Microsoft 365 Compromise Detection and Response
Most people still picture a breach as someone breaking in — cracking a password, slipping past the firewall, tripping an alarm. That picture is out of date. Today, the most damaging Microsoft 365 compromises don’t look like a break-in at all. They look like a normal login.
We wrote recently about how attackers now walk around multi-factor authentication — stealing session tokens, relaying real Microsoft sign-in pages, and abusing legitimate features to get a valid session without ever needing your password again. Once they hold that session, they’re inside your environment as a trusted user. Nothing looks wrong. And that raises two questions most businesses can’t answer:
If someone were inside your Microsoft 365 right now, would you see it? And if they had been, could you prove exactly what they touched?
The Breach That Doesn’t Look Like a Breach
When an attacker logs in with a valid session, the front-door defenses have already done their job and moved on. MFA verified the user. Email security scanned the inbound messages. Both are essential — and both are looking at the entrance, not at what happens once someone is inside.
So the attacker settles in quietly. They read email to learn your billing cycles and who approves payments. They create a hidden inbox rule that auto-files their own messages so you never see the replies. They register an OAuth app to keep access even after a password reset. They browse SharePoint and OneDrive for the documents that matter. None of this trips a traditional alert, because none of it is technically an “attack” — it’s a logged-in user doing ordinary things, just not the real user.
This is the gap. Verifying who logged in is not the same as watching what they do next.
What Modern Microsoft 365 Detection and Response Actually Does
Closing that gap takes a different kind of monitoring — one built specifically for identity-based threats in Microsoft 365. Here’s what that looks like in practice:
- Behavioral login analysis. Instead of asking only “is this login from an expected location?”, it studies the behavior of the session itself. That’s how it catches the attacks that pass location checks — logins routed through residential proxies, sessions riding on a stolen token, credentials that already cleared MFA.
- Watching activity after the login. It monitors what actually happens inside the tenant — new inbox rules, app registrations, MFA method changes, mailbox and file access, unusual sends and deletions, permission changes. The tell-tale signs of a takeover live in these actions, not in the sign-in itself.
- Fast, automated containment. When something is clearly malicious, waiting hours for a human to notice is waiting too long. The response can move immediately — ending the attacker’s sessions, removing the devices and MFA methods they registered, and deleting the malicious inbox rules they left behind — to shut the door before real damage is done.
- Forensic reconstruction. After an incident, it rebuilds the full timeline: how they got in, what they accessed, what they changed, what left the building. Not guesswork — a documented account of exactly what happened.
Behind Go West’s service, this capability is powered by Petra Security, an identity threat detection and response platform purpose-built for Microsoft 365, backed by our 24/7 Security Operations Center. The technology sees the threat; our SOC investigates and responds — around the clock, including the nights and weekends when these attacks are timed to land.
Why the Forensic Record Matters as Much as the Alert
For a regulated business — an RIA, a law firm, a family office — detecting the compromise is only half of it. The other half is being able to answer, with confidence, what happened.
After a Microsoft 365 incident, you may need to tell a regulator, a cyber-insurance carrier, or an affected client precisely what was and wasn’t accessed. “We think we contained it” is not an answer that holds up. A clear forensic timeline — the attacker’s infrastructure, the mailboxes and files they touched, the data that did or didn’t leave — turns a frightening, open-ended event into a defined, defensible one. It shortens the incident, supports the insurance claim, and lets you make disclosure decisions based on fact rather than fear.
That’s the difference between an event that controls you and one you control.
The Part That Has to Happen First
Here’s what surprises most businesses: a forensic timeline is only as good as the data behind it — and Microsoft 365 does not capture all of that data by default. The detailed logging that reveals which mailboxes were opened, which files were accessed, and what left your tenant has to be deliberately turned on, configured correctly, and retained long enough to matter — before an incident, not after. Plug even the best detection tool into a tenant that was never logging the right activity, and it has very little to work with. The evidence you’ll want on your worst day is created by choices you make on an ordinary one.
This is exactly why the smart move is to be proactive. Preventing, detecting, containing, and remediating a compromise aren’t four products you scramble to buy in a crisis — they’re one posture you put in place ahead of time. That means getting the foundation right first: logging and retention configured properly, detection tuned to the right activity, containment ready to act, and a response team already on call. It’s the work worth doing with a partner like Go West IT while everything is quiet — so that if the day ever comes, it’s all already in place.
Both Sides of the Coin
Here’s the confident version of all this: identity-based compromise is real and it’s rising — and it is now something you can genuinely see, stop, and account for. The businesses that come through these events well aren’t the ones that never get targeted. They’re the ones who detect fast, contain automatically, and can prove exactly what happened.
This protection is now included in our Go Secured | Advanced Cloud service and in Go Managed | Comprehensive — no separate purchase, no bolt-on. If Microsoft 365 is where your business runs, this is the layer that watches what happens after the login.
Where to Start
- Worried something may already be going on — an odd login alert, an email that didn’t sit right, a payment that went to the wrong place? Our free, no-obligation Microsoft 365 Compromise Assessment looks for the specific signs of a takeover and tells you plainly what we find.
- Just want to know where you stand? Our free Microsoft 365 Security Assessment gives you a clear, prioritized picture of your environment, in plain language.
- Ready to have this running quietly in the background? Let’s talk about Go Secured Advanced Cloud.
You can’t stop every attacker from trying. You can decide whether they get to operate in the dark. Go Boldly — we’ll guide the way.

