How Do You Monitor Mailbox Activities in Defender for Cloud Apps?
You have a Microsoft 365 E5 subscription. You need to use Microsoft Defender for Cloud Apps to monitor user mailbox activities. What should you do?
Community Votes
54% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the prerequisite for mailbox-visibility in MDCA — audit logging must be on before any activity exists; the trap is choosing a policy or connector action as if those alone generate Exchange mailbox telemetry.
Monitoring user mailbox activity in Microsoft Defender for Cloud Apps requires Exchange Online mailbox audit logging to be enabled first, because MDCA can only display mailbox events that Exchange actually records. This page explains why enabling mailbox audit logging (C) is the decisive step over creating an activity policy or an app connector.
Choosing A, creating an activity policy, because it sounds like 'monitoring'. An activity policy only filters and alerts on activity already present in the MDCA activity log, so with no mailbox audit logging there is nothing for the policy to match or report.
Community Discussion (8 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Microsoft Defender for Cloud Apps can surface Exchange Online mailbox activity only when that activity is first recorded by Exchange mailbox audit logging. Microsoft's own guidance for protecting Office 365 with Defender for Cloud Apps states that mailbox audit logging must be turned on for each user mailbox before user activity is logged, which makes option C the decisive action the question is looking for. Once auditing is enabled, the Microsoft 365 app connector ingests the events, they appear in the MDCA Activity log, and activity policies can then filter and alert on them. Without audit data the MDCA portal simply has nothing mailbox-related to display, no matter how many policies or connectors you configure.Why the Other Options Are Wrong
A (activity policy) is a downstream control: policies match and alert on activity that already exists in MDCA, so creating one before any mailbox telemetry exists produces a silent, never-triggering policy. B (access policy) governs real-time session control and access to connected apps — proxying, blocking downloads and conditional access to sessions — not the collection of mailbox activity records, and Exchange mail traffic is not read through MDCA session controls. D (app connector for Microsoft 365) is genuinely part of onboarding and is the ingestion channel into MDCA, but it is not the mailbox-specific prerequisite; the documented gating requirement for seeing mailbox activity is per-mailbox audit logging being enabled.Community Comment Notes
Sentiment strongly favors C, and justITtopics quoted Microsoft's requirement verbatim: "Exchange Mailbox audit logging must be turned on for each user mailbox". Meek_Learner laid out the full sequence — enable mailbox auditing, connect Microsoft 365 via the app connector, then create the activity policy — and concluded that the mailbox setting comes first, which matches the question's framing. Preeb and BJS78 voted D, arguing that the stem never says Exchange is already connected, a fair observation that reflects the connector's role in ingestion rather than the mailbox-data prerequisite. Xive chose A, but an activity policy cannot create the data it monitors, and as Ody summarized, "you have to turn on Mailbox audit logging" before reviewing connector choices.Official Reference
Exam Strategy
For MDCA questions about a specific workload (mail, SharePoint, Teams), first ask whether that workload's own audit/telemetry source is enabled, then pick policies or connectors. Policies and connectors consume data; they never produce it, so a per-workload logging option is usually the prerequisite the item is testing.
Frequently Asked Questions
Why is creating a Microsoft 365 app connector (D) not the correct answer?
The app connector is how MDCA ingests Office 365 activity, but with mailbox audit logging off there is no Exchange mailbox activity for it to surface, so the mailbox setting is the required first step.
Does creating an activity policy (A) monitor user mailbox activities on its own?
No. Activity policies only filter and alert on activity already logged in MDCA, so mailbox audit logging must be enabled before a policy can ever see mailbox events.
Related Analysis
Practice All MS-102 Questions
Access 111 questions with complete answers and detailed explanations.
View Full MS-102 Practice Test →