Investigating a Suspicious Microsoft 365 Account: Entra, Mailbox, and Defender

A Microsoft 365 account investigation requires connecting Identity, Audit Logs, API actions, resources, regions, and sessions. Begin by preserving evidence and building a timeline, then perform documented containment.
Cloud investigation requires connecting identities, Control Plane, resources, keys, sessions, and security services. Since activity is distributed across services and regions, a timeline and understanding permissions are critical. This article focuses on Microsoft 365 account investigations and is intended for SOC analysts and Cloud investigators. The goal is to provide a methodology that can be applied in practice, during professional interviews, and in a work environment, without settling for a dictionary definition.
The main challenge is that data is almost always partial. SigninLogs, AuditLogs, OfficeActivity can indicate a direction, but their meaning depends on time, asset, user, and expected activity. Therefore, we will build the investigation around an investigation question, required evidence, and a clear criterion for completion.
The practical scenario in the article is: A timeline of a simulated cloud account. All examples are lab data or process descriptions. When it comes to Penetration Testing, Web, or Cloud, one must work only with explicit permission, a defined scope, and the ability to stop the test.




