Reporting and message trace in EOP
The improved Microsoft 365 Defender portal is now available. This new experience brings Defender for Endpoint, Defender for Office 365, Microsoft 365 Defender, and more into the Microsoft 365 security center. Learn what's new.
- Exchange Online Protection
- Microsoft Defender for Office 365 plan 1 and plan 2
- Microsoft 365 Defender
In Microsoft 365 organizations with mailboxes in Exchange Online or standalone Exchange Online Protection (EOP) organizations without Exchange Online mailboxes, EOP offers many different reports that can help you determine the overall status and health of your organization. There are also tools to help you troubleshoot specific events (such as a message not arriving to its intended recipients), and auditing reports to aid with compliance requirements.
- Microsoft 365 groups activity: View information about the number of Microsoft 365 groups that are created and used. For more information, see Microsoft 365 Reports in the admin center - Microsoft 365 groups.
- Email activity: View information about the number of messages sent, received, and read in your whole organization, and by specific users. For more information, see Microsoft 365 Reports in the admin center - Email activity.
- Email app usage: View information about the email apps that are used. This includes the total number of connections for each app, and the versions of Outlook that are connecting. For more information, see Microsoft 365 Reports in the admin center - Email apps usage.
- Mailbox usage: View information about storage used, quota consumption, item count, and last activity (send or read activity) for mailboxes. For more information, see Microsoft 365 Reports in the admin center - Mailbox usage.
Security reports in the Microsoft 365 defender portal
These enhanced reports provide an interactive reporting experience for EOP admins, which includes summary information, and the ability to drill down for more details.
- Defender for Office 365: View information about Safe Links and Safe Attachments that are part of Microsoft Defender for Office 365. For more information, see View Defender for Office 365 reports in the Microsoft 365 Defender portal.
- EOP: View information about malware detections, spoofed mail, spam detections, and mail flow to and from your organization. For more information, see View email security reports in the Microsoft 365 Defender portal.
Custom reports using Microsoft Graph
Programmatically create reports that are available in the admin center by using Microsoft Graph. For more information, see Overview of Microsoft Graph and Working with Office 365 usage reports in Microsoft Graph.
Follows email messages as they travel through EOP. You can determine if an email message was received, rejected, deferred, or delivered by the service. It also shows what actions were taken on the message before it reached its final status.
You can use this information to efficiently answer your user's questions, troubleshoot mail flow issues, validate policy changes, and alleviates the need to contact technical support for assistance.
Tracks specific changes made by admins to your organization. These reports can help you troubleshoot configuration issues or find the cause of security or compliance-related problems. See Auditing reports in Exchange Online.
Reporting and message trace data availability and latency
The following table describes when EOP reporting and message trace data is available and for how long.
|Report type||Data available for (look back period)||Latency|
|Mail protection summary reports||90 days||Message data aggregation is mostly complete within 24-48 hours. Some minor incremental aggregated changes may occur for up to 5 days.|
|Mail protection detail reports||90 days||For detail data that's less than 7 days old, data should appear within 24 hours but may not be complete until 48 hours. Some minor incremental changes may occur for up to 5 days.
To view detail reports for messages that are greater than 7 days old, results may take up to a few hours.
|Message trace data||90 days||When you run a message trace for messages that are less than 7 days old, the messages should appear within 5-30 minutes.
When you run a message trace for messages that are greater than 7 days old, results may take up to a few hours.
Data availability and latency is the same whether requested via the admin center or remote PowerShell.