Exchange Admin Audit Log Event ID 25404
25404: Set-MailboxAuditBypassAssociation Exchange cmdlet issued
This is an event from
Exchange
audit event from
LOGbinder EX
generated by
.
On this page
See also the TechNet article on the Set-MailboxAuditBypassAssociation cmdlet.
Free Security Log Resources by Randy
Field |
Description |
Occurred |
Date and time when Exchange registered the cmdlet. |
Cmdlet |
The cmdlet that was issued. |
Performed by |
The user who issued the cmdlet. |
Succeeded |
"Yes", if succeeded, "No", otherwise. |
Error |
"None", if the cmdlet resulted in no error, the error message otherwise. |
Originating server |
The host name of the server. |
Object modified |
The object that was modified by the cmdlet. |
Parameters |
The list of parameters, listing them by the parameter's Name and Value. |
Modified properties |
Modified properties, if any (otherwise "n/a"). |
Additional information |
Additional information, if any (otherwise "n/a"). |
Supercharger Enterprise
This Event Is Produced By

Which Integrates with Your SIEM
Set-MailboxAuditBypassAssociation Exchange cmdlet issued
Occurred: 12/27/2013 1:53:53 PM
Cmdlet: Set-MailboxAuditBypassAssociation
Performed by: lb.local/Users/Administrator
Succeeded: Yes
Error: n/a
Originating server: DEV1B (15.00.0516.025)
Object modified: lb.local/TestUsers/TestMailbox
Parameters
Name: Identity, Value: [TestMailbox]
Name: AuditBypassEnabled, Value: [True]
Modified Properties
n/a
Additional information: CmdletParameters/Parameter/Name= [Identity]; CmdletParameters/Parameter/Value= [TestMailbox]; CmdletParameters/Parameter/Name= [AuditBypassEnabled]; CmdletParameters/Parameter/Value= [True]
For more information, see http://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25404
Top 10 Windows Security Events to Monitor
Free Tool for Windows Event Collection