Tom Whitfield Sample
Security leadership across 14 countries of retail estate. · member since Mar 2026
For anyone who has not read it: in July 2023 Microsoft disclosed that a threat actor tracked as Storm-0558 forged authentication tokens using a stolen signing key to access Exchange Online mail for a number of organisations, including government bodies. The subsequent public review of the incident was unusually critical of the vendor's practices.
What I took from it as a customer was not about that vendor specifically. It was that our own detection assumed the identity provider was trustworthy. If tokens can be forged upstream, the authentication logs look perfectly normal.
Priya Raghunathan Sample
Detection engineering lead. Writes the rules, tunes the noise. · 5 months ago
This is the part that changed our detection thinking too. We added detections that do not depend on the authentication event being suspicious: impossible travel on the mailbox rather than the login, anomalous mail rule creation, unusual client strings, bulk access patterns.
If the front door log cannot be trusted, watch what happens after the door.
Isabelle Moreau Sample
Consultant Independent consultant. Runs vendor bake-offs for a living. · 5 months ago
We also started retaining mailbox audit logs for longer than the default, because the investigation window for something like this is far longer than the retention most tenants ship with. That is a cheap change with a real payoff.
Tom Whitfield Sample
Security leadership across 14 countries of retail estate. · 5 months ago
Longer retention is on our list now. The uncomfortable general lesson is that a cloud service's own logs are the only evidence you have, and you are trusting the same party for both the service and the evidence about the service.