What This Playbook Covers
Microsoft 365 audit logs help security teams understand who acted, what changed, when activity occurred, and whether an event created risk. However, logs only create value when teams review them through a clear process. This playbook explains how to use Microsoft 365 audit data to investigate suspicious activity, validate identity risk, review administrative changes, and support incident response decisions.
The goal is not to collect logs for the sake of collection. Instead, the goal is to turn audit data into clear security decisions. As a result, teams can detect suspicious behavior earlier, understand the scope of an event, preserve useful evidence, and decide whether a finding requires escalation.
When This Playbook Is Used
Use this playbook when Microsoft 365 activity suggests possible account compromise, privilege abuse, data exposure, or unusual system behavior. Some events may have a valid business reason. However, each meaningful event should follow the same review path so teams can separate normal activity from real risk.
Suspicious Identity Activity
Risky sign-ins, impossible travel, password spray activity, MFA changes, and unusual account behavior may indicate that an identity needs deeper review. In many cases, identity events provide the first sign that a user account may no longer be safe.
Incident Investigation
A security alert, user report, phishing event, mailbox change, or unexpected admin action may require audit log review. For example, investigators may need to confirm whether a suspicious sign-in led to data access, mailbox changes, or new permissions.
Compliance And Audit Review
Leaders, auditors, clients, or regulators may request evidence that shows how the organization monitors and reviews Microsoft 365 activity. As a result, teams need a clear record of what happened, what they reviewed, and what action followed.
High-Value Microsoft 365 Audit Events
Not every audit event deserves the same level of attention. Therefore, investigators should focus first on events that commonly point to account takeover, unauthorized access, risky admin activity, or possible data exposure.
Identity And Sign-In Events
Start with risky sign-ins, user risk events, sign-in risk detections, impossible travel, password spray activity, unfamiliar locations, MFA registration changes, and authentication method changes. These events help teams decide whether an account still appears trustworthy.
For more context, review the Microsoft Entra User Risk and Sign-In Risk guide. In addition, use the Microsoft Entra Sign-In Risk Detections Explained guide to understand the specific sign-in risk signals that may trigger an investigation.
Administrative Changes
Give prompt attention to new admin roles, role changes, Conditional Access updates, mailbox permission changes, app consent grants, application registrations, and security policy changes. Because attackers often seek stronger access after entry, admin activity can reveal whether an event has grown beyond one account.
Data Access And Sharing
Look closely at large downloads, new sharing links, external sharing, OneDrive activity, SharePoint permission changes, mass deletion activity, and unusual file access. As a result, teams can decide whether sensitive data needs legal, compliance, or leadership review.
Execution Steps
A strong audit log investigation follows a clear order. First, define the event and scope. Next, collect the right logs. After that, compare activity across Microsoft 365 services. Finally, document findings and decide whether the issue requires containment, escalation, or follow-up review.
Define The Investigation Scope
Begin by stating why the investigation started. For example, the trigger may come from a risky sign-in, Defender alert, user report, mailbox change, or audit request. Then identify the users, accounts, devices, systems, and time period that need review.
Collect The Right Logs
Match the log sources to the event. For identity issues, use Entra sign-in logs, user risk, sign-in risk, and authentication changes. For data issues, use SharePoint, OneDrive, Exchange, and Purview audit records.
Create A Timeline
Build a timeline that shows when the activity started, what happened next, and which actions followed. In addition, include sign-ins, admin changes, mailbox actions, file access, alerts, and response steps so the team can see the full sequence.
Review For Abnormal Activity
Focus on activity that does not match normal behavior. For example, compare unfamiliar locations, new MFA methods, sudden admin role changes, nonstandard mailbox rules, large file downloads, and access from unusual devices or networks.
Determine The Impact
Identify what the activity affected. Next, investigators should confirm whether someone accessed data, changed permissions, modified settings, added authentication methods, created risky mailbox rules, or used elevated access. As a result, leaders can understand business risk more clearly.
Document And Escalate
Capture the evidence, summarize what the team found, and record the response decision. If the activity indicates account takeover, data exposure, policy abuse, or unauthorized admin action, move the issue into the incident response process.
Questions Every Investigator Should Ask
Audit logs become more useful when investigators ask the same core questions during every review. Therefore, each investigation should focus on identity, action, timing, location, impact, and business context.
Who Performed The Activity?
Identify the user, administrator, service account, device, or application involved. Then compare the activity to normal responsibilities. If the activity does not match the role, the team should review the account more closely.
