Mailbox auditing is the foundation for ALL post-incident investigation of an account compromise. Without it, you cannot tell what an attacker did inside a mailbox — when they signed in, what mail they read, what rules they created, what they deleted. Critical actions like UpdateInboxRules must be in the default owner audit set.
A scan reports where your tenant stands on this check — pass, fail with a step-by-step fix, or not applicable if your licensing doesn’t include the feature. When Tenant Strike can’t read a setting with read-only access, it says unverified and gives you a one-command way to confirm it yourself — it never guesses.
Related Logging & Alerting checks
Check your own tenant
Is your tenant covered on "enable mailbox auditing"?
One read-only scan answers it — this check and every other one in the catalog, each with a plain-English fix. 7-day Pro trial, no credit card.