Default logging settings in Microsoft 365 create a documented attack vector — flagged publicly by CISA, the FBI, and multiple incident response firms in 2023, 2024, and into 2025. The mechanism is not a software bug. It is a deliberate product-tier decision by Microsoft that determines what a standard business license records versus what a premium license records. Sophisticated attackers have learned exactly where that line sits, and they operate precisely below it. What follows is a data-backed analysis of how these logging deficiencies are exploited, who they target, what the public record reveals, and what any informed executive or IT decision-maker should demand of their environment today.
- Understanding Microsoft 365 Logging Tiers
- What CISA and FBI Advisories Actually Say
- The Storm-0558 Incident: A Case Study in Log Absence
- Why Small Businesses Are the Primary Target
- How the Attack Chain Exploits the Gap
- Real-World Incident Disclosures: The Pattern
- Defense Posture: Closing the Gap Without a Six-Figure Retainer
- What to Ask Your IT Firm Right Now
Understanding Microsoft 365 Logging Tiers and Where the Gaps Begin
Microsoft 365 ships with what it calls the Unified Audit Log. For most business license tiers — Microsoft 365 Business Basic, Business Standard, and even Business Premium — the default retention window for audit log data is 90 days. Certain high-value event types, including mail-item access logs (which record exactly who read which email and when), are gated behind Microsoft Purview Audit (Premium), formerly called Advanced Audit. That premium tier requires an E5 license or a separate Purview add-on that most small and mid-size businesses have never purchased.
The events locked behind that paywall are not trivial. They include MailItemsAccessed — the log entry that tells an investigator which specific emails a compromised account read during an intrusion. They also include Send events at the item level, extended sign-in intelligence, and longer retention windows (up to one year at Premium, up to ten years with an additional add-on). Without these logs, post-breach forensics on a standard tenant is like proving someone broke into a building by examining the building after they left. You know they were there. You cannot prove what they took.
This is not an accident. It is a product decision. The consequences of that decision, however, are now showing up in federal advisories and public incident disclosures with enough frequency to constitute a documented threat pattern — increasingly cited by name in regulatory and legal contexts.
What CISA and FBI Advisories Actually Say About Default Logging Deficiencies

In May 2023, CISA and several partner agencies published a joint advisory titled Enhanced Monitoring to Detect APT Activity Targeting Outlook Online — a direct response to the Storm-0558 intrusion (covered in the next section). The advisory made an unusually blunt statement for a government document: organizations that did not have Purview Audit (Premium) enabled could not determine whether their own mailboxes had been accessed during the intrusion. Not “might struggle to determine.” Could not. The data simply did not exist.
CISA followed that with updated guidance in its Microsoft 365 Security Recommendations documentation, explicitly naming the default logging gap as a remediation priority. The agency recommended enabling the Unified Audit Log for all users, extending retention beyond the 90-day default where possible, and enabling mailbox auditing on every account — because, critically, mailbox auditing is also not enabled by default on all account types in older tenant configurations.
The FBI’s Internet Crime Complaint Center 2024 annual report recorded $16.6 billion in total cybercrime losses in the United States — a 33% increase over 2023. Business email compromise, which almost always involves unauthorized email access of exactly the kind that Purview Audit (Premium) logs, accounted for $2.77 billion of that figure. Insufficient logging is not a theoretical problem. It is a documented contributor to the forensic silence that lets business email compromise actors complete wire transfer fraud before anyone realizes a mailbox was ever touched.
You can review CISA’s published Microsoft 365 hardening guidance directly at CISA.gov.
The Storm-0558 Incident: A Case Study in Log Absence
Storm-0558 is an attacker group assessed by Microsoft and U.S. government agencies as operating in alignment with Chinese state interests. In the summer of 2023, the group used a forged authentication token — created using a compromised Microsoft signing key — to access the Outlook Online mailboxes of approximately 25 organizations, including multiple U.S. government agencies.
The intrusion was not discovered by the targeted organizations. It was discovered by one agency that had purchased Purview Audit (Premium) and noticed anomalous MailItemsAccessed events during a routine review. Microsoft’s own security team subsequently confirmed the breach and identified the forged token as the root cause. But the critical forensic detail buried in the post-incident reporting was this: most of the 25 affected organizations had no way to determine which specific emails were accessed, because they lacked the premium logging tier that records individual mail-item reads.
