Microsoft 365 audit logs: what they are and what to look for

Microsoft 365 can expose audit records for supported sign-ins, inbox rules, and permission changes. Here is how those records may support an account-takeover monitoring process.

N°001sectionthe short answer

Section 01

The short answer

Microsoft 365 audit services record supported tenant activity such as sign-ins, mailbox-rule changes, and permission changes. Event availability, fields, timing, and retention depend on the workload, license, audit configuration, and Microsoft service. Administrators can search available records in Microsoft Purview and related portals.

N°002sectionwhat the audit log actually records

Section 02

What the audit log actually records

Microsoft exposes many event types across Exchange, SharePoint, Teams, and Entra ID. Depending on the tenant and available records, account-takeover review may include:

  • UserLoggedIn and related sign-in events — available records may include an IP address, location, and result. An unexpected country can warrant review.
  • New-InboxRule / Set-InboxRule — inbox rules created or changed. Attackers create rules that delete or hide security warnings and vendor replies.
  • Set-Mailbox with forwarding parameters — external forwarding configured on a mailbox can be relevant to BEC review.
  • Add-MailboxPermission — someone granting themselves (or another account) access to a mailbox that isn't theirs.
  • Update user / Add member to role — MFA method changes and new admin role grants, used to lock in access.
N°003sectionhow to check them yourself

Section 03

How to check them yourself

In the Microsoft Purview portal, open Audit and run a search filtered by activity type and date range. Available results can be reviewed or exported, subject to Microsoft's licensing, permissions, retention, and processing delays.

Choose a review schedule and record-retention process based on your organization's risks, licenses, contractual duties, and incident-response plan. InboxGuards does not replace those decisions.

N°004sectiona log is not the same as a monitoring process

Section 04

A log is not the same as a monitoring process

Audit records are evidence sources. Whether Microsoft generates a built-in alert depends on the event, tenant configuration, license, and enabled security products. An organization still needs a defined process for reviewing supported records and responding to findings.

InboxGuards connects read-only and checks supported audit records at roughly 5-minute intervals for configured indicators such as suspicious sign-ins, forwarding changes, inbox rules, and selected permission or MFA changes. It sends plain-English alerts and records monitoring activity, subject to provider and API limits.

N°005sectiondo it manually or automate it

Section 05

Do it manually or automate it

Manual review and automated monitoring each require clear scope, ownership, and response procedures. InboxGuards costs $4 per user per month — $480 a year for a 10-person business, or $400 billed annually — and schedules checks approximately every 5 minutes. It does not guarantee uninterrupted operation or detection of every incident.

N°006faqcommon questions

FAQ

Common questions.

Are Microsoft 365 audit logs enabled by default?
Availability and retention depend on the tenant, workload, audit configuration, and Microsoft license. Check the current Microsoft documentation and the tenant's actual Purview audit settings.
Which audit log events indicate a compromised mailbox?
Sign-ins from unexpected locations (UserLoggedIn), inbox rules being created or changed (New-InboxRule, Set-InboxRule), external forwarding configured on a mailbox, mailbox permission grants, and MFA or admin role changes.
Does Microsoft 365 alert me when a suspicious event appears?
Microsoft alert availability depends on the event, tenant configuration, license, and enabled security products. InboxGuards separately checks supported records at roughly 5-minute intervals and emails plain-English alerts for configured indicators, for $4 per user per month.

Automate my audit log checks

$4 per user / month · 30-day money-back guarantee