logo
search
Suspicious Login Issues

How to Investigate Unexpected Microsoft 365 Sign-In Activity

Maira MehtabMaira Mehtab Sep 22, 2026 869 views

Question details

The user needs to investigate potential unauthorized access to their Microsoft 365 account due to repeated unusual sign-ins and unexpected application activities.

Product
Microsoft 365
Device & OS
not provided
Scenario
Monitoring account security after noticing unfamiliar application names, remote-management software, and unexpected file or email changes.
Observed behavior
The Entra ID logs show repeated successful and failed sign-ins with unfamiliar application names like Microsoft Account Controls V2 or Office Online Core SSO, alongside unexpected notifications and Excel behavior.
Before you start

Ensure you have administrative privileges to access the Microsoft Entra admin center (formerly Azure AD) to view detailed sign-in logs and security policies.

Solution 1Recommended

Analyze Entra ID Sign-In Logs and Authentication Methods

Reviewing the specific details of sign-in events is the most reliable way to determine if an account is compromised or if background services are merely authenticating.

Application names alone (such as Microsoft Account Controls V2 or Office Online Core SSO) do not prove an account is compromised. Microsoft 365 services frequently perform routine background authentication.

When remote-management tools like NinjaRMM or ScreenConnect are present, it is crucial to verify if your IT team deployed them legitimately before assuming a breach.

1
Access Entra ID Admin Center

Log into the Microsoft Entra admin center and navigate to the 'Sign-in logs' section under the Identity menu.

2
Filter the Sign-In Logs

Filter the logs by the affected user, status (Success/Failure), and timeframe to isolate the suspicious activity.

3
Check IP and Location Data

Review the 'Location' and 'Device info' tabs for each sign-in to confirm if the IP address or device matches known user locations.

4
Review Authentication Details

Check the 'Authentication Details' tab to see which method was used (e.g., password, MFA) and verify if conditional access policies were applied correctly.

Background Processes: Many unfamiliar apps listed in logs are native Microsoft background services. Always correlate app names with IP addresses and device status before assuming a breach.
Free Microsoft Office alternative

Looking for a Secure and Lightweight Office Suite?

If managing complex Microsoft 365 subscriptions and enterprise network logs is becoming overwhelming for your personal or small business needs, consider switching to WPS Office. It provides robust, secure document management without the overhead of enterprise administrative centers.

  1. 1. Download and Install: Visit the official WPS Office website and download the free installer for your operating system.
  2. 2. Open Your Existing Files: Launch WPS Office and open your existing Microsoft Office files directly; no formatting conversion is required.
  3. 3. Secure Your Documents: Use the built-in document encryption feature under the 'Protect' tab to password-protect your sensitive files locally.
Fully compatible with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx).Built-in local document encryption to keep your files secure offline.Lightweight installation with a user-friendly, unified tabbed interface.Free to use for essential office tasks, saving you from expensive subscription fees.
microsoft office alternative - wps office

Frequently Asked Questions

Why do I see 'Office Online Core SSO' in my sign-in logs?

This is a legitimate Microsoft 365 background service used to authenticate your session across different Office online applications seamlessly. It does not indicate a hack unless it is paired with unrecognized IP addresses.

Are remote-management tools like ScreenConnect or NinjaRMM dangerous?

While these are legitimate tools commonly used by IT departments for remote support, they can be exploited by attackers if installed without authorization. Always verify with your IT team if you see them unexpectedly in your logs.

How can I stop unauthorized Microsoft 365 sign-in attempts?

You can mitigate unauthorized attempts by enabling Multi-Factor Authentication (MFA), configuring Conditional Access policies to block sign-ins from unexpected countries, and setting up Smart Lockout to prevent brute-force password attacks.

What should I do if my Excel behavior is suddenly unexpected?

Unexpected Excel behavior paired with suspicious network logs could indicate malicious macros or unauthorized add-ins. Disable macros in the Trust Center and run a full antivirus scan on your endpoint device.