Microsoft 365Detection & ResponseRetrospectives

Detecting Forged Token Mailbox Access: Defender XDR and Sentinel Hunting Queries

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from July 2023, written in 2026 with the benefit of hindsight.

Forged or stolen tokens let attackers access mailboxes without normal sign-ins. Mailbox access audit events are often the only evidence.

Signals worth watching

  • MailItemsAccessed events from unusual IP addresses, user agents or applications.
  • Mailbox access with no corresponding interactive sign-in in Entra ID sign-in logs.
  • Access to executive or sensitive mailboxes by unexpected clients.
  • Large numbers of items accessed in a short period (sync-type access).
  • Access through Outlook Web Access (OWA) from infrastructure not used by your organization.

Where the data lives

  • Microsoft Purview audit (MailItemsAccessed, Send, SearchQueryInitiated).
  • OfficeActivity and CloudAppEvents in Sentinel / Defender XDR.
  • Entra ID sign-in logs for correlation.

A starting query

Mailbox access from IPs never seen in the user's sign-in logs:

let signinIPs = SigninLogs
| where TimeGenerated > ago(14d) and ResultType == "0"
| summarize IPs = make_set(IPAddress) by UserPrincipalName;
OfficeActivity
| where TimeGenerated > ago(1d) and Operation == "MailItemsAccessed"
| join kind=leftouter signinIPs on $left.UserId == $right.UserPrincipalName
| where not(set_has_element(IPs, ClientIP))
| project TimeGenerated, UserId, ClientIP, ClientInfoString

Expect noise from Microsoft service IPs and mobile carriers; refine with known ranges.

Response

  1. Identify which mailboxes and items were accessed.
  2. Revoke sessions and tokens for affected users.
  3. Engage Microsoft support if you suspect token forgery or a provider-side issue.
  4. Notify affected parties as required.
detect forged token mailbox accessStorm-05582023

More on this story