Microsoft 365 Audit Log & Insider Investigation
Microsoft 365 audit log and insider investigation in British Columbia.
Most workplace misconduct now leaves its trace in the tenant, not on the laptop. We reconstruct who opened, downloaded, shared, forwarded, or deleted what, and when, from the Purview unified audit log, Entra ID, SharePoint, and Exchange records.

When this service is needed
Typical scenarios where counsel and corporate clients retain us.
- Departing employee suspected of taking client lists or files
- Mass download or external sharing from SharePoint or OneDrive
- Confidential email forwarded to a personal account
- Records deleted or altered before an audit or dispute
- Administrator misuse of privileged access
- Workplace misconduct in Teams chats or channels
How we approach it
A defensible, repeatable process.
Tools we apply
Named, current, and listed in every report.
- Microsoft Purview Audit (Standard and Premium)
- Microsoft Entra ID sign-in, audit, and risk logs
- SharePoint and OneDrive file activity reports
- Exchange Online mailbox audit and message trace
- Magnet AXIOM Cyber for endpoint correlation
Standards we follow
Aligned to Canadian and international guidance.
- Sedona Canada Principles on ESI
- Microsoft 365 audit log schema and retention documentation
- BC PIPA and PIPEDA limits on employee monitoring
What you receive
Deliverables built for counsel, the regulator, and the court.
Forensic image, examiner report, exhibits and hash logs, and an expert affidavit where the matter requires it.
Common questions
Microsoft 365 Audit Log & Insider Investigation questions from Canadian counsel and corporate clients.
How far back can Microsoft 365 audit logs be searched?
Answer pending.
Can you see which files an employee downloaded before resigning?
Answer pending.
Does the audit log show what was sent to a personal email address?
Answer pending.
Is it legal in BC to review an employee's Microsoft 365 activity?
Answer pending.
What if audit logging was never turned on?
Answer pending.
Do you also need the employee's laptop?
Answer pending.
Related services
Often retained alongside microsoft 365 audit log & insider investigation.
Business Email Compromise Investigation
Reconstruction of attacker activity in Microsoft 365 and Google Workspace after wire fraud, invoice fraud, or a mailbox takeover, with an insurer-ready report.
Explore servicePurview eDiscovery & Litigation Hold Support
Defensible litigation holds, custodian searches, and reviewable exports from Microsoft 365 using Purview eDiscovery, run for counsel and in-house teams.
Explore serviceComputer Forensics
Forensic imaging and analysis of Windows, macOS, and Linux systems for litigation, internal investigations, and expert witness work.
Explore serviceNeed microsoft 365 audit log & insider investigation support on a Canadian matter?
Book a confidential consultation. Our team will reach out as soon as possible.
