How to Investigate Unexpected Microsoft 365 Sign-In Activity
Question details
The user needs to investigate potential unauthorized access to their Microsoft 365 account due to repeated unusual sign-ins and unexpected application activities.
- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Monitoring account security after noticing unfamiliar application names, remote-management software, and unexpected file or email changes.
- Observed behavior
- The Entra ID logs show repeated successful and failed sign-ins with unfamiliar application names like Microsoft Account Controls V2 or Office Online Core SSO, alongside unexpected notifications and Excel behavior.
Ensure you have administrative privileges to access the Microsoft Entra admin center (formerly Azure AD) to view detailed sign-in logs and security policies.
Analyze Entra ID Sign-In Logs and Authentication Methods
Reviewing the specific details of sign-in events is the most reliable way to determine if an account is compromised or if background services are merely authenticating.
Application names alone (such as Microsoft Account Controls V2 or Office Online Core SSO) do not prove an account is compromised. Microsoft 365 services frequently perform routine background authentication.
When remote-management tools like NinjaRMM or ScreenConnect are present, it is crucial to verify if your IT team deployed them legitimately before assuming a breach.
Log into the Microsoft Entra admin center and navigate to the 'Sign-in logs' section under the Identity menu.
Filter the logs by the affected user, status (Success/Failure), and timeframe to isolate the suspicious activity.
Review the 'Location' and 'Device info' tabs for each sign-in to confirm if the IP address or device matches known user locations.
Check the 'Authentication Details' tab to see which method was used (e.g., password, MFA) and verify if conditional access policies were applied correctly.
Audit Mailbox Rules and Delegated Permissions
Attackers often create hidden mailbox rules or grant app permissions to maintain persistence after an initial compromise.
Looking for a Secure and Lightweight Office Suite?
If managing complex Microsoft 365 subscriptions and enterprise network logs is becoming overwhelming for your personal or small business needs, consider switching to WPS Office. It provides robust, secure document management without the overhead of enterprise administrative centers.
- 1. Download and Install: Visit the official WPS Office website and download the free installer for your operating system.
- 2. Open Your Existing Files: Launch WPS Office and open your existing Microsoft Office files directly; no formatting conversion is required.
- 3. Secure Your Documents: Use the built-in document encryption feature under the 'Protect' tab to password-protect your sensitive files locally.

Frequently Asked Questions
Why do I see 'Office Online Core SSO' in my sign-in logs?
This is a legitimate Microsoft 365 background service used to authenticate your session across different Office online applications seamlessly. It does not indicate a hack unless it is paired with unrecognized IP addresses.
Are remote-management tools like ScreenConnect or NinjaRMM dangerous?
While these are legitimate tools commonly used by IT departments for remote support, they can be exploited by attackers if installed without authorization. Always verify with your IT team if you see them unexpectedly in your logs.
How can I stop unauthorized Microsoft 365 sign-in attempts?
You can mitigate unauthorized attempts by enabling Multi-Factor Authentication (MFA), configuring Conditional Access policies to block sign-ins from unexpected countries, and setting up Smart Lockout to prevent brute-force password attacks.
What should I do if my Excel behavior is suddenly unexpected?
Unexpected Excel behavior paired with suspicious network logs could indicate malicious macros or unauthorized add-ins. Disable macros in the Trust Center and run a full antivirus scan on your endpoint device.




