Using an existing web application
To ensure that you will be able to audit mailbox activity:
• Upload the certificate for the web application through the Microsoft Entra admin center using App Registration | All Applications | (web application) | Certificates & secrets | Certificate | Upload certificate. The format for the certificate must be binary x.509 (.cer).
1 In the Microsoft Entra admin center, select Roles and Administrators | All roles.
2 Locate and open the Exchange administrator role.
4
6
7 Change the Assignment Type to Active, ensure the Permanently assigned option is selected and enter a Justification (required).
8 Click Assign to save the changes and verify that the web application name appears in the Members list for the Exchange Administrator role.
Disable a template
Disabling a template temporarily stops auditing activities without having to remove the template.
To disable a template
▪ Place your cursor in the Status cell for the auditing template to disable, click the arrow control, and select Disabled.The entry in the Status column for the template changes to ‘Disabled’.
2 To re-enable the auditing template, use the Enable option in either the Status cell or right-click menu.
Delete a template
To delete a template
1 On the Microsoft 365 Auditing page, select the template to delete and choose Delete | Delete Template.
2 Click Yes to confirm.
Microsoft 365 Auditing Wizard
For details on the integration points and process required to audit an organization, as well as auditing and agent considerations, see Deployment requirements.
Additional notes
If you choose to use an existing web application when you create a template, you will need to specify the application ID, application key, and a valid certificate. For required configuration, see Using an existing web application.
To create a template:
1 Under Authentication Configuration, select to Create a new web application or Use existing web application.If you select to create a new web application:
d Enter the Microsoft Entra Directory Name.
e Select Generate self-signed certificate or Select certificate to choose a previously created certificate from your personal store. By default, invalid certificates are filtered out from the list of available certificates.If you select to use an existing web application:
b Enter the Microsoft Entra Directory Name, Application ID, Application key, and select a previously created Application Certificate. For required settings and permissions, see Using an existing web application and Microsoft documentation for details on integrating applications with Microsoft Entra ID, creating a web application, and adding a certificate to a web application.
4 Click Select agent to view available agents and whether they are assigned to a template. The Microsoft 365 cell contains ‘None’ if an agent is not assigned to a template, or ‘Auditing’ if it is assigned to a template.
5To grant permission for all administrators to create a web application:
b
d To apply the consent to all the users in your organization, click to enable Consent on behalf of your organization and click Accept.
1 Under Authentication Configuration, select to Create a new web application or Use existing web application.If you select to create a new web application, select Generate self-signed certificate or Select certificate to choose a previously created certificate from your personal store. By default, invalid certificates are filtered out from the list of available certificates.
If you select to use an existing web application, enter the Application ID, Application Key, and an existing certificate. For required settings and permissions, see Using an existing web application and Microsoft documentation for details on integrating applications with Microsoft Entra ID, creating a web application, and adding a certificate to a web application.
Auditing activity selection page
Define or edit the types of activity to audit.
For a new template, before you can select to audit individual mailboxes or update the configuration to audit owner events, you need to select Finish to create the template.
You can choose from the following:
• All administrative events: This includes remote PowerShell connections to the mailbox, or any action in the web administration portal for the Microsoft 365 Exchange Online organization.Set tenant mailbox auditing settings
• Select All mailboxes for non-owner events
• Click Select mailboxes.
• To optionally add owner auditing on specific mailboxes, enable the Include Owner Activity option.The "Owner Activity" audited on a configured mailbox include folder, message and login events.
a To add or remove owner auditing on specific mailboxes enter the first letter or letters of the display name (not the mailbox name) into the bottom search field and click Search. Locate the required mailbox to enable or disable to Include Owner Activity as required.You can refine your mailbox search by selecting Non-Owner Only, Owner, or All.Use existing tenant mailbox settings
3 Click Close.
4 Click Next to optionally specify the generic events to exclude from auditing based on their operations. The operations are visible in the "Activity Name/Operation" column of the Microsoft 365 built-in searches. Generic events are dynamically created when associated activity is detected that does not have a corresponding event defined in Change Auditor.
5 Click Finish to apply the updates. When the agent’s configuration is updated, it may take some time (approximately 1 second per mailbox) for it to be applied and the auditing to start after a template is created or modified.To grant permission for all administrators to create a web application:
b
d To apply the consent to all the users in your organization, click to enable Consent on behalf of your organization and click Accept.