S-1-5-18 is using SendAs permissions in Office 365 (Exchange)

Venkatesh 36 Reputation points
2020-08-19T11:23:03.867+00:00

Hi- "S-1-5-18" is a well know operating system service account. On the exchange audit logs, i notice that this account is using SendAs permissions to send email on behalf of other mailboxes. Also, "Operation":"Create" kind of events are seen in very large numbers associated with several mailboxes. What is the rational behind these operations that are associated with "S-1-5-18" ? Is this expected behavior? What is the use of this account in Office 365 ? Trying to understand this because it helps me setup threat detection use cases on SIEM.

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,606 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Andy David - MVP 147.6K Reputation points MVP
    2020-08-19T13:49:19.597+00:00
    0 comments No comments

  2. Joyce Shen - MSFT 16,661 Reputation points
    2020-08-20T02:55:51.503+00:00

    As Andy said, the behavior is expected. The links provided above are also very useful, they point out that

    Audit records with S-1-5-18 captured in the UserId property record the generation of a welcome message for a new team.
    Audit records are generated when Teams sends a welcome message.
    Audit records are generated for the group mailbox when a member posts a message to a conversation in an Outlook group using OWA. Records are not generated when messages are posted with other clients or arrive from guest members.
    Audit records are generated for the group mailbox when someone updates a task in Planner.

    Below link discussed the related question as well for your reference: Why do I see User s-1-5-18 in Investigate?

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.