The sequence, in the order it happens
- Minute zero. Someone opens a message on an existing supplier thread and follows a link to a page that reproduces their own organisation's sign-in screen. The thread is genuine. Often it is being read from a mailbox at the supplier that was taken first.
- Minute 2. The password and the number match in the authenticator application are both satisfied against a reverse proxy, which relays them to the identity provider and keeps the session token that comes back.
- Minute 20 or thereabouts. The token is replayed from an address in a hosting provider's range. The sign-in log records a success with no second factor requested, because from the service's point of view that session is already authenticated.
- Within the hour. An inbox rule is created, usually named with a single character or a full stop. It moves anything containing invoice, remittance or bank to a folder nobody opens, and marks it read.
- The same working day. A reply leaves the mailbox on the supplier thread carrying amended account details, with no attachment and the correct signature block.
- Days later. The supplier asks about a payment it has not received. That is how almost every one of these is found, and by then the mailbox has been quiet for a week.
Where the evidence is
Four sources carry it, and they are pulled before anything is remediated, because password resets and rule deletions change what the mailbox looks like without changing what the log says. Sign-in logs, interactive and non-interactive, give the replay and the absence of a second factor. The unified audit log gives New-InboxRule, UpdateInboxRules and Set-Mailbox, with the client IP address and the session identifier. Message trace gives what actually left the tenant and when. The mailbox itself gives the rule as it stands now, which is the least reliable of the four. The session identifier is the join key: it is what ties the replayed token to the rule creation and to the sent item, and without it you have a sequence of coincidences.
Multi-factor authentication is not what failed. It worked, and the session it produced was carried away intact.
The mistake I have made
Early in this work I built a timeline that mixed audit records in UTC with times as the mailbox displayed them, in the mailbox owner's own local setting. The error was one hour, and it put the inbox rule before the sign-in that created it. That is not a cosmetic error. It changes the account of how the rule was created, and I had already said it out loud in a meeting. Every timeline I build now is in UTC, with the source and the field name written beside each row, and any converted time written twice.
The harder limit is licensing. MailItemsAccessed, the event that records which messages were read, is a premium audit feature. On a standard licence it does not exist, so you can prove what was sent and what rules were made, and you cannot prove what was read. When the mailbox holds personal data, that gap decides the notification: counsel has to assume access, and the notification goes wider than it might have. Say that in writing, in the report, rather than working around it in conversation.
The controls that change the outcome
- A compliant or hybrid-joined device required for mail and file access, which makes a token taken off the device useless
- Legacy authentication blocked across the tenant, with named service accounts moved to modern authentication first
- Creation of an inbox rule or a forwarding address raised as an alert into a queue with an owner, not into a monthly report
- A change to a supplier's bank details verified by callback to a number already held on file, with the callback logged against the payment
The identity work takes weeks and usually a licence uplift. The callback takes one meeting and costs nothing, and it is the control that stops the money leaving. We rehearse the reconstruction on our own tenant: create the rule, replay the token, then build the timeline from logs alone and check it against what we know we did. That is a laboratory, and a laboratory is not the same as doing it with a finance team waiting and a bank's recall window closing.