Microsoft 365 Evidence

Microsoft 365 ForensicsAudit Logs, Mailbox Access, and Proving What Was Reached

Microsoft 365 holds the mail, files, and chat records that define most business data exposure. Whether an investigation can say what an intruder actually read depends almost entirely on audit settings, licensing, and retention configured long before the incident. This page explains what those records contain and how examiners use them.

Updated August 2026 · Reviewed by Elite Digital Forensics examiners · Nationwide breach response

180 daysCommon baseline unified audit log retention at standard licensing, with longer windows available at higher tiers.
Message levelMailItemsAccessed records identify the specific items a session opened or synchronized.
Not retroactiveAuditing that was not enabled before the intrusion cannot produce records after it.

Quick answer

Microsoft 365 forensics relies on the unified audit log, which records mailbox operations, file activity in SharePoint and OneDrive, Teams events, sharing changes, and administrative actions across the tenant. For mailbox compromise the highest value records are MailItemsAccessed, inbox rule creation, forwarding configuration, and message trace. Retention depends on licensing and commonly starts around 180 days, with longer windows and advanced auditing features tied to higher tiers.

Common questions, answered in one line

QuestionOne line answer
Can you prove which emails were read?Yes when advanced mailbox auditing was licensed and enabled at the time.
How far back does the audit log go?Commonly about 180 days at baseline licensing, longer with premium tiers or audit retention policies.
Does message trace last as long?No. Detailed trace data is much shorter lived and should be exported immediately.
Can deleted email be recovered?Often, through recoverable items and holds, if a hold is applied before purge windows elapse.
Are file downloads recorded?Yes. SharePoint and OneDrive record file access, download, and sharing events.
Does eDiscovery replace forensics?No. It collects content; forensic analysis explains access, actor, and sequence.

Key terms defined

TermWhat it means
Unified audit logThe tenant wide record of user and administrative activity across Microsoft 365 workloads.
MailItemsAccessedA mailbox audit action recording that specific messages were accessed by a sync or bind operation.
Message traceDelivery records for messages entering and leaving the tenant, used for forwarding and outbound fraud analysis.
Recoverable itemsThe hidden mailbox area holding deleted content, retention of which is extended by a hold.
Litigation holdA setting that preserves mailbox content against deletion and purge for the duration of the hold.
Audit retention policyConfiguration extending how long specific audit record types are kept beyond the default window.

What the tenant records, and for how long

Microsoft 365 is not a single log. It is a set of workload specific record streams that surface through a common audit interface, each with its own coverage and licensing dependency.

SourceAnswersPractical note
Unified audit logWhat operations occurred, by which account, whenBaseline retention commonly about 180 days, extended by license or audit retention policy
Mailbox audit (MailItemsAccessed)Which specific messages a session accessedRequires appropriate licensing; the highest value record for exposure scoping
Inbox rules and forwardingAttacker hiding and exfiltration mechanismsCapture the rule definition before removing it
Message traceWhat was sent and where it was deliveredDetailed data ages out fast; export at the outset
SharePoint and OneDrive activityFile views, downloads, sharing, and deletionCentral to exfiltration questions in file heavy environments
Teams activityMessage and meeting events, membership changesIncreasingly relevant as business records move into chat
Entra ID sign in logsThe authentication behind each sessionShorter retention than the audit log, so export separately

Licensing is an evidentiary issue

Two organizations can suffer identical intrusions and reach different conclusions purely because one had advanced auditing and the other did not. Examiners must document which record types were available so that readers understand the basis and the boundaries of the findings.

Investigating a compromised mailbox

Mailbox compromise is the most common Microsoft 365 incident. The analytical goal is to bound each unauthorized session precisely and then determine what that session touched.

Step 1

Bound the intrusion. Use sign in logs to establish first and last unauthorized authentication, including non interactive sign ins that indicate token replay.

Step 2

Identify persistence. Pull audit records for authentication method registration, inbox rule creation, forwarding, delegation, and application consent.

Step 3

Determine access. Query MailItemsAccessed for the intrusion window to identify the specific items opened or synchronized.

Step 4

Trace outbound activity. Use message trace to identify fraudulent messages sent from the account and their recipients.

Step 5

Assess reach. Check whether the account was used to access files, Teams content, or other mailboxes through delegation.

Step 6

Scope exposure. Review the accessed message set for regulated data so counsel can evaluate notification duties on facts.

Where the record shows a sync operation rather than individual binds, the correct interpretation is that the entire folder should be treated as accessed. That distinction has direct consequences for the size of a notification population and should be explained explicitly in the report.

