Microsoft 365 breach detection for small businesses

InboxGuards checks available Microsoft 365 audit records approximately every 5 minutes and alerts you in plain English when configured account-takeover signals appear.

N°001sectionhow microsoft 365 accounts are used in email fraud

Section 01

How Microsoft 365 accounts are used in email fraud

Business email compromise can begin with stolen credentials, malicious app consent, or impersonation. A compromised Microsoft 365 account may be used to create inbox rules, configure forwarding, or send deceptive payment requests.

These techniques do not always produce the same records, and provider ingestion can be delayed. Monitoring is one control within a broader email-security and payment-verification process.

N°002sectionthe warning signs hiding in your microsoft 365 audit logs

Section 02

The warning signs hiding in your Microsoft 365 audit logs

Microsoft 365 may record supported actions in its audit services. An audit record alone is not a response process. InboxGuards checks available records approximately every 5 minutes and notifies you when a configured detection rule matches. Provider ingestion delays still apply. Reviewed signals include:

  • Sign-ins from new or unexpected countries and IP addresses
  • New inbox rules that delete, hide, or forward mail (the classic BEC move)
  • Mail forwarding turned on to an external address
  • New admin roles or app permissions granted without your knowledge
  • MFA or audit logging being switched off — the attacker covering their tracks
  • Impossible travel — one account signing in from two places it couldn't travel between
  • Dormant accounts suddenly waking up, and risky changes made after hours
N°003sectionbeyond alerts: your daily security posture

Section 03

Beyond alerts: your daily security posture

InboxGuards also runs a daily posture check on supported tenant data: Microsoft security defaults, older guest accounts, and — on tenants licensed for Entra ID P1 or P2 — Microsoft's per-user MFA enrollment report and Identity Protection risky-sign-in records. Microsoft does not expose those last two on Business Basic/Standard or other non-P1 plans, so the dashboard marks them unavailable there instead of guessing; InboxGuards' own sign-in detections run on every plan. On the 1st of each month you get a letter-grade scorecard summarizing available results — an informational snapshot, not a certification or audit.

N°004sectiondaily dark-web check of every mailbox

Section 04

Daily dark-web check of every mailbox

Stolen passwords are how most takeovers start. Once a day InboxGuards reads the list of user email addresses from your tenant directory (the same read-only User.Read.All permission used for guest-account counts) and checks each one against Have I Been Pwned and LeakCheck — including LeakCheck's info-stealer malware logs, which show credentials copied off an infected device. Every email domain your users have is also swept for leaked addresses that have never signed in, such as former staff or shared mailboxes.

New findings become one alert per person, graded by what was exposed: an address alone, a password, or a fresh stealer-log capture. Leaked values themselves are never stored or shown. The Dark Web tab on your dashboard lists every address checked, when, and what was found, and has a Scan now button for an immediate recheck.

N°005sectionhow inboxguards monitors your microsoft 365 account

Section 05

How InboxGuards monitors your Microsoft 365 account

InboxGuards connects to your Microsoft 365 tenant with read-only access to supported audit records — it does not request mailbox-content access and cannot change tenant settings. When a configured rule matches, you get a plain-English alert describing the available evidence and general response guidance.

Monitoring costs $4 per user per month with no minimum. An authorized Microsoft administrator must grant read-only access before monitoring can begin. InboxGuards supplies alerts and general response steps; your administrator or MSP remains responsible for tenant changes and incident response.

Put an alarm on my inbox

$4 per user / month · 30-day money-back guarantee