Skip to content

Latest commit

 

History

History
59 lines (44 loc) · 4.38 KB

message-trace-defender-portal.md

File metadata and controls

59 lines (44 loc) · 4.38 KB
title f1.keywords ms.author author manager audience ms.topic ms.collection ms.localizationpriority ms.assetid ms.custom description ms.service search.appverid ms.date appliesto
Message trace in the Microsoft Defender portal
NOCSH
chrisda
chrisda
deniseb
ITPro
how-to
m365-security
tier2
medium
3e64f99d-ac33-4aba-91c5-9cb4ca476803
seo-marvel-apr2020
Admins can use the Message trace link in the Microsoft Defender portal to find out what happened to messages.
defender-office-365
met150
10/9/2023
✅ <a href="https://learn.microsoft.com/defender-office-365/eop-about" target="_blank">Exchange Online Protection</a>
✅ <a href="https://learn.microsoft.com/defender-office-365/mdo-about#defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank">Microsoft Defender for Office 365 Plan 1 and Plan 2</a>
✅ <a href="https://learn.microsoft.com/defender-xdr/microsoft-365-defender" target="_blank">Microsoft Defender XDR</a>

Message trace in the Microsoft Defender portal

[!INCLUDE MDO Trial banner]

In Microsoft 365 organizations with mailboxes in Exchange Online or standalone Exchange Online Protection (EOP) organizations without Exchange Online mailboxes, message trace follows email messages as they travel through your Microsoft 365 organization. You can determine if a message was received, rejected, deferred, or delivered by the service. It also shows what actions were taken on the message before it reached its final status.

You can use the information from message trace to efficiently answer user questions about what happened to messages, troubleshoot mail flow issues, and validate policy changes.

The Summary report in the message trace contains the information that helps you answer user questions and troubleshoot mail flow issues. This Summary report enables you to view the report in a file that can be opened in Windows Explorer (also known as File Explorer).

You can use the View in Explorer option in the Message trace search results page in Exchange admin center. However, to use this option, you must fulfill the following prerequisite:

  • You must procure the E5/A5 license to access a feature within the Office 365 Threat Intelligence licensing. This feature only enables you to use the View in Explorer option.

Tip

The Message trace page in the Microsoft Defender portal is a really pass through to Message trace page in the new Exchange admin center (EAC) at https://admin.exchange.microsoft.com/#/messagetrace.

What do you need to know before you begin?

  • The maximum number of messages that are displayed in the results of a message trace depends on the report type you selected (see the Choose report type section for details). The Get-HistoricalSearch cmdlet in Exchange Online PowerShell or standalone EOP PowerShell returns all messages in the results.

  • You need to be assigned permissions before you can do the procedures in this article. You have the following options:

    • Exchange Online permissions: Membership in the Organization Management, Compliance Management or Help Desk role groups.

    • Microsoft Entra permissions: Membership in the Global Administrator* or Compliance Administrator roles gives users the required permissions and permissions for other features in Microsoft 365.

      [!IMPORTANT] * Microsoft recommends that you use roles with the fewest permissions. Using lower permissioned accounts helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.

Open message trace

In the Microsoft Defender portal at https://security.microsoft.com, go to Email & collaboration > Exchange message trace.

At this point, the Message trace page in the new EAC opens. To go directly to this page, use https://admin.exchange.microsoft.com/#/messagetrace. For more information, see Message trace in the new Exchange admin center.