An audit event is a sentence: an identity performed an action on a resource. Each Microsoft 365 service decides how those parts appear in its records.

For Exchange mailbox activity, UserId identifies the actor, Operation the action, and MailboxOwnerUPN or MailboxGuid the mailbox. The actor can be a user, application or system account.

That distinction matters with shared mailboxes. If a delegate accesses one, the delegate is the actor and the mailbox is the target. Entering the shared mailbox in Purview’s Users filter searches for actions by that identity, not actions by everyone accessing the mailbox.

Microsoft documents mailbox-targeted searches using the mailbox’s primary SMTP address or Exchange GUID in Keywords. Another option is to search by operation and time range, identify matching mailbox records, then narrow to the relevant user accounts. That makes the results easier to inspect; it does not add detail to the records.

The summary row is only a starting point. Available mailbox, folder, item and client details live in the record payload, exported as JSON in AuditData. Those details connect the actor to the resource.

One important limit: MailItemsAccessed records client or protocol access, not proof that a person read a message. Record availability also depends on auditing, licensing and retention.

The useful distinction is simple: who acted is not the same as what they acted on.