Correlating Microsoft 365 Evidence Sources Across Layers
Overview & Investigation Context
Section titled βOverview & Investigation ContextβThis reference card details the technical mechanics, log artifacts, and forensic methodology for Correlating Microsoft 365 Evidence Sources Across Layers.
During Microsoft 365 incident response engagements, investigators must navigate the identity plane, workload activity records, and cloud telemetry while maintaining strict adherence to the evidentiary threshold:
Possible β Configured β Authorized β Accessible β Utilized β Observed β Proven
Key Cross-References & Prerequisites
Section titled βKey Cross-References & Prerequisitesβ 01. M365 DFIR Fundamentals Understand the core tenant architecture, identity boundaries, and workload interactions.
02. Microsoft Entra ID: The Identity Plane Explore user, group, device, and service principal authentication pipelines.
04. Preparing a Tenant for DFIR CSIRT onboarding protocol, credential sanitization, and emergency tenant access.
06. M365 DFIR Access Matrix Operational role, license, portal, and log retention lookup table.