Beruflich Dokumente
Kultur Dokumente
In the current article, we will review the four options that we can use for recovering
mail items in the Exchange Online environment.
The available tools for recovering mail items are:
1. Recovering deleted mail items by using Outlook and OWA mail clients.
2. Recovering deleted mail items by using MFCMAPI utility.
3. Recovering deleted mail items by using Exchange In-Place eDiscovery and
Hold.
4. Recovering deleted mail items by using the PowerShell cmdlets SearchMailbox and New-MailboxSearch.
The characters of our scenario are as follows:
An organization user calls us and complain that some of his mail disappeared. We
have implemented our due diligence and perform a mailbox search to verify if the
mail its still exists in the user mailbox.
In the current time, we are entering into the phase in which we assume that the
mail item was deleted and we want to check if we the specific mail items are still
recoverable.
The two main questions that relate to this scenario are:
Q1: What are the recovery mail methods that are available for us in the Office 365
and Exchange Online environment?
Q2: Does the mail item is still recoverable meaning, can we still save the deleted
mail item?
The scenario in which only the Exchange Administrator can recover mail items are:
1. Hard delete
A scenario in which the user deletes also the mail item that was stored in
the Deletion folder(hard delete). In this case, the mail will be placed in
the Purges folder.
The user doesnt have access permission to the Purges folder (only the
Exchange Online Administrator can view the content of this folder).
2. Mailbox with Litigation Hold or In-Place Hold
In case that the mailbox was configured with Litigation Hold or In-Place Hold, the
ability to recover deleted mail items older than 14 days (the default Deleted
Item retention policy in Exchange Online is 14 days), only the Exchange Online
administrator has the ability to recover this mail items.
Search-Mailbox
New-MailboxSearch
For example, the PowerShell cmdlets Search-Mailbox considers is older than the
new PowerShell cmdlets: New-MailboxSearch but, the PowerShell cmdlets
Search-Mailbox includes capabilities that the newer PowerShell cmdlets dont
have such as the ability to search and recover mail items only from
the Recoverable Items folder.
If you want to get a detailed review of how to use these PowerShell cmdlets, you
can read the article Recovering deleted mail items using PowerShell cmdlets
Search-Mailbox | 7#7
3. Mail client (Outlook\OWA)
The mail clients Outlook and OWA, include a built-in option that enables users to
recover mail items. The Outlook\OWA recovery mail items interface enables the
user (the mailbox owner) to view the content of the Deletion folder + recover mail
items. In other words, enable the user to recover mail items from a Soft delete
event.
4. MFCMAPI
The MFCMAPI is a very powerful GUI tool, that enables users (the mailbox owner or
another user that have Full access permission to the mailbox) to have access to the
behind the scenes of the mailbox content.
The MFCMAPI tools can provide many capabilities for a variety of troubleshooting
scenarios but in this article, we will review only a very specific capability of
the MFCMAPI -the capability of enabling users to access the hiding partition
Recoverable Items folder.
In the current article, we will review the following methods for recovering mail
items in Exchange Online environment:
One important concept that I would like to emphasize is that, the process of
recovering deleted mail items doesnt restore the mail item to the original folder
in which the mail item was originally created but instead, to the folder that host
the mail item before he was deleted meaning the Deleted items folder.
For example a scenario in which user delete a mail item that is stored within a
mailbox folder named: Customers.
When the user deleted the mail, the mail is moved to the Deleted items folder. In
case that the mail item was removed (deleted) also from the Deleted items
Written by Eyal Doron | o365info.com | Copyright 2012-2015
folder and, the user decides that he wants to recover the mail item, the recovered
mail items will be restored back to the Deleted items folder and not to the
original folder (Customer folder in our scenario).
In the following screenshot, we can see we can see an example in which we recover
a specific mail item.
After the mail item is successfully restored, we can see that the new location of
the mail item is the Deleted items folder.
To be able to display the Deleted items folder, choose the More option.
(The OWA default view in an Exchange Online environment is a minimized view
that doesnt display the Deleted items folder).
In the new window that appears, you will be able to see a list of mail items that can
be recovered.
On the right bottom of the screen, you can see the option of: Recover or Purge
Additional reading
One of the most relevant examples for the need to use the MFCMAPI tool is a
scenario of Hard Delete.
Just a quick reminder the term Hard Delete, define a scenario in which the user
(or other element) deletes the mail item from the Deleted items folder + also
purges the mail item from the recovery folder (the Deletion folder).
In this scenario, the mail is relocated or moved to the Purges folder and the
standard Outlook or the OWA mail client interface, doesnt enable users to get
access to the Purges folder.
In this case, we have a couple of options -the Exchange Administrator can use the
Exchange Online in-place eDiscovery option (a tool that is available via the
Exchange Online web management interface) for searching and recovering the mail
item.
But in a scenario in which we are not able to access the Exchange Online admin
interface or, in a scenario in which a standard user doesnt have the required
administrative right for accessing the Exchange Online in-place eDiscovery, we can
use the powerful ability of the MFCMAPI tool for trying to recover mail items from a
Hard delete scenarios.
Export the deleted mail items into a mail message format (msg file).
Copy deleted mail items into inbox folder.
To be able to recover the deleted mail items that is stored in the Purges folder we
will use the MFCMAPI tool. We will use the MFCMAPI tool for login to the John
mailbox and then, recover a specific mail item using the Export option and using
the Copy option.
To be able to view the content of the user mailbox we need to login, to Johns
mailbox (the MFCMAPI tool mimics Outlook client behavior).
Using the MFCMAPI tool, enable us to get a clear view of the physical mailbox
structure.
The most top container is the Root container that includes sub partitions such as:
Top of Information store this is the mailbox partition that contains the
standard mailbox folder that we know such as: inbox, sent items, etc.
To be able to recover the deleted mail items we will click on the Recoverable
items folder.
In the option box: Format to save message, choose the suitable format for your
needs. In our example, we will choose MSG File (UNICODE)
In our example, we will save a copy of the deleted mail item in a folder
named: Recover Mail.
In the following screenshot, we can see the mail item that was saved in the
folder.
Choose the inbox folder and under the inbox folder choose the specific folder
that will be used for saving the copy of the recovered mail items. In our scenario,
we choose the folder named: John recover Mail items
In our scenario we want to copy the recovered mail items and not move the
recovered mail items. We will not check the option box Move message instead of
copy
In the following screenshot, we can see the mail item that was recovered.
Additional reading