How Do You Monitor Mailbox Activities in Defender for Cloud Apps?

Implement and manage Microsoft Defender for Cloud Apps
Answer Correct answer: C — Enable mailbox audit logging so Exchange Online records the mailbox activities that Defender for Cloud Apps then displays.

You have a Microsoft 365 E5 subscription. You need to use Microsoft Defender for Cloud Apps to monitor user mailbox activities. What should you do?

  1. Create an activity policy.
  2. Create an access policy.
  3. Enable mailbox audit logging. Correct Answer
  4. Create an app connector for Microsoft 365.

Community Votes

C
54%
A
31%
D
15%

54% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the prerequisite for mailbox-visibility in MDCA — audit logging must be on before any activity exists; the trap is choosing a policy or connector action as if those alone generate Exchange mailbox telemetry.

Monitoring user mailbox activity in Microsoft Defender for Cloud Apps requires Exchange Online mailbox audit logging to be enabled first, because MDCA can only display mailbox events that Exchange actually records. This page explains why enabling mailbox audit logging (C) is the decisive step over creating an activity policy or an app connector.

Choosing A, creating an activity policy, because it sounds like 'monitoring'. An activity policy only filters and alerts on activity already present in the MDCA activity log, so with no mailbox audit logging there is nothing for the policy to match or report.

Community Discussion (8 comments)

DPAJA 👍 1 Selected: C
https://learn.microsoft.com/en-us/defender-cloud-apps/protect-office-365#:~:text=Exchange%20Mailbox%20audit%20logging%20must%20be%20turned%20on%20for%20each%20user%20mailbox%20before%20user%20activity%20in%20Exchange%20Online%20is%20logged%2C%20see%20Exchange%20Mailbox%20activities.
Meek_Learner 👍 2 Selected: C
To use Microsoft Defender for Cloud Apps to monitor user mailbox activities, follow these steps in sequence: Enable mailbox auditing in Exchange Online. Connect Microsoft 365 to Microsoft Defender for Cloud Apps (App Connector). Create an activity policy in Defender for Cloud Apps. Configure the activity policy to track mailbox activities. Set alerts and notifications for triggered activities. Monitor alerts and activity logs in Defender for Cloud Apps. Investigate and respond to suspicious activity as needed.
BJS78 👍 2 Selected: D
I guess the trick here is that nobody says "Exchange is in use". Because of this, I would vote on connecting the app to Defender at first.
justITtopics 👍 3 Selected: C
"Exchange Mailbox audit logging must be turned on for each user mailbox before user activity in Exchange Online is logged" https://learn.microsoft.com/en-us/defender-cloud-apps/protect-office-365
Hiyas 👍 1 Selected: C
Correct
Ody 👍 1
Before you can monitor mailbox activities, you have to turn on Mailbox audit logging. You also have to add a Connector. The question is a bit vague, but I am going with enabling the mailbox first.
Xive 👍 4 Selected: A
I think should be A
Preeb 👍 4
D. Create an app connector for Microsoft 365.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Microsoft Defender for Cloud Apps can surface Exchange Online mailbox activity only when that activity is first recorded by Exchange mailbox audit logging. Microsoft's own guidance for protecting Office 365 with Defender for Cloud Apps states that mailbox audit logging must be turned on for each user mailbox before user activity is logged, which makes option C the decisive action the question is looking for. Once auditing is enabled, the Microsoft 365 app connector ingests the events, they appear in the MDCA Activity log, and activity policies can then filter and alert on them. Without audit data the MDCA portal simply has nothing mailbox-related to display, no matter how many policies or connectors you configure.

Why the Other Options Are Wrong

A (activity policy) is a downstream control: policies match and alert on activity that already exists in MDCA, so creating one before any mailbox telemetry exists produces a silent, never-triggering policy. B (access policy) governs real-time session control and access to connected apps — proxying, blocking downloads and conditional access to sessions — not the collection of mailbox activity records, and Exchange mail traffic is not read through MDCA session controls. D (app connector for Microsoft 365) is genuinely part of onboarding and is the ingestion channel into MDCA, but it is not the mailbox-specific prerequisite; the documented gating requirement for seeing mailbox activity is per-mailbox audit logging being enabled.

Community Comment Notes

Sentiment strongly favors C, and justITtopics quoted Microsoft's requirement verbatim: "Exchange Mailbox audit logging must be turned on for each user mailbox". Meek_Learner laid out the full sequence — enable mailbox auditing, connect Microsoft 365 via the app connector, then create the activity policy — and concluded that the mailbox setting comes first, which matches the question's framing. Preeb and BJS78 voted D, arguing that the stem never says Exchange is already connected, a fair observation that reflects the connector's role in ingestion rather than the mailbox-data prerequisite. Xive chose A, but an activity policy cannot create the data it monitors, and as Ody summarized, "you have to turn on Mailbox audit logging" before reviewing connector choices.

Official Reference

Exam Strategy

For MDCA questions about a specific workload (mail, SharePoint, Teams), first ask whether that workload's own audit/telemetry source is enabled, then pick policies or connectors. Policies and connectors consume data; they never produce it, so a per-workload logging option is usually the prerequisite the item is testing.

Frequently Asked Questions

Why is creating a Microsoft 365 app connector (D) not the correct answer?

The app connector is how MDCA ingests Office 365 activity, but with mailbox audit logging off there is no Exchange mailbox activity for it to surface, so the mailbox setting is the required first step.

Does creating an activity policy (A) monitor user mailbox activities on its own?

No. Activity policies only filter and alert on activity already logged in MDCA, so mailbox audit logging must be enabled before a policy can ever see mailbox events.

Related Analysis

Practice All MS-102 Questions

Access 111 questions with complete answers and detailed explanations.

View Full MS-102 Practice Test →

← Back to MS-102 Study Guide