Which Settings Or Permissions Changed?
Examine whether the activity changed access, settings, policies, roles, mailbox rules, authentication methods, file permissions, or sharing links. In other words, focus on what the activity allowed someone to do next.
Where Did It Come From?
Check the location, IP address, device, browser, app, and sign-in context. For example, a successful sign-in from an unfamiliar location followed by an MFA change may require immediate account review.
Is The Activity Normal?
Compare the event against normal user behavior, business hours, known travel, expected admin work, and prior access patterns. However, do not assume that a familiar user account means the activity was safe.
Which Evidence Supports The Finding?
Gather the records that support the conclusion. Useful evidence may include sign-in logs, audit events, Defender alerts, message trace, file activity, screenshots, ticket notes, and user confirmation.
What Action Should Follow?
Decide whether the team should close the review, monitor the account, reset credentials, revoke sessions, remove access, contain a device, notify leadership, or move the event into incident response.
Common Audit Log Red Flags
Certain audit events appear often during real security investigations. Because of this, teams should review these events carefully and document why each event did or did not require action.
Identity Risk Indicators
Pay close attention to risky sign-ins, impossible travel, password spray activity, anonymous IP use, new MFA methods, failed sign-in spikes, and user risk events. If these signals appear together, the account may need containment.
Privilege And Admin Red Flags
Treat new admin assignments, role changes, Conditional Access edits, app consent grants, mailbox permission changes, and security policy updates as high-value review items. In addition, confirm whether each change came from an approved request.
Data Exposure Indicators
Watch for large file downloads, new external sharing links, mass deletions, unusual SharePoint access, new OneDrive sharing, and unexpected permission changes. As a result, the team can decide whether legal, compliance, or leadership review is needed.
Identity Investigation Workflow
Identity events require special care because one account can provide access to email, files, Teams, SharePoint, admin portals, and business apps. Therefore, teams should use a focused identity workflow when audit logs show risky sign-ins or account changes.
Review User Risk
Start with the user risk record in Microsoft Entra. Then review the detection type, severity, and related activity. If user risk suggests possible compromise, the team should inspect recent sign-ins, authentication changes, mailbox activity, and file access.
Review Sign-In Risk
Next, inspect the specific sign-in event that triggered concern. For example, compare impossible travel, unfamiliar locations, malicious IP activity, anonymous IP use, or suspicious browser behavior against known user activity.
Confirm Account Control
Finally, confirm whether the user recognizes the activity. If the user does not recognize the sign-in, revoke sessions, reset credentials, review MFA methods, and check for mailbox rules or data access that followed the event.
Operational Requirements
A playbook only works when the organization gives teams the access, records, and decision rights they need. Therefore, leaders should confirm these requirements before a security event occurs.
Log Access And Retention
Provide the right team members with access to the logs they need. Also confirm that retention settings support investigations, compliance reviews, and leadership reporting needs.
Defined Review Ownership
Assign clear owners for daily review, investigation, escalation, evidence handling, and leadership updates. As a result, events do not sit unreviewed because each team assumes someone else owns them.
Monitoring And Alerting
Use Microsoft-native alerts, Defender signals, Entra risk data, and Purview audit records to reduce manual review work. However, teams should still review high-risk events and confirm the business context.
Escalation Criteria
Not every audit finding requires incident response. However, certain findings should trigger immediate escalation because they may indicate active compromise, data exposure, or unauthorized control changes.
Escalate Identity Findings
Escalate when the user does not recognize the sign-in, risky sign-ins appear with MFA changes, password spray activity succeeds, or attackers may still have active sessions.
Review Administrative Findings
Raise the issue when audit logs show unapproved admin role changes, Conditional Access edits, new application consent, or mailbox permission changes tied to sensitive accounts.
Respond To Data Findings
Move the event forward when logs show large downloads, external sharing, sensitive file exposure, unusual deletion activity, or access that the data owner cannot explain.
Expected Outcome
After the team completes this playbook, the organization should have more than a list of reviewed logs. Instead, leaders should receive a clear record of the event, the evidence reviewed, the risk decision, and the response actions taken.
- Security teams identify high-risk Microsoft 365 activity earlier.
- Investigators understand who acted, what changed, and whether the activity matched normal behavior.
- Identity investigations use both audit data and Entra risk signals.
- Teams document evidence clearly for security, compliance, leadership, and audit review.
- Leaders receive a clear summary of findings, response actions, and remaining risk.
