Skip to content
Skip to main content
Cloud Services Technical Explainer

How might an investigator recognise unauthorised cloud access?

Unauthorised access is usually recognised when several independent records form an inconsistent sequence: a new access route, activity outside established use, account changes that preserve access, and evidence that the authorised user did not initiate or understand them.

Give more weight to joined indicators

Northstar records an unfamiliar non-interactive sign-in for Dave's account at 07:42. At 07:44 a new application reads 680 files; at 07:49 it creates a sharing grant. Dave's normal phone session remains active elsewhere and his device contains the message that induced the application approval.

Compare four kinds of evidence

Dimension Examples Why it matters
Access route New factor, device, application, recovery or session Explains how authority arose
Resource behaviour Unusual volume, objects, deletion, forwarding or sharing Shows use and impact
Account change New credential, consent, permission, rule or administrator action May establish persistence or altered control
Independent context Device records, communications, user report, workplace activity Tests authority and personal attribution

Network location is only one comparison. VPNs, mobile networks and travel can alter it, while stolen tokens can be replayed from familiar infrastructure. Establish a baseline only from reliable records and the relevant period.

Microsoft risk detections - checked 2 September 2026

Microsoft Entra risk detections can include unfamiliar sign-in properties, anomalous tokens, suspicious browser or MFA activity and mass access to sensitive files. Microsoft says risk can be calculated later and can change; licensing also affects visible detail. Treat a provider risk label as an indicator with its own basis and time.

The point to remember

Recognise unauthorised access through a joined pattern of route, behaviour, account change and independent context. Preserve the underlying events behind any alert or risk score.

Reference: CLD-038Cloud Services