Glossary
Plain-language definitions of the Microsoft 365 and Entra ID forensics terms used across the site.
- MailItemsAccessed
- Exchange Online mailbox audit action recording when mail items are accessed by any protocol or client, used to determine which messages an intruder could see.
- Illicit consent grant
- An attack in which a user or admin is tricked into granting an attacker's OAuth application access to mail, files or the directory, bypassing password and MFA.
- Device code phishing
- Phishing that abuses the OAuth device code flow: the victim enters an attacker-supplied code on Microsoft's device login page and the attacker receives the tokens.
- Impossible travel
- Two sign-ins of the same account from places too far apart for the time between them; a useful lead for account takeover, with many false positives.
- Non-interactive sign-in
- An Entra ID sign-in performed by a client with an existing token, without user input; the log where token use and token replay become visible.
- Adversary-in-the-middle (AiTM) phishing
- Phishing that proxies the real Microsoft sign-in page, relaying password and MFA to steal the resulting session cookie so the attacker can bypass MFA.
- Token replay
- Reuse of a stolen session cookie, refresh token or access token from another device or network, letting an attacker act as the user without signing in again.
- Inbox rule
- A mailbox rule that automatically moves, deletes, marks or forwards incoming messages; attackers use them in BEC to hide replies and exfiltrate mail.
- AuditData
- The JSON column of a Microsoft 365 audit log export that holds the full detail of each record: parameters, client IP, session and token identifiers.
- Linkable identifiers (Session ID, Unique token identifier)
- Identifiers Microsoft Entra embeds in tokens and surfaces in sign-in and workload logs, linking mailbox and file actions back to the sign-in that issued the token.
- Unified Audit Log (UAL)
- Microsoft Purview's tenant-wide audit log of user and admin activity across Exchange Online, SharePoint, OneDrive, Entra ID, Teams and other Microsoft 365 services.
- Business email compromise (BEC)
- Fraud in which an attacker uses or impersonates a trusted mailbox, typically to divert payments or steal data, often after taking over a Microsoft 365 account.