Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

To investigate a compromised Microsoft 365 account, fix the time window and the affected identities first, then correlate three distinct record sources: Microsoft Entra sign-in logs, Microsoft Entra audit logs, and the Microsoft Purview Unified Audit Log (UAL). After that, check mailbox access, forwarding and inbox rules, consented applications, and administrative changes. A successful sign-in does not show that the account was used legitimately, and a single source rarely answers the whole question.

Set the scope before you search

An investigation without a written scope drifts quickly. Before you open any log, record the following in your incident notes:

  • The suspected start of the incident and the earliest symptom you can date.
  • Affected users, mailboxes, and any shared or service accounts those users could reach.
  • The tenant, the time zone your portals and exports use, and the name of the investigator running each search.
  • Known indicators, such as attacker IP addresses, unfamiliar forwarding addresses, or suspicious application names.
  • Containment already performed, with timestamps. Disabling an account or resetting a password changes the state you are about to read, so you need that timeline to interpret what you find.

Confirm auditing is on and your access is adequate

Check that auditing is enabled for the tenant before you rely on any search. Audit search is permission-controlled. Microsoft recommends least privilege, so use a role that grants audit search rather than Global Administrator by default. Reserve Global Administrator for cases where a narrower role genuinely cannot do the work. If your organization uses administrative units, a restricted administrator may see only the records inside that scope, so an investigator’s view can be narrower than the tenant’s full record set.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose the time window deliberately

Start the search before the earliest suspicious activity you can find, not at the first alert. Microsoft advises reviewing logs from just before suspicious behavior through completion of remediation. Phishing and application-consent activity can predate the first obvious symptom, so widen the window until you have found the earliest attacker-linked records rather than stopping at the first confirmed one.

#1 Best Overall
Microsoft 365 Personal | 12-Month Subscription | 1 Person | Premium Office Apps: Word, Excel, PowerPoint and more | 1TB Cloud Storage | Windows Laptop or MacBook Instant Download | Activation Required
  • Designed for Your Windows and Apple Devices | Install premium Office apps on your Windows laptop, desktop, MacBook or iMac. Works seamlessly across your devices for home, school, or personal productivity.
  • Includes Word, Excel, PowerPoint & Outlook | Get premium versions of the essential Office apps that help you work, study, create, and stay organized.
  • 1 TB Secure Cloud Storage | Store and access your documents, photos, and files from your Windows, Mac or mobile devices.
  • Premium Tools Across Your Devices | Your subscription lets you work across all of your Windows, Mac, iPhone, iPad, and Android devices with apps that sync instantly through the cloud.
  • Easy Digital Download with Microsoft Account | Product delivered electronically for quick setup. Sign in with your Microsoft account, redeem your code, and download your apps instantly to your Windows, Mac, iPhone, iPad, and Android devices.

Reconstruct identity activity from sign-in and directory logs

These sources answer different questions. Treat each as its own evidence set and cross-reference them, rather than assuming one shows the others.

Evidence source Question it answers Typical findings in this kind of investigation
Microsoft Entra sign-in logs Who authenticated, from which IP address and reported location, and whether the attempt succeeded Successful sign-ins from unfamiliar IP addresses; a run of failures followed by a success
Microsoft Entra audit logs What changed in the directory, and who initiated the change User, group, application, role, and license changes; additions of authentication methods
Microsoft Purview Unified Audit Log What users and administrators did in supported Microsoft 365 workloads Mailbox access, forwarding and inbox-rule changes, message deletion, file activity
Microsoft Defender records Which security alerts, incidents, and response actions were recorded Incident timeline and actions taken by security tooling

Start with sign-in logs. In the Microsoft Entra admin center, open Monitoring & health, then Sign-in logs, and filter to the affected user and your window. For each attempt, note the IP address, the reported location, the timestamp, and whether it succeeded or failed. Compare these against the user’s normal pattern of working hours, devices, and countries. Give particular attention to successful sign-ins that follow a run of failures, and to sign-ins that occur shortly before mailbox or directory changes.

Location data is a lead, not an identification. Reported locations are derived from IP addresses, and an IP-based location does not establish the precise physical location of the person behind a session. Use it to prioritize your review, then corroborate with other records.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Next, open Monitoring & health and then Audit logs in the same portal. These show directory changes such as user, group, application, and license updates, along with the initiating account. Entra audit logs are not the same as sign-in logs or the Unified Audit Log, so label every finding with the source it came from.

