You can run the set-eventloglevel command in Exchange Management
Shell to turn on the logging against the logon that resembles the following
command:
set-eventloglevel -identity "MSExchange IS\9000 Private\Logons" -level low/medium/high/expert
After you install this hotfix, Exchange 2007 server may
audit successful access to a user folder in a mailbox. The details of the
auditing event are as follows:
Event ID 10100
Event Source MSExchangeIS Auditing
Description The folder <folder name> in Mailbox '<mailbox name>' was opened by user <domain\user>
Display Name: <folder name>
Accessing User: <legacyExchangeDN of the mailbox user>
Mailbox: <legacyExchangeDN of the mailbox user>
Administrative Rights: xx
Client Information (if Available):
Machine Name: <machine>
Process Name: xx
Process Id: xx
Application Id: xx