How might an investigator recognise unauthorised cloud access?¶
Unauthorised access is usually recognised when several independent records form an inconsistent sequence: a new access route, activity outside established use, account changes that preserve access, and evidence that the authorised user did not initiate or understand them.
Give more weight to joined indicators¶
Northstar records an unfamiliar non-interactive sign-in for Dave's account at 07:42. At 07:44 a new application reads 680 files; at 07:49 it creates a sharing grant. Dave's normal phone session remains active elsewhere and his device contains the message that induced the application approval.
Compare four kinds of evidence¶
| Dimension | Examples | Why it matters |
|---|---|---|
| Access route | New factor, device, application, recovery or session | Explains how authority arose |
| Resource behaviour | Unusual volume, objects, deletion, forwarding or sharing | Shows use and impact |
| Account change | New credential, consent, permission, rule or administrator action | May establish persistence or altered control |
| Independent context | Device records, communications, user report, workplace activity | Tests authority and personal attribution |
Network location is only one comparison. VPNs, mobile networks and travel can alter it, while stolen tokens can be replayed from familiar infrastructure. Establish a baseline only from reliable records and the relevant period.
Microsoft risk detections - checked 2 September 2026
Microsoft Entra risk detections can include unfamiliar sign-in properties, anomalous tokens, suspicious browser or MFA activity and mass access to sensitive files. Microsoft says risk can be calculated later and can change; licensing also affects visible detail. Treat a provider risk label as an indicator with its own basis and time.
The point to remember
Recognise unauthorised access through a joined pattern of route, behaviour, account change and independent context. Preserve the underlying events behind any alert or risk score.