Overview ✨
This article explains how Microsoft 365 report privacy settings can affect mailbox-related data in Liongard, including blank Last Activity Date values and unexpected differences in the Users Active Last 30 Days metric.
⭐️ Summary: When Microsoft 365 is configured to conceal user, group, and site names in reports, Microsoft usage reporting may return anonymized identifiers instead of recognizable user values. When that happens, mailbox usage data cannot always be matched back to specific users, and mailbox-related fields may remain blank.
What this issue looks like
If report concealment is enabled in Microsoft 365, you may notice one or more of the following:
Last Activity Date appears blank for users you expect to have activity
Mailbox Type appears blank
Storage Used appears blank
Users are excluded from the Users Active Last 30 Days count even though they appear active elsewhere
Inspection results include an advisory related to mailbox usage visibility
This behavior is caused by the way Microsoft returns usage report data when identity concealment is enabled.
Why this happens
Microsoft 365 reporting can be configured to hide identifiable user, group, and site names in usage reports. When this setting is enabled, the reporting data may contain anonymized or hashed identifiers rather than the user values needed to associate mailbox usage to a specific account.
Because Liongard relies on matching mailbox usage reporting to the appropriate Microsoft 365 user record, that concealment can prevent the expected user mapping from taking place.
⚠️ Important: This is a Microsoft 365 tenant configuration behavior. It is not caused by mailbox licensing alone, and it is not resolved by re-running the inspection unless the tenant setting is changed and enough time has passed for Microsoft reporting to update.
Impact on Liongard data
When Microsoft report concealment prevents mailbox usage records from being matched to users, the following fields may remain blank:
Last Activity Date
Mailbox Type
Storage Used
This also affects any reporting logic that depends on Last Activity Date, including the Users Active Last 30 Days metric.
As a result, affected users may be excluded from activity counts even though Microsoft 365 usage exists in the tenant.
📊 Related metric behavior: If users are missing from the Users Active Last 30 Days count and their Last Activity Date is blank, review this tenant setting before assuming the issue is with the 30-day activity window itself.
How to identify this condition
Review the inspection output for mailbox usage-related status messages. In some cases, the inspection may surface an advisory under mailbox usage status indicating that de-identified names must be disabled to access this data.
Disable de-identified names in Microsoft 365 to access this data.
If you see that message, the tenant’s Microsoft reporting privacy setting is the likely cause.
How to change the Microsoft 365 setting
If your organization allows identifiable reporting, a Microsoft 365 administrator can disable the concealment setting in the Microsoft 365 admin center.
Sign in to the Microsoft 365 admin center.
Go to Settings.
Open Org settings.
Select the Services tab.
Choose Reports.
Clear the option Display concealed user, group, and site names in all reports.
Save the change.
✅ Best practice: After changing the setting, allow time for Microsoft reporting to refresh before re-running or reviewing inspection data.
What to do after making the change
Wait for Microsoft reporting to refresh.
Run a new inspection or wait for the next scheduled inspection.
Review mailbox-related fields again.
Confirm whether Last Activity Date is now populated.
Re-check the Users Active Last 30 Days count.
When this article applies
Scenario | Likely relevance | Recommended next step |
Users are missing from the active 30-day count and Last Activity Date is blank | High | Review the Microsoft report concealment setting |
Mailbox fields are blank across many or all users | High | Check whether usage report identities are concealed |
Last sign-in data differs from mailbox activity data | Moderate | Review how mailbox activity differs from sign-in reporting |
Additional guidance
If your organization requires concealed names in Microsoft reporting for privacy reasons, this behavior may be expected. In that case, mailbox usage data that depends on identifiable user mapping may remain limited.
If you are uncertain whether this tenant setting should be changed, consult your Microsoft 365 administrator and internal privacy or compliance stakeholders before making the update.