Microsoft 365 can expose audit records for supported sign-ins, inbox rules, and permission changes. Here is how those records may support an account-takeover monitoring process.
Section 01
Microsoft 365 audit services record supported tenant activity such as sign-ins, mailbox-rule changes, and permission changes. Event availability, fields, timing, and retention depend on the workload, license, audit configuration, and Microsoft service. Administrators can search available records in Microsoft Purview and related portals.
Section 02
Microsoft exposes many event types across Exchange, SharePoint, Teams, and Entra ID. Depending on the tenant and available records, account-takeover review may include:
Section 03
In the Microsoft Purview portal, open Audit and run a search filtered by activity type and date range. Available results can be reviewed or exported, subject to Microsoft's licensing, permissions, retention, and processing delays.
Choose a review schedule and record-retention process based on your organization's risks, licenses, contractual duties, and incident-response plan. InboxGuards does not replace those decisions.
Section 04
Audit records are evidence sources. Whether Microsoft generates a built-in alert depends on the event, tenant configuration, license, and enabled security products. An organization still needs a defined process for reviewing supported records and responding to findings.
InboxGuards connects read-only and checks supported audit records at roughly 5-minute intervals for configured indicators such as suspicious sign-ins, forwarding changes, inbox rules, and selected permission or MFA changes. It sends plain-English alerts and records monitoring activity, subject to provider and API limits.
Section 05
Manual review and automated monitoring each require clear scope, ownership, and response procedures. InboxGuards costs $4 per user per month — $480 a year for a 10-person business, or $400 billed annually — and schedules checks approximately every 5 minutes. It does not guarantee uninterrupted operation or detection of every incident.
FAQ