Know what was reached, not what was feared

We preserve tenant evidence and scope exposure on the records, so notification decisions rest on facts.

SharePoint, OneDrive, and Teams as exfiltration channels

As business records moved into cloud file storage and chat, the exfiltration question moved with them. A departing employee or an intruder with a valid session can move very large volumes without touching a single external tool.

Bulk download detection

Activity records showing sustained download volume from a single session, frequently just before a resignation or after a compromise.

Sharing link abuse

Anonymous or external sharing links created on sensitive libraries, which persist after the account is disabled.

Sync client activity

Registration of a new sync client that pulls entire libraries to an unmanaged device.

External guest access

Guest accounts added to Teams or sites, providing quiet ongoing access to internal content.

Version and deletion history

Records showing content altered or removed, which matters in insider and spoliation disputes.

Retention and hold interplay

Whether deleted content is recoverable depends on holds and retention policies in force at the time.

These records are also the reason preservation matters even when nothing appears wrong. A hold placed on discovery of an issue protects content prospectively, but it cannot recreate audit records that already rolled off.

Configuration that makes future investigations possible

Every Microsoft 365 investigation ends with the same observation: the useful findings came from settings enabled before anyone suspected a problem. These are the ones that matter most.

  • Verify mailbox auditing is on for every mailbox, including shared and resource mailboxes, and that the action list includes message level access.
  • Configure audit retention policies for the record types most relevant to your risk, rather than accepting the baseline for everything.
  • Stream sign in and audit data to a log analytics workspace or SIEM to hold history beyond provider defaults.
  • Alert on high signal events such as new forwarding rules, new consents, mass download, and anonymous link creation.
  • Document the configuration annually so an examiner can establish what the tenant was capable of recording.
  • Practice the export, because the first attempt should not happen during an active incident.

What matters most

  • Auditing enabled and licensed before the incident, which determines whether exposure can be scoped at all.
  • Immediate export of the shortest lived sources, particularly message trace and sign in logs.
  • Holds applied early so deleted content remains recoverable during the investigation.
  • Careful reading of sync versus individual access, since the difference changes notification scope.
  • Tenant wide review rather than single mailbox review, because lateral movement inside the tenant is common.

Common misconceptions

The audit log has everything for years

Baseline retention is measured in months, varies by record type and license, and premium record types may not have been captured at all.

We can enable auditing now and see the past

Audit configuration only affects future events. There is no retroactive capture.

eDiscovery search is the same as forensics

eDiscovery finds content. Forensics establishes who accessed it, when, from where, and under what session.

Deleting the attacker rule closes the issue

The rule definition is evidence and should be exported before removal, and the rule is rarely the only persistence.

When this applies, and when it does not

This applies when

  • A mailbox shows unfamiliar sign ins, hidden rules, or unexpected forwarding.
  • You must determine whether a compromise exposed regulated data.
  • A departing employee is suspected of downloading files from SharePoint or OneDrive.
  • Counsel or a carrier requires an independent tenant investigation.

This does not apply when

  • The organization does not use Microsoft 365 for the data at issue.
  • All relevant audit retention has expired and no export exists.
  • The matter concerns only on premises systems with no tenant involvement.
  • The need is routine legal collection with no question about unauthorized access.

Microsoft 365 record types and what each can establish

RecordEstablishesLicensing sensitivityTypical urgency to export
MailItemsAccessedSpecific messages accessedHigh, requires advanced auditingHigh
Inbox rule eventsAttacker persistence and concealmentLowHigh
Message traceOutbound fraud and forwardingLowVery high, short retention
SharePoint activityFile access, download, and sharingLow to moderateModerate
Sign in logsSession bounding and sourceModerateVery high, short retention
Admin audit eventsConfiguration and privilege changeLowModerate

How Elite Digital Forensics helps

We investigate Microsoft 365 tenants for businesses, outside counsel, and cyber insurance carriers. Our examiners preserve the short lived records first, scope exposure on the evidence rather than on assumption, and produce reports written for the people who have to make notification and claim decisions.

Emergency tenant preservation

Immediate export of audit, sign in, mailbox rule, and message trace data with documented methodology.

Mailbox compromise investigation

Session bounded reconstruction of unauthorized access with message level exposure findings where records allow.

Exfiltration analysis

Review of SharePoint, OneDrive, and Teams activity for bulk download, sharing abuse, and sync based collection.

Insider departure review

Analysis of file activity and sharing in the period before a resignation or termination.

Audit readiness assessment

Verification that licensing, auditing, and retention will support an investigation before you need one.

