The instinct after discovering a compromised Microsoft 365 account is to fix it immediately: reset the password, revoke sessions, and move on. That instinct is right for stopping the bleeding — but acted on carelessly, it can quietly destroy the very records you would need to understand what happened.
This is a practical guide to preserving evidence in the first hours of a Microsoft 365 incident, written for the person who has just realized something is wrong. It is general information, not legal advice, and every tenant is different — what you can preserve depends on your licensing, your logging configuration, and how much time has passed.
Containment and preservation are not the same thing
Two separate goals are in play, and they can pull in opposite directions.
Containment stops the attacker: disabling the account, revoking active sessions and tokens, and removing any malicious inbox rules or app grants. Preservation protects the record of what occurred so it can be reconstructed later.
You usually need both, in that order — contain first, because an active intruder is doing ongoing harm. The mistake is treating containment as the whole job and skipping preservation entirely. A middle path exists: contain in ways that are documented and reversible, and capture the current state before you start deleting things.
Capture the state before you change it
Before you remediate, record what the environment looks like right now. A few minutes of screenshots and exports here can matter enormously later.
- Inbox rules. Attackers frequently create rules that forward, delete, or hide mail. Before removing them, capture what they were — their conditions and actions — because the rule itself is evidence of intent and scope.
- Mail forwarding. Check both mailbox-level forwarding and any transport rules. Note the destination addresses.
- Connected applications and OAuth grants. A consented malicious app can retain access even after a password reset. Record what is connected before you revoke anything.
- Sign-in activity. Note the timeframe, source locations, and IP addresses associated with the suspicious access while it is fresh.
- The account’s recent sent items and deletions. If the attacker sent messages or deleted them, that activity is part of the story.
Write down what you did and when, in a simple running log. A clear, timestamped account of your own actions is one of the most useful things you can produce, and one of the most commonly skipped.
Understand what the audit log can and cannot tell you
Microsoft 365’s unified audit log is often the backbone of an investigation, but it is not unlimited, and assuming otherwise leads to false confidence.
Retention of audit records depends on the licensing and configuration in place at the time the events happened — not what you upgrade to afterward. If audit logging was disabled, or the events have aged out of your retention window, upgrading a license today will not retroactively create records for last month. Mailbox auditing behavior and the availability of certain events likewise vary by plan and configuration.
The honest position is this: you may be able to reconstruct a great deal, or you may find meaningful gaps. Establishing what evidence actually exists is the first analytical step, and it should be done before anyone promises a conclusion.
Preserve mailbox content deliberately
If there is any chance the incident will matter beyond IT — a departure dispute, a regulatory question, a possible legal matter — content should be preserved before normal retention or an eventual cleanup removes it.
Microsoft 365 offers holds that preserve mailbox and, depending on configuration, other content in place. Applying an appropriate hold is generally preferable to ad-hoc exports, because it preserves items without altering them. The right mechanism depends on your licensing and on the questions being asked, so this is a point where getting it wrong is costly and worth a moment’s care.
Do not rely on the attacker’s convenience. Deleted items, purged folders, and time-limited recoverability all work against you the longer you wait.
A first-hours checklist
- Contain the account: disable sign-in, revoke sessions and refresh tokens, reset credentials.
- Capture inbox rules, forwarding, and OAuth app grants before removing them.
- Record suspicious sign-in times, locations, and IPs while visible.
- Log your own remediation actions with timestamps.
- Preserve mailbox content with an appropriate hold if the matter may extend beyond IT.
- Confirm what audit data actually exists for the relevant window before drawing conclusions.
- Widen the question: was this one account, or a foothold into others?
When to bring in help
Not every incident needs outside assistance. But there are signals that experienced help is worth it: the compromised account had privileged access, more than one account is involved, sensitive data may have been reached, or the matter could plausibly end up in front of counsel, a regulator, or a departing employee’s attorney. In those situations, how the evidence is handled early can shape what is defensible later.
If that describes your situation, the goal of a first conversation is simple: establish what happened, what the available evidence can support, and what to do next — without overstating what anyone can promise.