Skip to main content

Exchange EWS eDiscovery Powershell Module

eDiscovery is one of the more useful features introduced in Exchange 2013, and offers a quick and powerful way of Searching and reporting on Items in a Mailbox or across multiple mailboxes on an Exchange Server or in Exchange Online. In this post I wanted to rollup a few eDiscovery scripts I posted in the past to a more user friendly and expandable PowerShell module.

eDiscovery uses KQL (Keyword Query Language) to search indexed properties which are listed on . For doing quick reporting with eDiscovery you can tell Exchange to only return the number (and size) of the items that match your KQL query. Otherwise Exchange will return preview items (200 at time) which means the query can take some time to complete if your enumerating though a large result set.

I've tried to take a very modular approach with the code in this module to make it easier to extend

Permissions - The eDiscovery parts of this module requires the account that is running the script be a member of the Discovery Search RBAC role see . The code that gets the FolderPath does require the user running the script have rights to the Mailbox or EWS Impersonation rights.

Here are what the cmdlet's in the Module can do at the moment


This is just a generic cmdlet you can either enter in some KQL to make a query or entering in a Start and End Date to create a report of Items in a particular Date Range eg to show email from the Last month

Get-MailboxItemStats -MailboxName -Start (Get-Date).AddDays(-31) -End (Get-Date)

this will show results like

If you use the FolderPath switch this will instead show a folderlevel view of the results to get the folder list it must use the previewItems which are slower to retrieve eg

Get-MailboxItemStats -MailboxName -Start (Get-Date).AddDays(-31) -End (Get-Date) -FolderPath

would yield a results like


This is from one of my previous posts and returns a list of ItemTypes in a Mailbox, I've added a parameter so you can do a query on just one itemtype as well. So running it like this would yield a report of the Contacts in a Mailbox and where they are located


This lets you report on the From,To,CC and BCC fields of a message with Exchange these fields are indexed in the Participants property (as well as there own keywords for Recipients, to etc). Some cool things you can do with this is query Mailbox Traffic to and from a particular domain eg

If you then want to know more about one particular recipient type you can take the value in the Name property and use that in Get-MailboxItemTypeStats eg


One of the more useful things that you can do with this module is search and download attachments from a Mailbox using eDiscovery which you can't easily automate in the eDiscovery Console. So I've got a few different options for this. First I have


This works like the ItemType cmdlet in that it makes use of doing multiple OR queries on a list of attachment types. By default if you don't pass in an array of Attachmenttypes to query I have a list of 8 common types so it will produce a report like this

If you want to run a query based on one AttachmentType across folders you can use something like the following

Or limit it to one particular Attachment Name


You can download attachments using this cmdlet eg

If Exchange online if you have reference Attachments located in One Drive the module does have code to detect and download those using the sharepoint client libraries. You do need to change the version in

$ExchangeVersion = [Microsoft.Exchange.WebServices.Data.ExchangeVersion]::Exchange2013_SP1


$ExchangeVersion = [Microsoft.Exchange.WebServices.Data.ExchangeVersion]::Exchange2015

I've put the Module up on GitHub

You can download a copy of the script from here I've include a compile version of the latest version of the Managed API which include the update to process reference attachments.

Popular posts from this blog

Export calendar Items to a CSV file using EWS and Powershell

Somebody asked about this last week and while I have a lot of EWS scripts that do access the Calendar I didn't have a simple example that just exported a list of the Calendar events with relevant information to a CSV file so here it is. I've talked on this one before in this howto  but when you query the calendar folder using EWS you need to use a CalendarView which will expand any recurring appointments in a calendar. There are some limits when you use a calendarview in that you can only return a maximum of 2 years of appointments at a time and paging will limit the max number of items to 1000 per call. So if you have a calendar with a very large number of appointments you need to break your query into small date time blocks. In this example script I'm just grabbing the next 7 days of appointments if you want to query a longer period you need to adjust the following lines (keeping in mind what I just mentioned) #Define Date to Query $StartDate = (Get-Date) $EndDate

Downloading a shared file from Onedrive for business using Powershell

I thought I'd quickly share this script I came up with to download a file that was shared using One Drive for Business (which is SharePoint under the covers) with Powershell. The following script takes a OneDrive for business URL which would look like This script is pretty simple it uses the SharePoint CSOM (Client side object Model) which it loads in the first line. It uses the URI object to separate the host and relative URL which the CSOM requires and also the SharePointOnlineCredentials object to handle the Office365 SharePoint online authentication. The following script is a function that take the OneDrive URL, Credentials for Office365 and path you want to download the file to and downloads the file. eg to run the script you would use something like ./spdownload.ps1 '

Writing a simple scripted process to download attachmentts in Exchange 2007/ 2010 using the EWS Managed API

Every complicated thing in life is made up of smaller simpler building blocks, when it comes to writing a script (or any code really) the more of these little building blocks you have to figure out the more the process of solving a problem can become bewildering. The Internet generally provides you with lots of half eaten sandwiches of information something someone else has taken a bite out but a lot of the time half done, and as with any code its usefulness declines over time as new and better API's and methods are derived. In this post I'm going to go through a simple scripted process that hopefully covers a few more of these smaller building blocks that you might face when asked to come up with a simple costless solution to perform an automated business function with a script. So the process im going to look at is one that comes up a lot and that is you have an Email that comes into to certain mailbox every day with a certain subject in my case "Daily Export" this
All sample scripts and source code is provided by for illustrative purposes only. All examples are untested in different environments and therefore, I cannot guarantee or imply reliability, serviceability, or function of these programs.

All code contained herein is provided to you "AS IS" without any warranties of any kind. The implied warranties of non-infringement, merchantability and fitness for a particular purpose are expressly disclaimed.