Expert reporting and testimony

Findings suitable for regulators, carriers, and litigation, supported by court qualified examiners.

Problems we solve

  • You need to know which specific emails an intruder read before deciding who to notify.
  • Fraudulent messages went to your clients from a real employee mailbox.
  • A former employee is suspected of taking files and you need to know what left.
  • Your carrier requires an independent scope determination before advancing the claim.
  • You are unsure whether your tenant is even configured to answer these questions.

Talk with a forensic examiner about your incident

Consultations are confidential. We work directly with affected businesses, with outside counsel, and with cyber insurance carriers and brokers nationwide.

About Elite Digital Forensics

Elite Digital Forensics is an independent digital forensics firm serving businesses, attorneys, and insurers nationwide. Our examiners include former law enforcement forensic examiners who have testified as court qualified expert witnesses in state and federal proceedings. We do not sell security software and we do not manage client networks, so our findings carry no conflict of interest when the question is whether an environment was adequately secured.

Every engagement follows documented chain of custody, defensible acquisition methods, and reporting written for attorney review, insurer submission, regulator response, or courtroom use. Work performed at the direction of counsel is generally treated as attorney work product prepared in anticipation of litigation. Call (833) 292-3733 or request a confidential consultation.

Frequently asked questions

How long does Microsoft 365 keep audit logs?

Baseline unified audit log retention commonly runs about 180 days, with longer windows available through higher license tiers and audit retention policies applied to specific record types. Sign in logs and detailed message trace have significantly shorter windows and should be exported first.

Can you prove which emails a hacker actually opened?

Where advanced mailbox auditing was licensed and enabled, MailItemsAccessed records identify the specific items a session accessed. Where the record shows a folder sync rather than individual access, the whole folder should be treated as accessed, which is an important distinction for notification scope.

What is the difference between eDiscovery and forensic analysis?

eDiscovery collects and reviews content for legal proceedings. Forensic analysis explains access: which account, from which address and device, during which session, and in what sequence. Investigations usually need both, but one is not a substitute for the other.

Can we recover email the attacker deleted?

Frequently yes. Deleted items move to the recoverable items area, and applying a litigation hold preserves that content against purge. The sooner the hold is applied, the better the odds, because purge windows continue to run until it is in place.

Does Microsoft 365 record file downloads from SharePoint and OneDrive?

Yes. File access, download, sharing link creation, sync client registration, and deletion are recorded in the unified audit log. These records are central to both intruder exfiltration analysis and departing employee investigations.

What should we do first when we suspect a tenant compromise?

Revoke sessions and refresh tokens, apply holds to affected mailboxes, export sign in logs and message trace immediately, capture inbox rules and consented applications before removing them, and engage an examiner before remediation eliminates the records needed to scope exposure.

References and authoritative sources

  1. Microsoft Purview, Manage audit log retention policies — https://learn.microsoft.com/purview/audit-log-retention-policies
  2. Microsoft Entra ID, How long does Microsoft keep activity report data — https://learn.microsoft.com/entra/identity/monitoring-health/reference-reports-data-retention
  3. FBI Internet Crime Complaint Center (IC3) — https://www.ic3.gov/
  4. HHS Office for Civil Rights, HIPAA Breach Notification Rule — https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html
  5. NIST SP 800-61 Rev. 3, Incident Response Recommendations (April 2025) — https://csrc.nist.gov/pubs/sp/800/61/r3/final
  6. Federal Rule of Civil Procedure 37(e), Failure to Preserve Electronically Stored Information — https://www.law.cornell.edu/rules/frcp/rule_37

#DigitalForensics #ComputerForensics #CellPhoneForensics #ExpertWitness #DigitalForensicExperts #EliteDigitalForensics #ForensicInvestigation #DataBreachResponse #DataBreachInvestigation #IncidentResponse #CyberForensics #Microsoft365 #UnifiedAuditLog #CloudForensics #MailboxCompromise

This content is for educational and informational purposes only and does not constitute legal advice. Elite Digital Forensics provides independent digital forensic services and expert witness testimony; we do not provide legal representation. Every case is fact specific; outcomes depend on the evidence, jurisdiction, and counsel. Retain qualified legal counsel for advice about your matter.

Assistant Icon Elite Digital Forensics Assistant
πŸ‘‹ Live Chat Now!
Free Virtual Consultation 24/7
Chat Now!

By submitting this form, you consent to be contacted by email, text, or phone. Your information is kept secure and confidential. Reply Stop to opt out at anytime.Β 

IMPORTANT: Please remember to check your spam or junk folder