Link to home
Start Free TrialLog in
Avatar of Pau Lo
Pau Lo

asked on

imap connection office365

if you suspect someones office365 email account may have been compromised via imap protocol (now disabled on the account and pwd updated), where specifically could you look to see if any specific data from their account has been breached/leaked/viewed? would there be any traces within the mailbox itself, or other administrative features/logs of office365?
ASKER CERTIFIED SOLUTION
Avatar of Vasil Michev (MVP)
Vasil Michev (MVP)
Flag of Bulgaria image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Pau Lo
Pau Lo

ASKER

>None of these will tell you winch exact items were accessed though.

What would they tell you then in regards to the question?
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
They will tell you when/where from the account was accessed, whether any additional workloads were accessed and so on. There are tons of audited activities, but "reading" messages in your own mailbox is simply not one of them.
If the account was compromised by IMAP, it is accessible by all other means. If data was forwarded, it shoukd be part of the sent..