Microsoft 365

Monitor Microsoft 365 mailbox usage

DoubleCheck checks every mailbox in your Microsoft 365 tenant once a day and warns you when one comes close to its quota, before mail starts to bounce.

The problem

When an Exchange Online mailbox reaches its Prohibit Send/Receive quota, it stops receiving mail. Senders get a bounce and the user often only finds out when someone calls to ask why their mail did not arrive.

Microsoft sends a warning to the user, but users ignore it, and shared mailboxes have nobody to read it at all.

Why it matters

A full mailbox is lost mail and a support call that could have been a routine task: archive, clean up or raise the quota a few weeks earlier.

Shared mailboxes for sales, support or invoices tend to grow the fastest, and they are the ones where missed mail costs the most.

How to check it manually

In the Microsoft 365 admin center, go to Reports, Usage, Exchange, Mailbox usage. The report lists storage used and quotas per mailbox.

With Exchange Online PowerShell you can compare the size of one mailbox with its quota:

Connect-ExchangeOnline
Get-EXOMailboxStatistics -Identity user@contoso.com | Select-Object DisplayName, TotalItemSize
Get-EXOMailbox -Identity user@contoso.com -Properties ProhibitSendReceiveQuota |
  Select-Object ProhibitSendReceiveQuota

Doing that for every mailbox, every week, in every tenant is where it usually stops.

How DoubleCheck checks it

Once a day DoubleCheck downloads the mailbox usage report from Microsoft Graph and works out, for every mailbox, how full it is compared to its Prohibit Send/Receive quota.

Each mailbox is compared on its own against your warning and error levels. There is no average that hides one full mailbox behind many empty ones: if one mailbox is over the error level, the check is in error, and the result lists which mailboxes are over each level.

A mailbox that is large on purpose, such as an archive or a shared mailbox you already know about, can be excluded. It stays visible in the list, marked as excluded, but no longer triggers alerts.

Measures
The mailbox usage report of Microsoft Graph (getMailboxUsageDetail, last 7 days): for every mailbox the storage used as a percentage of its Prohibit Send/Receive quota.
Runs
Once a day by default
Status
  • Lower is better.
  • You set the warning and error levels as a percentage of the mailbox quota, for example a warning at 90% and an error at 95%.
  • You can change the levels per check.
What you need
  • An app registration in your tenant with a client secret.
  • Microsoft Graph application permission Reports.Read.All, with admin consent. It reads usage reports only, not mail.
FAQ

Frequently asked questions

Which permission does DoubleCheck need?

The Microsoft Graph application permission Reports.Read.All, approved by a Global Administrator or Privileged Role Administrator. It reads usage reports only. It cannot read mail or change anything.

Can I exclude a mailbox that is meant to be large?

Yes. You exclude it on the check page. It stays in the list, marked as excluded, so you can switch it back on later.

How up to date is the data?

DoubleCheck uses Microsoft's usage report, which Microsoft updates with a delay of a day or two. That is fast enough for mailboxes, which fill up over weeks rather than hours.

The report shows strange names instead of my users. Why?

Your tenant hides user names in usage reports. A Global Administrator can turn that off in the Microsoft 365 admin center under Settings, Org settings, Reports.

Are shared mailboxes included?

Yes, every mailbox in the report that has a Prohibit Send/Receive quota is checked.

How are my credentials stored?

The tenant ID, application ID and client secret are kept in a dedicated, encrypted secrets vault, separate from the DoubleCheck database. Access to it is restricted to DoubleCheck's own services under strict access policies.

Get started

Start monitoring with DoubleCheck

Alerts by email, SMS, Slack, Microsoft Teams or Discord. You pay per check run: cost management in the app shows what every check costs, and a longer interval lowers it.

Start monitoring