Microsoft 365 Monitoring, Security & Management
Monitor sign-ins, account changes, mailbox activity and unusual file behaviour so potential risks can be identified and investigated sooner.
Security Is Not Just About Blocking Bad Email
Microsoft 365 contains your users, email, files, permissions, applications and business data. Changes inside the environment can be just as important as threats arriving from outside.
As part of the KES Business User Pack, Microsoft 365 activity is monitored for unusual behaviour, suspicious sign-ins, mailbox changes, file events and administrative activity that may indicate compromise, misuse or configuration drift.
Activity Across Users, Mailboxes, Files and Administration
Unusual Sign-In Activity
Sign-ins can be reviewed against expected countries, networks and normal user behaviour to help identify suspicious access.
Mailbox Forwarding and Rules
Suspicious forwarding changes or inbox rules may indicate that an account has been compromised or misused.
Administrative Changes
Changes to users, permissions, roles and security settings can be monitored for unexpected or unauthorised activity.
File Activity
Unusual downloads, deletions, modifications or volumes of file activity can be identified for review.
Application Access
New or unexpected application connections and consent activity can be reviewed where they affect company data.
Account Changes
User creation, deletion, MFA changes and other account events can be reviewed where they may create risk.
Context Helps Separate Normal Activity from Risk
Monitoring is more useful when it understands where users are normally expected to connect from.
KES can define expected countries, trusted IP addresses, network ranges and approved cloud-service locations so alerts can be assessed with better context.
This does not mean every connection outside an approved location is malicious, but it helps prioritise events that need attention.
Context can include:
- Expected countries
- Known office networks
- Approved public IP addresses
- Trusted cloud-service providers
- Normal user activity patterns
- Customer-specific exceptions
Relevant Events Can Be Escalated for Investigation
Event Detection
The monitoring platform records and evaluates Microsoft 365 activity against configured rules and thresholds.
KES Review
Relevant events can be reviewed by KES to determine whether the activity appears legitimate or requires further action.
Customer Contact
Where user confirmation, account action or remediation is required, KES can contact the customer and agree the next steps.
Account Containment
Depending on the event, response may include password changes, session revocation or additional account-security checks.
Mailbox Investigation
Suspicious forwarding, permissions and inbox rules can be reviewed as part of account-compromise investigation.
Ongoing Improvement
Findings can be used to strengthen security policies and reduce the chance of similar events recurring.
Monitoring What Happens and Reviewing How Microsoft 365 Is Configured
Activity monitoring helps identify events. Security posture review helps identify configuration weaknesses before they become incidents.
Mailbox Security
Review of settings such as forwarding, auditing, spam notifications and external access.
Application Consent
Review of controls that determine whether users can grant third-party applications access to company data.
Sharing and Collaboration
Review of external sharing, calendar access and other collaboration settings that may expose business information.
Data Protection
Identification of opportunities to improve data-loss prevention, retention and information classification.
Session and Access Controls
Review of sign-in, session and access settings that affect how users and devices connect.
Security Recommendations
KES can identify recommended improvements and assess whether they are suitable for the customer’s licences and working practices.
Security recommendations are not applied blindly. Some controls can affect legitimate applications, external sharing or business workflows and must be assessed before implementation.
Useful Oversight Without Making Unrealistic Promises
Not Every Event Is Malicious
Microsoft 365 produces a large volume of legitimate activity. Monitoring helps identify events that deserve review.
Not a 24/7 Security Operations Centre
Standard Business User Pack customers receive active monitoring during KES support hours, not a continuously staffed external SOC.
Not a Guarantee Against Compromise
Monitoring improves visibility and response but cannot guarantee that every attack or misuse will be prevented.
Microsoft 365 Monitoring Is Stronger When Combined with Other Controls
Microsoft 365 Business Premium
Identity, access and device-management capabilities that support stronger Microsoft 365 control.
Learn more →Managed Email Security
Additional analysis and user guidance for phishing, impersonation and suspicious messages.
Learn more →Dark Web Monitoring
Monitoring for business email addresses and credentials appearing in known breach data.
Learn more →Microsoft 365 Backup
Independent backup and recovery for supported Microsoft 365 data.
Learn more →Identity Protection
Controls and monitoring designed to reduce the risk of unauthorised account access.
Learn more →Included IT Support
Routine user support and administration when investigation or remediation is required.
Learn more →Automated Monitoring Continues Outside Support Hours
Microsoft 365 monitoring continues collecting and evaluating activity outside normal KES service hours.
Human review and response are provided during standard support hours unless a separate extended-hours arrangement has been agreed.
KES support hours:
- Monday to Friday
- 8:00am to 5:30pm
- Excluding public holidays
- Urgent out-of-hours review is not guaranteed
Explore the Related Protection and Management Services
Microsoft 365 Business Premium
Managed licensing, identity, applications and device-management capabilities.
Learn more →Managed Device Security
Encryption, compliance, patching and device management for included computers.
Learn more →Business User Pack Onboarding
Structured deployment of Microsoft 365, security, backup and monitoring services.
Learn more →Security Awareness Training
Practical training and phishing simulations to improve user awareness.
Learn more →Included IT Support
Pooled remote support and routine Microsoft 365 administration.
Learn more →Business User Pack
See how Microsoft 365, monitoring, backup, security and support fit together.
View the complete package →Would You Know If Something Changed Inside Microsoft 365?
We can review your current Microsoft 365 security, activity monitoring and alerting and show you where visibility can be improved.
Microsoft 365 Monitoring, Security and Management FAQs
What Microsoft 365 activity is monitored?
Monitoring can include sign-ins, mailbox forwarding, inbox rules, account changes, administrative changes and unusual file activity.
Does monitoring block suspicious sign-ins automatically?
Monitoring identifies events for review. Access controls and automated responses depend on the customer’s Microsoft licensing, configuration and the nature of the event.
Are all monitoring alerts genuine security incidents?
No. Many events are legitimate. Monitoring provides context and visibility so unusual activity can be assessed.
Does every alert create a support ticket?
Not currently. Alerting is tuned to avoid overwhelming the service desk with routine events, and relevant events are escalated for investigation.
Is this a 24/7 SOC service?
No. Automated monitoring continues outside normal hours, but standard human review and response are provided during KES support hours.
Does KES automatically apply every Microsoft 365 recommendation?
No. Recommendations are assessed for suitability because some controls can affect applications, sharing and normal business workflows.
Is Microsoft 365 monitoring included in the Business User Pack?
Yes. Microsoft 365 activity and security posture monitoring are included as part of the wider managed-service protection.