Detecting Forged Token Mailbox Access: Defender XDR and Sentinel Hunting Queries
Retrospective: this article looks back at events from July 2023, written in 2026 with the benefit of hindsight.
Forged or stolen tokens let attackers access mailboxes without normal sign-ins. Mailbox access audit events are often the only evidence.
Signals worth watching
MailItemsAccessedevents from unusual IP addresses, user agents or applications.- Mailbox access with no corresponding interactive sign-in in Entra ID sign-in logs.
- Access to executive or sensitive mailboxes by unexpected clients.
- Large numbers of items accessed in a short period (sync-type access).
- Access through Outlook Web Access (OWA) from infrastructure not used by your organization.
Where the data lives
- Microsoft Purview audit (MailItemsAccessed, Send, SearchQueryInitiated).
OfficeActivityandCloudAppEventsin Sentinel / Defender XDR.- Entra ID sign-in logs for correlation.
A starting query
Mailbox access from IPs never seen in the user's sign-in logs:
let signinIPs = SigninLogs
| where TimeGenerated > ago(14d) and ResultType == "0"
| summarize IPs = make_set(IPAddress) by UserPrincipalName;
OfficeActivity
| where TimeGenerated > ago(1d) and Operation == "MailItemsAccessed"
| join kind=leftouter signinIPs on $left.UserId == $right.UserPrincipalName
| where not(set_has_element(IPs, ClientIP))
| project TimeGenerated, UserId, ClientIP, ClientInfoString
Expect noise from Microsoft service IPs and mobile carriers; refine with known ranges.
Response
- Identify which mailboxes and items were accessed.
- Revoke sessions and tokens for affected users.
- Engage Microsoft support if you suspect token forgery or a provider-side issue.
- Notify affected parties as required.
- Storm-0558 (July 2023): A Stolen Signing Key and Forged Tokens Into Government Email Incident Teardowns
- How to Enable Expanded Audit Logging to Detect Mailbox Access How-To & Hardening
- CIO Brief: Storm-0558 and Paying Extra for Security Logs CIO Briefings