Information
You should review the Mailbox Access by Non-Owners report at least every other week. This report shows which mailboxes have been accessed by someone other than the mailbox owner.
Rationale:
While there are many legitimate uses of delegate permissions, regularly reviewing that access can help prevent an external attacker from maintaining access for a long time, and can help discover malicious insider activity sooner.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
To review the report, perform the following steps using the Microsoft 365 Admin Center:
Click Exchange.
Click Compliance Management and auditing.
Select Run a non-owner mailbox access report.
Enter Start Date and End Date.
Change Search for access by field to all non-owners.
Select Search.