Exchange Mailbox Audit Log Event ID 25011

SourceExchange (LOGbinder EX)
LogMailbox Audit
Windows Security Log
Category
 • Subcategory
Object Access
 • Application Generated
Type Success
Failure
Discussions on Event ID 25011
Ask a question about this event

25011: Operation Update - Update Exchange mailbox item's properties

This is an event from Exchange audit event from LOGbinder EX generated by Log  Mailbox Audit.

On this page

Exchange Update action.

Free Security Log Resources by Randy

Description Fields in 25011

Field Description
Occurred Date and time when Exchange registered the cmdlet.
Operation Operation performed on the mailbox.
Result Result of the operation:
  • Failed
  • PartiallySucceeded
  • Succeeded
Originating server The host name of the server.
Mailbox GUID Destination of move or copy (if applicable) - Mailbox's Globally Unique Identifier.
Mailbox owner Mailbox user resolved name in the format DOMAIN\SamAccountName.
Mailbox owner UPN Destination of move or copy (if applicable) - Mailbox owner's User Principal Name.
Mailbox owner SID Destination of move or copy (if applicable) - Mailbox owner's SID (Security Identifier).
Folder ID ID of affected folder (if applicable).
Folder name Name of affected folder (if applicable).
Performed user name Display name of the user who performed the operation.
Performed user SID SID of the user who performed the operation.
Performed logon type Logon type of the user who performed the operation. Logon types include:
  • Owner
  • Delegate
  • Admin
Client info Details that identify which client or Exchange component performed the operation.
Client IP address IP address of the client (e.g. Outlook).
Client process name Process name of the client application as reported by the client
Client version Version of the client application as reported by the client.
Item ID ID of affected item (if applicable).
Item subject Subject of affected item (if applicable).
Item properties Properties of affected item (if applicable).
Additional information Additional information, if any (otherwise "n/a").

Setup PowerShell Audit Log Forwarding in 4 Minutes

 

Where Does This Event Come From?

This Event Is Produced By

Which Integrates with Your SIEM

Examples of 25011

Update Exchange mailbox item's properties
Occurred: 2/1/2019 3:25:44 AM
Operation: Update
Result: Succeeded
Originating server: DM6PR06MB4025 (15.20.1580.012)
Mailbox
  GUID: 442c099f-638d-4637-a879-52228b4e9349
  Owner: LOGbinder Sales Team
  Owner UPN: sales@logb****r.com
  Owner SID: S-1-5-21-552374389-1257796532-2444955936-16748769
Folder
  ID: LgAAAABeghG5b6dBSLkVu+7AXVhRAQDFdR9Divk/Tb1Fiviz3mjrAAAAAAEMAAAB
  Folder: \Inbox
Performed By
  User name: Patrick Baker
  User SID: S-1-5-21-552374389-1257796532-2444955936-9312891
  Logon type: Owner
Client
  Info: Client=MSExchangeRPC
  IP address: [31.3.153.128]:16096
  Process name: OUTLOOK.EXE
  Version: 16.0.10730.20264
Item
  ID: RgAAAABeghG5b6dBSLkVu+7AXVhRBwDFdR9Divk/Tb1Fiviz3mjrAAAAAAEMAADFdR9Divk/Tb1Fiviz3mjrAAJ9xM4iAAAX
  Subject: Undeliverable: Monitoring every endpoint catches intrusions earlier and gives you more time
  Properties: AllAttachmentsHidden, RecipientCollection
Additional information: Owner= [LOGbinder Sales Team]; LastAccessed= [2019-02-01T11:25:44+00:00]; ItemAttachments= [(30514b)]; LogonType= [Delegate]
Audit Source: General Mailbox Audit

For more information, see http://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25011

Keep me up-to-date on the Windows Security Log.
Email*:
*We will NOT share this

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection



 

Additional Resources