Free cloud evidence checklist

An unfamiliar Microsoft 365 sign-in. What should you check next?

Use this guide with your authorized administrator. Cloud access can occur away from the office, so the on-premises firewall may have no matching record.

This guide organizes questions and evidence. It does not connect to a tenant, analyze logs or determine whether a breach occurred.

Build your investigation handoff

Select the items your team has addressed. An unchecked item means it still needs an owner; a checked item is not proof that the environment is secure.

0 of 7 items marked addressed.

Ask whether the time, application and device match expected activity. Use a known phone number or another verified channel if the mailbox may be compromised. An unfamiliar IP location alone does not prove unauthorized access.

Have an authorized administrator preserve the relevant Entra sign-in and audit records, mailbox evidence and alert details promptly. Record time zones, account identifiers, application, IP, device details, authentication results and correlation IDs. Keep original exports protected. Retention and access depend on licensing and prior configuration.

Compare interactive and non-interactive activity where available, authentication details, Conditional Access results and nearby sessions. A successful sign-in is evidence that access was granted; it does not establish who used the session. A device display name or geolocation is not a reliable identity on its own.

Review unexpected forwarding, inbox rules including hidden rules, delegates, app consents and application permissions. Confirm legitimate business use before treating a setting as malicious. Document what changed, when, by whom and which resources it permits.

Look for unexpected MFA methods, administrator roles, new accounts, device registrations and permission changes. Review available file access and sharing evidence. Registration alone does not show lateral movement; correlate changes with sign-ins and audit activity.

If access appears unauthorized, follow your incident plan promptly. The administrator may need to disable access, revoke sessions, reset credentials and remove unauthorized access paths. Preserve evidence in parallel when possible; do not delay urgent containment to finish this worksheet. A password reset alone may leave other access paths.

Record confirmed facts separately from theories. Specify the time window and systems reviewed, missing evidence, containment actions and owners. Consider provider, insurer or incident-response escalation under your existing plan. Never conclude there was no compromise solely because logs are absent.

Your selections stay in this page until you close or reload it. They are not uploaded or saved by this tool. The download contains only checklist text and selections.

Why the office firewall may not tell the story

An attacker can access a cloud mailbox from an external device using compromised credentials, an existing session or granted application access. That connection can bypass the office network entirely. Correlate cloud sign-ins, audit records, mailbox activity and endpoint evidence rather than relying on one log source.

Do not put evidence into a public inquiry

Keep passwords, MFA codes, tokens, session cookies, full log exports and identifying case details out of public forms. Agree on protected evidence sharing with an authorized provider.

If you want a planned review of controls and evidence coverage, see Wolex’s Microsoft 365 Security Review. Wolex starts by email and agrees scope, access and pricing before the review. It is not a 24/7 emergency response service.

Microsoft guidance

Reviewed October 9, 2026. Follow your organization’s current incident plan and vendor documentation.