Search the Purview audit log

Microsoft’s audit search, reached through the Microsoft Purview portal and also available in the Microsoft Defender portal, is the main workspace for user and administrator activity in supported Microsoft 365 services. Work through it in this order:

  1. Open Audit in the Microsoft Purview portal, or open the audit search in the Microsoft Defender portal.
  2. Enter the date range from your scope notes and the time zone you recorded.
  3. Filter by the affected users. If your hypothesis is still uncertain, start with the broadest activity set, then narrow with activity filters once you know what you are looking for.
  4. When a filter name or exported column does not match what you expect, check Microsoft’s activity catalog, which maps friendly activity names to operation names.
  5. Export the results, and record the export time, the file name, and the query parameters. The export becomes your repeatable analysis set.

Verify the detailed record, not only the summary row

Most audit records include an IP address and client details, but the properties present vary by operation. A summary row can look ordinary while the detail shows an unfamiliar client, or a session you cannot match to any sign-in. Open each record that matters and read its full properties before you classify it.

Map each finding to an operation you can explain

Group what you find by operation: forwarding changes, inbox-rule creation, message deletion, mailbox access, and administrative actions. For each group, state what the operation did, which account and IP address performed it, and whether a legitimate owner could have made the change. This is the point where an audit record becomes evidence. A row on its own is only a claim.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Know the latency and retention limits before you read an empty result

Microsoft’s audit search documentation states that core services such as Exchange, SharePoint, OneDrive, and Teams typically return audit records 60 to 90 minutes after the event. That is a typical window, not a commitment. Microsoft does not guarantee a specific time, and delays or outages can happen. The documentation puts the point directly:

“Microsoft doesn’t guarantee a specific time after an event occurs for the corresponding audit record to be returned in the results of an audit log search.”

In practice, if a search covering the last hour returns nothing, rerun it later before drawing any conclusion, and note the gap in your coverage record.

Rank #3
Cryptnox FIDO2 Security Key NFC Smart Card for 2FA MFA Passwordless Login
  • FIDO2 CERTIFIED: FIDO Alliance Certified FIDO2 v2.1 and CTAP Level 1 for 2FA and MFA on Google Microsoft Apple GitHub login.gov AGOV SwissID and any WebAuthn service
  • PASSKEY READY: Works as a hardware passkey for passwordless sign-in where the service enables it and as a U2F and WebAuthn security key everywhere else
  • CERTIFIED SECURITY: NXP JCOP 4.5 secure element rated Common Criteria EAL6+ (augmented)
  • TAP OR INSERT: Dual NFC ISO 14443 and contact ISO 7816 interface in an ID-1 format smart card that is passive and battery-free
  • BUILT TO LAST: Passive smart card made in Switzerland designed by Swiss company Cryptnox and backed by a 2 year manufacturer warranty

Retention depends on license and policy

Retention is not one number for the whole tenant. Microsoft’s current figures, as checked in 2026, are summarized below. Confirm the subscription and policy that apply to your tenant before you rely on them.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Tier or configuration Retention stated by Microsoft Conditions
Audit Standard, records generated before October 17, 2023 90 days These records may remain on the prior 90-day period.
Audit Standard, records generated on or after October 17, 2023 180 days Default baseline for qualifying records.
Audit Premium, specified workloads and appropriately licensed users One year Applies to the specified workloads and eligible users; confirm the exact subscription and policy.
Audit Premium with the additional per-user add-on license Up to 10 years Requires the add-on license for each user concerned.
Custom retention policy Length not stated Can extend retention for eligible users and workloads; the period depends on the policy configured in the tenant.

Calculate your own horizon. On 9 October 2026, a 180-day Audit Standard default would reach back only to records generated on or after about 12 April 2026. Anything earlier in your tenant may have aged out, so the earliest activity may not appear in the UAL at all. In that case, rely on the other evidence sources and document the gap rather than treating the absence as proof.

How can I tell which emails an attacker accessed?

MailItemsAccessed records are the primary Microsoft 365 evidence for mailbox reads. They help only if your tenant’s audit configuration actually produces them and the retention window still covers the period. Confirm both before you build conclusions on them.

Build the access picture from context fields

Each record carries context you can filter on: client IP address, client and protocol, session, user, mailbox, and access type. Group the records by session and IP address first. A cluster of accesses from an IP address you cannot tie to the user’s normal devices is your starting point for scoping.

