Graph change notifications via Event Hub: created notifications silently dropped for several minutes, no missed lifecycle event

Francesco 0 Reputation points
2026-10-02T09:44:45.2466667+00:00

We use Microsoft Graph change notifications to track new mail in an Exchange Online shared mailbox. The setup:

  • Resource: /users/{mailbox}/messages
  • changeType: created,updated
  • Delivery to Azure Event Hubs, with lifecycle notifications enabled on the same hub
  • Delegated permissions (Mail.ReadWrite.Shared)
  • The subscription is renewed daily and was active and well within its expiration time.

Recently, for about 7 minutes, we received no notifications at all for this subscription, although about 10 new messages arrived in the mailbox during that time. Afterwards:

  • No created notification ever arrived for those messages. For some of them the only notifications we got were changeType: updated, many minutes later. For others the only notifications came after a user moved the message to another folder.
  • No missed lifecycle notification was sent for that period. We do receive missed events normally on other occasions, so lifecycle delivery itself works.
  • When delivery resumed, notifications came in a burst, and for some items updated arrived before created.

We're fairly confident nothing was lost on our side:

  • Event Hub sequence numbers on the partition are contiguous across the gap.
  • Notifications for other subscriptions on the same Event Hub kept arriving normally during that window.

Questions:

  1. Is it expected that Graph can drop created notifications without sending a missed lifecycle event?
  2. If so, what's the recommended way to guarantee no new messages are missed? Is a periodic delta query on the subscribed folders the only reliable safeguard?
  3. Is it safe to treat an updated notification for a message we've never seen as an implicit created?
  4. Are there known delays or outages in Graph change-notification delivery to Event Hubs that would explain a gap like this?
Microsoft Security | Microsoft Graph
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.