M365 Security Portal - Audit Logs

karthik palani 1,016 Reputation points
2024-05-14T07:53:59.04+00:00

Dear All,

I have security admin access, under email and collaboration - explorer. I can see all important users email and i can preview and download it. My management wanted to audit or disable this feature. Please advice on how to do it. No where it is getting audited.

Email Preview.png

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
3,998 questions
Microsoft Exchange
Microsoft Exchange
Microsoft messaging and collaboration software.
418 questions
Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,786 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Bruce Jing-MSFT 1,305 Reputation points Microsoft Vendor
    2024-05-15T07:36:38.3933333+00:00

    Hi,

    Thanks for posting your question in the Microsoft Q&A forum.

    This is the method I offered based on your description :

    1. If management wants to audit the administrator's actions on email, they can search the audit logs in Microsoft purview.

    A screenshot of a computerDescription automatically generated

    1. According to the official Microsoft documentation I looked up, it's because your role group has the Preview role that you can view or download emails.

    A screenshot of a computerDescription automatically generated

    You find the Data Investigator or eDiscovery Manager role group in Permissions in Microsoft Defender(https://security.microsoft.com/emailandcollabpermissions) to see if you are in this role group. If yes, remove the Preview role. If not, check if there is a custom role group and remove the Preview role.

    Here are my tests:

    1. I added myself to the Data Investigator role group.

    A screenshot of a computerDescription automatically generated

    2.Found myself available to view or download emails.

    A screenshot of a computerDescription automatically generated

    1. Then removed myself from the role group and tested again and found that I could not view or download the email.

    A screenshot of a computerDescription automatically generated

    Finally, there is a delay in this modification, so it is recommended to wait 24 hours after the modification.

    If my answer is helpful to you, please mark it as the answer so that other users can refer to it. Thank you for your support and understanding.