VISIBILITY ACROSS MICROSOFT 365

Microsoft 365 Monitoring, Security & Management

Monitor sign-ins, account changes, mailbox activity and unusual file behaviour so potential risks can be identified and investigated sooner.

MICROSOFT 365 NEEDS OVERSIGHT

Security Is Not Just About Blocking Bad Email

Microsoft 365 contains your users, email, files, permissions, applications and business data. Changes inside the environment can be just as important as threats arriving from outside.

As part of the KES Business User Pack, Microsoft 365 activity is monitored for unusual behaviour, suspicious sign-ins, mailbox changes, file events and administrative activity that may indicate compromise, misuse or configuration drift.

WHAT WE MONITOR

Activity Across Users, Mailboxes, Files and Administration

Unusual Sign-In Activity

Sign-ins can be reviewed against expected countries, networks and normal user behaviour to help identify suspicious access.

Mailbox Forwarding and Rules

Suspicious forwarding changes or inbox rules may indicate that an account has been compromised or misused.

Administrative Changes

Changes to users, permissions, roles and security settings can be monitored for unexpected or unauthorised activity.

File Activity

Unusual downloads, deletions, modifications or volumes of file activity can be identified for review.

Application Access

New or unexpected application connections and consent activity can be reviewed where they affect company data.

Account Changes

User creation, deletion, MFA changes and other account events can be reviewed where they may create risk.

TRUSTED LOCATIONS AND NETWORKS

Context Helps Separate Normal Activity from Risk

Monitoring is more useful when it understands where users are normally expected to connect from.

KES can define expected countries, trusted IP addresses, network ranges and approved cloud-service locations so alerts can be assessed with better context.

This does not mean every connection outside an approved location is malicious, but it helps prioritise events that need attention.

Context can include:

  • Expected countries
  • Known office networks
  • Approved public IP addresses
  • Trusted cloud-service providers
  • Normal user activity patterns
  • Customer-specific exceptions
ALERT REVIEW

Relevant Events Can Be Escalated for Investigation

Event Detection

The monitoring platform records and evaluates Microsoft 365 activity against configured rules and thresholds.

KES Review

Relevant events can be reviewed by KES to determine whether the activity appears legitimate or requires further action.

Customer Contact

Where user confirmation, account action or remediation is required, KES can contact the customer and agree the next steps.

Account Containment

Depending on the event, response may include password changes, session revocation or additional account-security checks.

Mailbox Investigation

Suspicious forwarding, permissions and inbox rules can be reviewed as part of account-compromise investigation.

Ongoing Improvement

Findings can be used to strengthen security policies and reduce the chance of similar events recurring.

SECURITY POSTURE REVIEW

Monitoring What Happens and Reviewing How Microsoft 365 Is Configured

Activity monitoring helps identify events. Security posture review helps identify configuration weaknesses before they become incidents.

Mailbox Security

Review of settings such as forwarding, auditing, spam notifications and external access.

Application Consent

Review of controls that determine whether users can grant third-party applications access to company data.

Sharing and Collaboration

Review of external sharing, calendar access and other collaboration settings that may expose business information.

Data Protection

Identification of opportunities to improve data-loss prevention, retention and information classification.

Session and Access Controls

Review of sign-in, session and access settings that affect how users and devices connect.

Security Recommendations

KES can identify recommended improvements and assess whether they are suitable for the customer’s licences and working practices.

Security recommendations are not applied blindly. Some controls can affect legitimate applications, external sharing or business workflows and must be assessed before implementation.

WHAT MONITORING DOES NOT MEAN

Useful Oversight Without Making Unrealistic Promises

Not Every Event Is Malicious

Microsoft 365 produces a large volume of legitimate activity. Monitoring helps identify events that deserve review.

Not a 24/7 Security Operations Centre

Standard Business User Pack customers receive active monitoring during KES support hours, not a continuously staffed external SOC.

Not a Guarantee Against Compromise

Monitoring improves visibility and response but cannot guarantee that every attack or misuse will be prevented.

OUR STANDARD SERVICE POSITION

Automated Monitoring Continues Outside Support Hours

Microsoft 365 monitoring continues collecting and evaluating activity outside normal KES service hours.

Human review and response are provided during standard support hours unless a separate extended-hours arrangement has been agreed.

KES support hours:

  • Monday to Friday
  • 8:00am to 5:30pm
  • Excluding public holidays
  • Urgent out-of-hours review is not guaranteed
GAIN BETTER VISIBILITY

Would You Know If Something Changed Inside Microsoft 365?

We can review your current Microsoft 365 security, activity monitoring and alerting and show you where visibility can be improved.

FREQUENTLY ASKED QUESTIONS

Microsoft 365 Monitoring, Security and Management FAQs

What Microsoft 365 activity is monitored?

Monitoring can include sign-ins, mailbox forwarding, inbox rules, account changes, administrative changes and unusual file activity.

Does monitoring block suspicious sign-ins automatically?

Monitoring identifies events for review. Access controls and automated responses depend on the customer’s Microsoft licensing, configuration and the nature of the event.

Are all monitoring alerts genuine security incidents?

No. Many events are legitimate. Monitoring provides context and visibility so unusual activity can be assessed.

Does every alert create a support ticket?

Not currently. Alerting is tuned to avoid overwhelming the service desk with routine events, and relevant events are escalated for investigation.

Is this a 24/7 SOC service?

No. Automated monitoring continues outside normal hours, but standard human review and response are provided during KES support hours.

Does KES automatically apply every Microsoft 365 recommendation?

No. Recommendations are assessed for suitability because some controls can affect applications, sharing and normal business workflows.

Is Microsoft 365 monitoring included in the Business User Pack?

Yes. Microsoft 365 activity and security posture monitoring are included as part of the wider managed-service protection.