Free cloud evidence checklist
An unfamiliar Microsoft 365 sign-in. What should you check next?
Use this guide with your authorized administrator. Cloud access can occur away from the office, so the on-premises firewall may have no matching record.
This guide organizes questions and evidence. It does not connect to a tenant, analyze logs or determine whether a breach occurred.
Build your investigation handoff
Select the items your team has addressed. An unchecked item means it still needs an owner; a checked item is not proof that the environment is secure.
0 of 7 items marked addressed.
Your selections stay in this page until you close or reload it. They are not uploaded or saved by this tool. The download contains only checklist text and selections.
Why the office firewall may not tell the story
An attacker can access a cloud mailbox from an external device using compromised credentials, an existing session or granted application access. That connection can bypass the office network entirely. Correlate cloud sign-ins, audit records, mailbox activity and endpoint evidence rather than relying on one log source.
Do not put evidence into a public inquiry
Keep passwords, MFA codes, tokens, session cookies, full log exports and identifying case details out of public forms. Agree on protected evidence sharing with an authorized provider.
If you want a planned review of controls and evidence coverage, see Wolex’s Microsoft 365 Security Review. Wolex starts by email and agrees scope, access and pricing before the review. It is not a 24/7 emergency response service.
Microsoft guidance
- Respond to a compromised cloud email account
- App consent incident response playbook
- Entra audit and sign-in data retention
Reviewed October 9, 2026. Follow your organization’s current incident plan and vendor documentation.
