How to Investigate Identity Compromise in Microsoft 365

Published: April 2, 2026

Key Takeaways

Identity compromise is no longer a warning sign in Microsoft 365 — in many 2026 intrusions, it is the intrusion.

Attackers authenticate using stolen credentials, AiTM-captured sessions, or abused OAuth access, then operate as legitimate users inside the tenant.

The first 30 minutes of an investigation determine whether the incident remains contained or escalates into Business Email Compromise (BEC), data exfiltration, or broader tenant compromise.

Effective response depends on structured analysis of identity telemetry, post-authentication activity, and persistence mechanisms — not just the initial sign-in event.

For broader strategic context, see ByteVanguard’s earlier analysis, Identity Compromise in Microsoft 365: 2026 Trends, which examined why identity has become both the primary entry point and the primary target in Microsoft 365 intrusions, and why defenders increasingly need to treat authentication telemetry as the main early-warning surface.

Why Microsoft 365 Identity Investigations Are Different in 2026

Modern Microsoft 365 compromises often look legitimate.

There may be no exploit chain, no malware execution, and no obvious endpoint alert. The attacker signs in using valid credentials or a hijacked session and begins operating through normal Microsoft services.

This changes the investigation model fundamentally.

Identity telemetry now sits at the center of detection and response. Sign-in logs, audit events, OAuth grants, mailbox activity, and Conditional Access outcomes provide the most reliable signals of compromise.

Traditional assumptions break down quickly. MFA success does not guarantee a legitimate session. Trusted applications do not imply safe consent. A familiar geography does not rule out session replay.

The responder’s task is no longer to find “the breach.” It is to reconstruct the sequence: how access was obtained, what persistence was added, what data was accessed, and whether the identity was used to pivot further across the environment.

The First 30 Minutes

The first 30 minutes should focus on four priorities: confirm suspicious access, preserve evidence, scope impact, and begin containment without destroying the investigative trail.

0–5 minutes: Capture the trigger and preserve context

Document the alert source, affected UPN, timestamp, IP address, device context, and any user-reported symptoms. Preserve the original signal (risky sign-in, impossible travel, inbox rule alert, or BEC report).

5–10 minutes: Review Entra sign-in activity

Filter Entra ID sign-in logs for the affected user over at least the previous 48 hours. Export raw results immediately. Look for unusual IPs, impossible travel, suspicious user agents, blank device identifiers, legacy authentication, and Conditional Access anomalies.

10–15 minutes: Check identity and administrative changes

Review Entra ID audit logs and Microsoft Purview Audit for MFA registration changes, authentication method updates, role assignments, app consents, and service principal creation. A suspicious sign-in followed by an MFA change is a high-confidence indicator of compromise.

15–20 minutes: Review post-authentication activity

Examine mailbox access, forwarding rules, file downloads, Teams activity, and Microsoft Graph operations using Microsoft 365 Defender and Defender for Cloud Apps.

20–25 minutes: Validate Conditional Access enforcement

Analyze Conditional Access results to identify bypassed or missing controls. Determine whether the sign-in should have been blocked.

25–30 minutes: Contain without erasing evidence

Revoke active sessions, reset credentials if required, remove rogue MFA methods, and disable malicious OAuth access. Always export logs before making changes that reduce visibility.

High-Signal Findings That Confirm Compromise

Certain patterns strongly indicate active compromise and should drive immediate escalation.

  • Successful sign-in following a cluster of failed attempts (password spray or credential stuffing)
  • Suspicious geography immediately followed by MFA changes, inbox rules, or OAuth consents
  • Blank or inconsistent Device ID combined with unusual User-Agent (common in AiTM attacks)
  • New MFA method registered shortly after initial access
  • Inbox forwarding or hidden rule creation within minutes of authentication
  • Unexpected OAuth app consent or service principal creation with broad Graph permissions
  • Legacy authentication success despite Conditional Access controls
  • Sudden spike in Graph API, mailbox, or SharePoint activity from a low-activity account

Evidence Sources That Matter Most

A strong investigation depends on using the right telemetry in the right order.

  • Entra ID Sign-in Logs
    Authentication method, IP address, device context, Conditional Access results, and risk signals.
  • Entra ID Audit Logs
    MFA changes, role assignments, app registrations, and administrative actions.
  • Microsoft Purview Unified Audit Log
    Exchange Online, SharePoint, OneDrive, Teams, and mailbox activity.
  • Exchange Online Mailbox Audit Data
    Forwarding rules, inbox rules, and mailbox access behavior.
  • Microsoft Defender for Cloud Apps
    Anomalous session behavior and risky application activity.
  • Microsoft 365 Defender / XDR Advanced Hunting
    Cross-source correlation using KQL.
  • Conditional Access Insights and Reporting
    Policy enforcement gaps and misconfigurations.

Example Attack Timeline: AiTM to BEC

A typical Microsoft 365 identity compromise can escalate rapidly.

  • T+0 min — User clicks an AiTM phishing link and authenticates through attacker-controlled proxy
  • T+2 min — Session tokens are captured
  • T+7 min — New MFA method added
  • T+12 min — Inbox forwarding rule created
  • T+20 min — Mailbox accessed via Outlook Web or Graph
  • T+45 min — BEC emails sent targeting financial workflows
  • T+90 min — Malicious OAuth application registered
  • T+3.5 hrs — Lateral movement into other accounts or hybrid environments

Key lesson: Business impact often occurs within the first hour.

Common Mistakes That Slow Response

  • Focusing only on the login event instead of post-authentication activity
  • Resetting credentials before exporting logs
  • Assuming MFA success equals a safe session
  • Overlooking OAuth applications and service principals
  • Reviewing only recent logs instead of full timelines
  • Ignoring mailbox forwarding and hidden rules
  • Stopping investigation at a single account without checking lateral movement

What to Check Before Closing the Case

Before closing an investigation, confirm:

  • Was this the first malicious access or just the first detected one?
  • Were MFA methods, forwarding rules, or OAuth consents modified?
  • Was sensitive data accessed or exfiltrated?
  • Was the account used to target other users?
  • Did any persistence survive containment?
  • Does a Conditional Access gap still exist for other identities?

If these questions remain unanswered, the incident is not fully contained.

Why This Matters

A single compromised Microsoft 365 identity can expose Exchange communications, SharePoint and OneDrive data, Teams conversations, delegated applications, privileged roles, and hybrid infrastructure.

Identity compromise is no longer a supporting tactic. It is a high-speed control failure at the authentication layer.

In 2026, effective defense depends on rapid, structured investigation built on identity telemetry and post-authentication evidence — not on endpoint signals alone.

Sources

Support independent security analysis

If you find ByteVanguard useful, you can support the site and help keep the analysis independent.

Support the analysis
Intelligence over headlines. Signal over noise.

Stay Connected

Report Intelligence
© 2026 ByteVanguard. Built for security professionals.