Read bind and sync context with its caveats

Microsoft’s guidance treats matching sync context as a sign that the mailbox was synchronized. Look for sync activity in the same context as the attacker’s other activity, meaning the same IP address, client, and session window. Microsoft’s guidance is to assume broad mailbox exposure in that case, so treat the whole mailbox as potentially read rather than only the items you can enumerate. Bind-type records generally reflect individual items being opened, so a set of bind records narrows the exposure, while sync records widen it. This is Microsoft’s investigative guidance, not an independent finding that every sync event means full exposure. Record your reasoning and its limits in your report.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Microsoft System Builder | Windоws 11 Home | Intended use for new systems | Install on a new PC | Branded by Microsoft
  • STREAMLINED & INTUITIVE UI, DVD FORMAT | Intelligent desktop | Personalize your experience for simpler efficiency | Powerful security built-in and enabled.
  • OEM IS TO BE INSTALLED ON A NEW PC with no prior version of Windows installed and cannot be transferred to another machine.
  • OEM DOES NOT PROVIDE SUPPORT | To acquire product with Microsoft support, obtain the full packaged “Retail” version.
  • PRODUCT SHIPS IN PLAIN ENVELOPE | Activation key is located under scratch-off area on label.
  • GENUINE WINDOWS SOFTWARE IS BRANDED BY MIRCOSOFT ONLY.

Scope the exposure in writing

  1. Establish the attacker access window from sign-in records and the first suspicious activity.
  2. Pull MailItemsAccessed records for each affected mailbox across that window.
  3. Group the records by session and client IP address, and separate bind records from sync records.
  4. Check whether any sync record shares a context with attacker activity. If it does, record the broader exposure assumption.
  5. State which mailboxes, which period, and which evidence support each conclusion.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Find persistence before you treat the account as clean

A compromised account is often not the whole problem. Attackers who want to keep access tend to leave changes that survive a password reset. Check each area below. In each case, use the audit record to establish the change, then verify whether someone authorized it.

How do I find who set up email forwarding in Microsoft 365?

Check the mailbox’s forwarding configuration for external or unfamiliar destinations. Then search the audit log for forwarding-related operations across your window. The matching record shows which account made the change, along with the IP address and client involved. In a compromise, that account is usually the victim’s own, so the IP address and session context are what show the change was not made by the owner. Confirm the change with the mailbox owner, and remove forwarding only after you have recorded its details.

Inspect inbox rules

Review every inbox rule in each affected mailbox, not only the rules you already know about. Rules that forward, redirect, delete, or move messages, for example into folders the user rarely checks, are a common way to hide attacker activity from the owner. Use the audit log to find when each rule was created or changed, and from which session.

Check registered authentication methods

For each affected account, compare the registered authentication methods with what the owner recognizes. An unfamiliar method added during your window is a persistence candidate. Such a change should be traceable in Entra audit logs. If you cannot find it there, record that gap.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Review consented applications and application roles

Microsoft’s application investigation guidance describes two patterns. In consent phishing, a user is tricked into granting an application access to mail or files. In the other pattern, a compromised administrator creates an application to keep access or collect data. For both, check consent grants and application role assignments in Microsoft Entra, identify the application and the account that granted it, and then validate that against your change records. An application created during your window is a finding even if its name looks legitimate.

Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Look for unexpected administrator changes

Search Entra audit logs for role assignments, group membership changes, and user or license updates made by accounts in your scope. An attacker with administrative rights may change more than one account. A change you did not expect is a lead even when it does not involve the original victim.

Contain the account without erasing the trail

Containment limits further damage, but it also changes the records you are investigating, so the order matters. Export and preserve the evidence first, then act. Microsoft’s compromised-account guidance recommends the following sequence:

  1. Disable the affected account for the duration of the investigation.
  2. Revoke active sessions so that existing sign-ins stop working.
  3. Check the account’s registered authentication methods, and remove any you cannot attribute to the owner after recording them.
  4. Review consented applications and role assignments, and revoke any that are not authorized.
  5. Remove suspicious forwarding and inbox rules after recording their settings.

Containment does not answer how the attacker got in, or whether other accounts were affected. Treat those as separate questions with their own evidence, and do not close the incident on containment alone.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Document what you searched and what you could not see

A finding is only as strong as the description of the search behind it. Record these items with each export or conclusion:

  • The exact query, including activity filters, identities, and workloads.
  • The time range and the time zone used by the portal and the export.
  • The role and permissions used, and any administrative-unit scope in effect.
  • The export time, file name, and record count.
  • The retention tier that applied to the period, and any gap it creates.
  • Latency or outage observations during the search, and the time you reran any empty query.

When a record set is incomplete, write down what is established and what is not. For example: “Purview audit records show a forwarding rule created on a given day from a given IP address. Records for the period before the retention cutoff were not available, so the earliest activity cannot be confirmed.” Keeping findings and limits in separate sentences makes the report easier to defend.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.