Audit Logging for Master-User Access

The master-user login feature provides administrators with direct access to user mailboxes, which is extremely useful for troubleshooting and support. However, because it bypasses the need for the user’s own credentials, it should be treated as a privileged operation and audited accordingly.

This is particularly important in multi-tenant environments, where administrators may have access to mailboxes belonging to different customers or organizations. Without clear audit records, it becomes difficult to prove who accessed a mailbox, when the access occurred, and whether the access was legitimate. Such privileged access can create privacy, compliance, and trust concerns if it is not properly tracked.

I would like to see explicit audit logging that records when a mailbox is accessed through a master-user login, including the identity of the administrator who initiated the session. This would improve accountability, simplify security investigations, and help prevent potential misuse of this powerful feature.