Glossary
MailItemsAccessed
Exchange Online mailbox audit action recording when mail items are accessed by any protocol or client, used to determine which messages an intruder could see.
MailItemsAccessed is an Exchange Online mailbox auditing action, recorded in the Unified Audit Log, that logs access to mail items by any protocol (POP, IMAP, MAPI, EWS, Exchange ActiveSync, REST). Microsoft documents it as part of Audit (Standard), enabled by default for Office 365 and Microsoft 365 E3/E5 users.
It has two access types. Bind records list individual messages by InternetMessageId, aggregated per two-minute window with a count in OperationCount. Sync records mean an Outlook desktop client downloaded a whole folder, which must then be treated as exposed. Records can be throttled when a mailbox generates too many of them.
It proves access by a client, not that a person read a message. See MailItemsAccessed: what it proves.