS Controls v8 — 8.2
Microsoft documentation:
_KB status: new — this check is not yet documented in the knowledge base._
_Source: Augmentt native check, aligned to the CIS Microsoft 365 Foundations Benchmark. Check ID AUG.CIS.M365.6.1.2 (module 1087)._
Sourced for this page:
Secure Score — Microsoft Learn publishes the Secure Score improvement action "Ensure mailbox auditing for all users is enabled".
Draft metadata — apply these as Stonly tags in the console, then delete this block. The Stonly API cannot set tags, so they are recorded here instead.
Tags: posture-check · compliance-audit · Exchange Online · Exchange · M365 Basic · CIS M365 v6 L1 · CIS v8