The Senate Homeland Security Committee published a detailed report in June 2024 criticizing Microsoft’s security practices and, specifically, its decision to keep certain logging capabilities behind a paywall. The committee’s report noted that the differential logging model “creates a two-tiered system of cybersecurity” where organizations with standard licenses are structurally disadvantaged in their ability to detect and investigate intrusions. That is a congressional committee — not a vendor — stating that the product is designed in a way that harms security outcomes for customers who cannot afford premium tiers. The Storm-0558 case remains the clearest public illustration of how default logging deficiencies directly impair breach investigation.
Why Small Businesses Are the Primary Target
Attackers who understand the logging tier gap do not target it randomly. They favor environments where the premium logging tier is unlikely to be present. Large enterprises with dedicated security teams almost always carry E5 licensing or equivalent — in part because their cyber insurers require it. Small businesses running Business Basic or Business Standard, which represents the majority of the SMB market, are structurally more likely to have the gap.
The math for an attacker is straightforward:
- A 50-person professional services firm running Microsoft 365 Business Standard pays roughly $12.50 per user per month — a license with 90-day log retention and no MailItemsAccessed logging.
- Upgrading to E3 with the Purview Audit (Premium) add-on more than doubles the per-seat cost for logging capabilities alone.
- Most SMB owners have never been told that these logging deficiencies exist, let alone been shown what they mean for their ability to investigate a breach.
- Cyber insurance underwriters are starting to ask about audit log retention, but many small businesses answer these questions through brokers who are not technically equipped to verify the actual tenant configuration.
The result: a population of businesses using a platform that holds their most sensitive communications, operating with a forensic blind spot they don’t know they have, facing attackers who know exactly where that blind spot is.
How the Attack Chain Exploits Logging Blind Spots
The attack sequence that takes advantage of insufficient audit logging follows a recognizable pattern across multiple public incident disclosures. It typically proceeds as follows:
- Initial access via credential theft or token hijacking. Phishing, adversary-in-the-middle proxy attacks, or stolen session tokens give the attacker authenticated access to the target tenant without triggering a failed-login alert.
- Reconnaissance inside the mailbox. The attacker reads emails, identifies financial workflows, locates wire transfer instructions, maps org charts, and harvests credentials shared over email — all of which generates MailItemsAccessed events that exist only in premium logs.
- Inbox rule creation. The attacker creates forwarding rules or auto-delete rules to suppress alert emails and copy specific threads to an external address. Inbox rule creation is logged in the standard Unified Audit Log, but only if mailbox auditing is enabled and the organization is actively reviewing those logs — which most are not.
- Dwell and observe. The attacker waits — sometimes for weeks or months — learning the target’s financial cadence and communication patterns. Dwell time in business email compromise incidents averages over 100 days before fraud is executed, according to multiple incident response firm reports.
- Fraud execution and exit. When the moment is right — often timed to a known transaction — the attacker redirects a payment, harvests credentials from another user, or exfiltrates sensitive data. By the time the fraud surfaces, the attacker has been gone for days or weeks.
- No recoverable forensic trail. The victim organization opens a breach investigation. Without MailItemsAccessed logs, investigators cannot confirm which emails were read, which attachments were opened, or what intelligence the attacker gathered for follow-on attacks against the victim’s clients or partners.
That last point matters enormously for professional services firms and any organization whose clients share sensitive information over email. Not knowing what an attacker read means not knowing who else may be at risk — and not being able to make legally required breach notifications with specificity. This is where logging blind spots translate directly into legal and financial exposure well beyond the initial intrusion.
Real-World Incident Disclosures: The Pattern
Beyond Storm-0558, the public record contains a consistent pattern across multiple sectors:
- A 2024 CISA advisory on Scattered Spider — a group responsible for major cloud intrusions at hospitality and financial sector targets — specifically noted that the group exploited help-desk social engineering to gain tenant administrative access, then used that access to modify audit and alert configurations before conducting data theft. Tenants without active log monitoring did not detect the configuration changes.
- CISA’s Secure by Design initiative, updated in 2024, called out cloud platform vendors by name for defaulting to insecure configurations — including insufficient logging — and argued that the security burden should not fall on customers to purchase add-ons just to achieve baseline visibility.
- Multiple incident response firms — including Mandiant and CrowdStrike, both of which publish annual threat reports with case data — documented business email compromise investigations in 2023 and 2024 where the absence of MailItemsAccessed logs made it impossible to determine the full scope of mailbox access, forcing organizations to assume worst-case exposure for breach notification purposes. Assuming worst-case under state breach notification laws can trigger notification obligations that cost more to fulfill than a premium logging license would have cost for years.
