Exchange Mailbox Audit Log Event ID 25005
25005: Operation MessageBind - Access Exchange mailbox item
This is an event from
Exchange
audit event from
LOGbinder EX
generated by
.
On this page
Exchange MessageBind action.
This event is not logged for logon types: Delegate, Owner.
Free Security Log Resources by Randy
| Field |
Description |
| Occurred |
Date and time when Exchange registered the cmdlet. |
| Operation |
Operation performed on the mailbox. |
| Result |
Result of the operation:
- Failed
- PartiallySucceeded
- Succeeded
|
| Originating server |
The host name of the server. |
| Mailbox GUID |
Destination of move or copy (if applicable) - Mailbox's Globally Unique Identifier. |
| Mailbox owner |
Mailbox user resolved name in the format DOMAIN\SamAccountName. |
| Mailbox owner UPN |
Destination of move or copy (if applicable) - Mailbox owner's User Principal Name. |
| Mailbox owner SID |
Destination of move or copy (if applicable) - Mailbox owner's SID (Security Identifier). |
| Folder ID |
ID of affected folder (if applicable). |
| Folder name |
Name of affected folder (if applicable). |
| Performed user name |
Display name of the user who performed the operation. |
| Performed user SID |
SID of the user who performed the operation. |
| Performed logon type |
Logon type of the user who performed the operation. Logon types include:
|
| Client info |
Details that identify which client or Exchange component performed the operation. |
| Client IP address |
IP address of the client (e.g. Outlook). |
| Client process name |
Process name of the client application as reported by the client |
| Client version |
Version of the client application as reported by the client. |
| Item ID |
ID of affected item (if applicable). |
| Item subject |
Subject of affected item (if applicable). |
| Additional information |
Additional information, if any (otherwise "n/a"). |
Setup PowerShell Audit Log Forwarding in 4 Minutes
This Event Is Produced By

Which Integrates with Your SIEM