Skip to content

This tool is not affiliated with, endorsed by or sponsored by Microsoft Corporation. Microsoft 365, Microsoft Entra ID, Exchange Online and Microsoft Purview are trademarks of the Microsoft group of companies. Other names are trademarks of their respective owners.

Glossary

Plain-language definitions of the Microsoft 365 and Entra ID forensics terms used across the site.

MailItemsAccessed
Exchange Online mailbox audit action recording when mail items are accessed by any protocol or client, used to determine which messages an intruder could see.
Illicit consent grant
An attack in which a user or admin is tricked into granting an attacker's OAuth application access to mail, files or the directory, bypassing password and MFA.
Device code phishing
Phishing that abuses the OAuth device code flow: the victim enters an attacker-supplied code on Microsoft's device login page and the attacker receives the tokens.
Impossible travel
Two sign-ins of the same account from places too far apart for the time between them; a useful lead for account takeover, with many false positives.
Non-interactive sign-in
An Entra ID sign-in performed by a client with an existing token, without user input; the log where token use and token replay become visible.
Adversary-in-the-middle (AiTM) phishing
Phishing that proxies the real Microsoft sign-in page, relaying password and MFA to steal the resulting session cookie so the attacker can bypass MFA.
Token replay
Reuse of a stolen session cookie, refresh token or access token from another device or network, letting an attacker act as the user without signing in again.
Inbox rule
A mailbox rule that automatically moves, deletes, marks or forwards incoming messages; attackers use them in BEC to hide replies and exfiltrate mail.
AuditData
The JSON column of a Microsoft 365 audit log export that holds the full detail of each record: parameters, client IP, session and token identifiers.
Linkable identifiers (Session ID, Unique token identifier)
Identifiers Microsoft Entra embeds in tokens and surfaces in sign-in and workload logs, linking mailbox and file actions back to the sign-in that issued the token.
Unified Audit Log (UAL)
Microsoft Purview's tenant-wide audit log of user and admin activity across Exchange Online, SharePoint, OneDrive, Entra ID, Teams and other Microsoft 365 services.
Business email compromise (BEC)
Fraud in which an attacker uses or impersonates a trusted mailbox, typically to divert payments or steal data, often after taking over a Microsoft 365 account.