Canonical distinguished name (for example, /Users/Akia Al-Zuhairi).A valid value depends on how the object is represented in the audit log. The ObjectIds parameter filters the results by the object that was modified by the cmdlet. You can only use the Parameters parameter together with the Cmdlets parameter. Use the following syntax: Search-AdminAuditLog You can use Exchange Online PowerShell or standalone Exchange Online Protection PowerShell to search for audit log entries that meet the criteria you specify. Use PowerShell to view the admin audit log If you want to print a specific audit log entry, choose the Print button in the details pane. Parameters (Parameter:Value): The cmdlet parameters that were used, and any value specified with the parameter. Object modified: The object that was modified by the cmdlet. If you select an individual search result, the following additional information is displayed in the details pane: Specify a smaller date range if you need to narrow your results. Up to 5000 entries will be displayed on multiple pages. User: The name of the user account of the user who made the configuration change. The date and time are stored in Coordinated Universal Time (UTC) format.Ĭmdlet: The name of the cmdlet that was used to make the configuration change. All configuration changes made during the specified time period are displayed, and can be sorted, using the following information:ĭate: The date and time that the configuration change was made. In the Search for changes to administrator role groups page that opens, choose a Start date and End date (the default range is the past two weeks), and then choose Search. In the EAC, go to Compliance management > Auditing, and then choose Run the admin audit log report. Visit the forums at Exchange Online or Exchange Online Protection. Having problems? Ask for help in the Exchange forums. To see what permissions you need, see the "View-only administrator audit logging" entry in the Feature permissions in Exchange Online topic.įor information about keyboard shortcuts that may apply to the procedures in this article, see Keyboard shortcuts for the Exchange admin center in Exchange Online. You need to be assigned permissions before you can perform this procedure or procedures. To connect to standalone Exchange Online Protection PowerShell see Connect to Exchange Online Protection PowerShell. To connect to Exchange Online PowerShell, see Connect to Exchange Online PowerShell. To open the Exchange admin center (EAC), see Exchange admin center in Exchange Online. What do you need to know before you begin? When an entry is older than 90 days, it's deleted.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |