SOLVED

New-ComplianceSearch list of mailboxes

%3CLINGO-SUB%20id%3D%22lingo-sub-672119%22%20slang%3D%22en-US%22%3ENew-ComplianceSearch%20list%20of%20mailboxes%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-672119%22%20slang%3D%22en-US%22%3E%3CP%3EHey%20Guys%2C%26nbsp%3B%3C%2FP%3E%3CP%3EHoping%20to%20get%20some%20assistance%20here.%20So%20this%20is%20the%20situation%2C%20one%20of%20our%20Managers%20sent%20an%20email%20to%20an%20list%20of%20200%20users.%20This%20was%20sent%20via%20single%20distro%20group.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3EI%20ran%20the%20following%20command%3A%26nbsp%3B%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENew-ComplianceSearch%20-Name%20%3CNAME%20of%3D%22%22%20search%3D%22%22%3E%20-ExchangeLocation%20distrogroup%40domain.com%20-ContentMatchQuery%20%22(From%3Auser.domain%40fqdn.com)%20AND%20(Subject%3AFW%3A%20Subject%20Name%20Here)%20AND%20(Recipients%3A%20distrogroupname%40fqdn.com)%20AND%20(Received%3A06%2F05%2F2019)%22%3C%2FNAME%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20above%20worked%20as%20expected%2C%20however%20only%2098%20members%20were%20identified%20as%20having%20received%20the%20email.%20I%20was%20able%20to%20delete%20the%20messages%20using%20new-compliancesearchaction%20however%20the%20total%20number%20of%20deletes%20should%20have%20been%20185-200.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3ESo%20then%20to%20confirm%20my%20findings%20i%20ran%20this%20command%3A%26nbsp%3B%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%24groups%7C%20%25%7BGet-MessageTrace%20-RecipientAddress%20%24_.PrimarySMTPAddress%20-StartDate%20%2206%2F05%2F2019%22%20-EndDate%20%2206%2F06%2F2019%22%20-SenderAddress%20user.domain%40fqdn.com%7D%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThen%20i%20was%20able%20to%20export%20that%20to%20a%20excel%20spreadsheet%20and%20sure%20enough%20i%20see%20197-200%20messages%20that%20were%20sent%20to%20those%20members%20of%20the%20distro%20group.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ein%20the%20above%20command%26nbsp%3B%20%24Groups%20%3D%20Get-DistributionGroupMember%20-Identity%20recip.group%40domain.com%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20as%20you%20can%20see%2C%20198%20members%20received%20the%20emails%2C%20but%20only%2098%20members%20had%20them%20deleted%20when%20using%20new-compliancesearchaction.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3EMy%20question%20is%20this%3A%3C%2FSTRONG%3E%20How%20can%20i%20use%20new%20compliance%20search%2C%20against%20a%20list%20of%20mailboxes%3F%20like%20the%20one%20in%20my%20groups%20variable%3F%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%2C%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERobert%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-672119%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ECompliance%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EExchange%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-673233%22%20slang%3D%22en-US%22%3ERe%3A%20New-ComplianceSearch%20list%20of%20mailboxes%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-673233%22%20slang%3D%22en-US%22%3E%3CP%3EAs%20you%20are%20already%20restricting%20the%20search%20by%20subject%20and%20sender%2C%20there's%20no%20point%20of%20adding%20the%20DG%20to%20the%20search%20query.%20But%20in%20theory%2C%20should%20be%20the%20same%20for%20your%20scenario%2C%20I'm%20not%20really%20sure%20why%20it's%20skipping%20some%20of%20the%20members.%20Are%20they%20all%20regular%20user%20mailboxes%3F%20Do%20you%20have%20nested%20groups%20and%20other%20object%20types%20added%20as%20members%20of%20the%20DG%3F%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F64%22%20target%3D%22_blank%22%3E%40Tony%20Redmond%3C%2FA%3E%20might%20be%20aware%20of%20some%20gotcha...%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-673486%22%20slang%3D%22en-US%22%3ERe%3A%20New-ComplianceSearch%20list%20of%20mailboxes%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-673486%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F58%22%20target%3D%22_blank%22%3E%40Vasil%20Michev%3C%2FA%3E%26nbsp%3BThe%20only%20gotcha%20I%20can%20think%20of%20is%20that%20a%20compliance%20search%20action%20can%20only%20remove%2010%20messages%20at%20a%20time%2C%20so%20you'd%20have%20to%20run%20the%20search%20and%20the%20action%20multiple%20times%20to%20find%20and%20remove%20all%20the%20messages.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20would%20use%20the%20Search-Mailbox%20cmdlet%20for%20something%20like%20this.%20It%20will%20process%20all%20the%20mailboxes%20and%20remove%20all%20the%20offending%20messages%20at%20one%20time.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-694752%22%20slang%3D%22en-US%22%3ERe%3A%20New-ComplianceSearch%20list%20of%20mailboxes%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-694752%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F58%22%20target%3D%22_blank%22%3E%40Vasil%20Michev%3C%2FA%3E%26nbsp%3BIt%20turns%20out%20that%20actually%20it%20was%20removing%20more%20messages%2C%20about%20150%20messages%20(total)%20from%20my%20list%20of%20mailboxes.%20I%20know%20this%20because%20our%20ProofPoint%20Trap%20system%20was%20able%20to%20go%20in%20and%20remove%20the%20remaining%20messages.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20also%20only%20set%20the%20cmdlet%20to%20do%20a%20softdelete.%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F64%22%20target%3D%22_blank%22%3E%40Tony%20Redmond%3C%2FA%3E%26nbsp%3BI%20was%20under%20the%20impression%20that%20the%2010%20message%20limit%20was%20per%20mailbox%20per%20run.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20for%20instance%20if%20i%20wanted%20to%20move%201%20message%20from%20a%20100%20mailboxes%20new%20compliance%20search%20would%20do%20that%20on%20one%20pass%2C%20but%20if%20i%20wanted%20to%20remove%2011%20messages%20from%20100%20mailboxes%20that%20would%20take%202%20passes%3F%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20that%20incorrect%3F%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%2C%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERobert%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-694824%22%20slang%3D%22en-US%22%3ERe%3A%20New-ComplianceSearch%20list%20of%20mailboxes%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-694824%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F78373%22%20target%3D%22_blank%22%3E%40Robert%20Bollinger%3C%2FA%3E%26nbsp%3B%20Right%2C%20as%20confirmed%20by%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fpowershell%2Fmodule%2Fexchange%2Fpolicy-and-compliance-content-search%2Fnew-compliancesearchaction%3Fview%3Dexchange-ps%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fpowershell%2Fmodule%2Fexchange%2Fpolicy-and-compliance-content-search%2Fnew-compliancesearchaction%3Fview%3Dexchange-ps%3C%2FA%3E%2C%20it%20is%2010%20items%20per%20mailbox%20per%20run.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ETo%20quote%3A%20%22%3CSPAN%3E%3CEM%3EA%20maximum%20of%2010%20items%20per%20mailbox%20can%20be%20removed%20at%20one%20time.%20Because%20the%20capability%20to%20search%20for%20and%20remove%20messages%20is%20intended%20to%20be%20an%20incident-response%20tool%2C%20this%20limit%20helps%20ensure%20that%20messages%20are%20quickly%20removed%20from%20mailboxes.%20This%20action%20isn't%20intended%20to%20clean%20up%20user%20mailboxes%3C%2FEM%3E.%22%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Frequent Contributor

Hey Guys, 

Hoping to get some assistance here. So this is the situation, one of our Managers sent an email to an list of 200 users. This was sent via single distro group.

 

I ran the following command: 

 

New-ComplianceSearch -Name <Name of Search> -ExchangeLocation distrogroup@domain.com -ContentMatchQuery "(From:user.domain@fqdn.com) AND (Subject:FW: Subject Name Here) AND (Recipients: distrogroupname@fqdn.com) AND (Received:06/05/2019)"

 

The above worked as expected, however only 98 members were identified as having received the email. I was able to delete the messages using new-compliancesearchaction however the total number of deletes should have been 185-200. 

 

So then to confirm my findings i ran this command: 

 

$groups| %{Get-MessageTrace -RecipientAddress $_.PrimarySMTPAddress -StartDate "06/05/2019" -EndDate "06/06/2019" -SenderAddress user.domain@fqdn.com}

 

Then i was able to export that to a excel spreadsheet and sure enough i see 197-200 messages that were sent to those members of the distro group. 

 

in the above command  $Groups = Get-DistributionGroupMember -Identity recip.group@domain.com

 

So as you can see, 198 members received the emails, but only 98 members had them deleted when using new-compliancesearchaction. 

 

My question is this: How can i use new compliance search, against a list of mailboxes? like the one in my groups variable? 

 

Thanks, 

 

Robert 

 

 

4 Replies
Highlighted
Best Response confirmed by Robert Bollinger (Frequent Contributor)
Solution

As you are already restricting the search by subject and sender, there's no point of adding the DG to the search query. But in theory, should be the same for your scenario, I'm not really sure why it's skipping some of the members. Are they all regular user mailboxes? Do you have nested groups and other object types added as members of the DG?

 

@Tony Redmond might be aware of some gotcha...

Highlighted

@Vasil Michev The only gotcha I can think of is that a compliance search action can only remove 10 messages at a time, so you'd have to run the search and the action multiple times to find and remove all the messages.

 

I would use the Search-Mailbox cmdlet for something like this. It will process all the mailboxes and remove all the offending messages at one time.

Highlighted

@Vasil Michev It turns out that actually it was removing more messages, about 150 messages (total) from my list of mailboxes. I know this because our ProofPoint Trap system was able to go in and remove the remaining messages. 

 

I also only set the cmdlet to do a softdelete. @Tony Redmond I was under the impression that the 10 message limit was per mailbox per run. 

 

So for instance if i wanted to move 1 message from a 100 mailboxes new compliance search would do that on one pass, but if i wanted to remove 11 messages from 100 mailboxes that would take 2 passes? 

 

Is that incorrect? 

 

Thanks, 

 

Robert

Highlighted

@Robert Bollinger  Right, as confirmed by https://docs.microsoft.com/en-us/powershell/module/exchange/policy-and-compliance-content-search/new..., it is 10 items per mailbox per run.

 

To quote: "A maximum of 10 items per mailbox can be removed at one time. Because the capability to search for and remove messages is intended to be an incident-response tool, this limit helps ensure that messages are quickly removed from mailboxes. This action isn't intended to clean up user mailboxes."