- Microsoft itself, under pressure from the Senate committee’s findings, announced in August 2023 that it would make certain previously premium logging capabilities available at no additional cost to more license tiers. The rollout has been gradual and uneven — and the responsibility for verifying that those features are actually enabled in any specific tenant still falls on the tenant’s IT administrator.
That last detail is worth underscoring. Even when Microsoft expands default logging access, it does not automatically enable those features in existing tenants. An organization that has been a Microsoft 365 customer for years may be running a configuration that reflects defaults set at tenant creation — defaults that predate any of these changes. Verification requires an active audit of the tenant configuration, not an assumption that the vendor has handled it. This is precisely why logging deficiencies persist even in organizations that believe they are fully covered.
Defense Posture: Closing Logging Gaps Without a Six-Figure Retainer
Addressing these audit log deficiencies does not require a complete platform overhaul or an enterprise security budget. It requires deliberate configuration and, in some cases, a license upgrade that is far cheaper than a breach investigation. Here is the practical checklist:
- Verify that the Unified Audit Log is enabled. In the Microsoft Purview compliance portal, confirm that audit logging is turned on for all users. This is free — but it is not guaranteed to be active in older tenants.
- Verify that mailbox auditing is enabled on every account. Run a PowerShell check against every mailbox in the tenant. Microsoft enabled mailbox auditing by default for Exchange Online in 2019, but tenants created before that date may still have it off on specific accounts.
- Assess whether your current license tier captures MailItemsAccessed events. If you are on Business Basic or Business Standard without a Purview add-on, you do not have this log. Determine whether the cost of upgrading is justified by the sensitivity of the communications flowing through your tenant.
- Set log retention to the maximum available for your license. Ninety days is not enough when attacker dwell time routinely exceeds 100 days. Where budget allows, extend retention to one year or longer.
- Implement active alerting, not just passive logging. Logs that exist but are never reviewed provide no real-time protection. Configure alerts for inbox rule creation, bulk mail downloads, external forwarding rules, and sign-ins from unexpected geographies or devices.
- Conduct a tenant configuration audit at least annually. Microsoft changes defaults, policy settings migrate during updates, and administrators make changes that drift over time. A one-time audit is not a substitute for scheduled review.
Organizations that work with a managed IT services provider should confirm that their provider is conducting this type of configuration audit proactively — not reactively after an incident is suspected. If your provider cannot show you a current audit of your Microsoft 365 logging configuration, that is a meaningful gap in your security posture, regardless of how many other services they provide. Learn more about how our team approaches cybersecurity for small and mid-size businesses, including proactive tenant configuration reviews.
What to Ask Your IT Firm Right Now About Your Logging Coverage
The logging tier gap is technical. The questions you need answered are not. Any IT firm managing your Microsoft 365 environment should be able to answer the following clearly and specifically:
- Is our Unified Audit Log enabled for every user in our tenant, and when was it last verified?
- Is mailbox auditing enabled on every account, including shared mailboxes and service accounts?
- What is our current log retention window, and does it meet or exceed the average dwell time for business email compromise attacks?
- Does our current license tier capture MailItemsAccessed events, and if not, have we made a documented decision about whether to upgrade?
- Is someone actively reviewing alert queues for inbox rule creation, external forwarding, and anomalous sign-in patterns?
- If we discovered today that an account had been compromised six months ago, could we reconstruct which emails were read? If not, what does that mean for our breach notification obligations?
If the answer to that last question is “no” or “we’re not sure,” the conversation that follows should be about remediation, not reassurance. Attackers exploiting these logging blind spots are not guessing — they know precisely which environments will leave no forensic trail. The only meaningful defense is making sure your environment is not one of them.
The quiet environments are the ones where this audit has already been done, the gaps have been closed, and the configuration is checked on a schedule. That is not a luxury posture — it is the baseline that separates organizations that can investigate a breach from organizations that have to guess what happened and notify everyone just to be safe. Closing these logging deficiencies is one of the highest-leverage, lowest-cost security improvements available to any organization running the platform today. The inherent risks created by default Microsoft 365 audit log gaps are well understood by the attacker community — the question is whether your defenders understand them equally well.
If you want a clear picture of where your Microsoft 365 tenant stands, Book a Free Cybersecurity Strategy Call. We will tell you exactly what we find — no obligation, no pressure.
Let’s Talk About Your IT Strategy
If anything in this post raised a question about your own environment, the fastest path to an answer is a 20-minute strategy call. We’ll look at your specific situation and tell you what we’d actually do about it.