logo

The Invisible Enemy: Unmasking Microsoft 365’s Logging Blind Spots

ID: d9745cd8-1f3f-5264-aba9-e5d37d22fad7

STIX ID: report--d9745cd8-1f3f-5264-aba9-e5d37d22fad7

Feed Name: Abstract Security Blog

Date Published: 2025-04-22

Date Updated: 2026-04-26

...
...

This report examines blind spots in Microsoft 365 Management API and Microsoft Graph audit logs, validated through msInvader attack simulations, revealing that enumeration and many failed modification attempts are often unlogged while certain successful mailbox actions (e.g., inbox rule creation) and failed sign-ins are captured. It details discrepancies between M365 and Graph log formats, notes delays and event ordering issues, and provides detection guidance focused on what is reliably logged, chaining detections across attack steps, and leveraging enhanced Graph activity logging for improved visibility.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.