Office 365 email monitoring

Sensitive files leave your tenant by email every week. Here is the list.

In a typical tenant, a month of outbound mail carries dozens of messages to external addresses with card numbers, IDs or contracts attached - and hundreds of delegate and send-as uses nobody reviews. 1Security reads mail flow across every mailbox and turns it into filters: direction, sending method, attachments, sensitive content, whole threads. It stores signals, not a copy of anyone's inbox.

  • 5
    sending methods recorded on every message: direct, send as, send on behalf, shared mailbox, delegate
  • 300+
    detectors run on attachments and bodies, so "sensitive content leaving" is a filter
  • 0
    message bodies stored - metadata and detections only, no browsable mail archive

The problem

Mail security judges what arrives. Nothing judges what leaves.

Mail security is built for inbound verdicts. The two events that cost money are outbound.

A mail gateway asks three questions of every incoming message: is it spam, is it phishing, does it carry malware - and answers them well. The outbound questions are different: what left the tenant this month, how it was sent, whether an external sender who got past the filter is now getting internal replies, and what was actually inside the attachment. Those need a second view, kept longer than a trace.

The two expensive scenarios both hide in the shape of the exchange. A single outbound message with an attachment is unremarkable. The same message to an external address, carrying a spreadsheet with 2,000 customer records that exists nowhere in SharePoint or OneDrive, sent through delegate access on a director's mailbox, is a different object. 1Security puts those four facts on one row.

And the mailbox itself is a blind spot: a typical mid-size tenant has hundreds of shared mailboxes and thousands of delegate grants, reviewed by nobody, plus forwarding rules that stay in place long after the person who created them left.

What you get

Mail flow as filters, not as an export

Every signal below is a column on the Emails screen and a filter you combine - not a report you request and wait for.

  • Direction

    Inbound, outbound or internal on every message. Exfiltration analysis starts with "outbound + external recipients"; phishing analysis with "inbound + two-way exchange".

  • Sending method

    Direct, send as, send on behalf, shared mailbox or delegate access - the four delegated paths are the favourite disguises of business email compromise, and here they are filters.

  • Attachments, three ways

    Classic attachments, cloud attachments that are really SharePoint or OneDrive links, and unique uploads - files sent by mail that exist nowhere in your tenant, the strongest single exfiltration signal.

  • Sensitive content on the row

    The 1Security scan runs 300+ detectors and OCR on bodies and attachments, so "outbound + sensitive info" is a filter. Purview labels and protection status sit beside it.

  • Whole threads as rows

    The Conversations tab rolls every thread into one line: participants, files across the exchange, accumulated detections, and whether an external sender is receiving internal replies.

  • Thread evidence that survives deletion

    Every message is classified as root, reply or forward and linked across mailboxes. A reply whose parent is missing from every scanned mailbox is proof the original was removed.

How deep it goes

The exfiltration shortlist, in four filters

Outbound + external recipients + sensitive info + unique uploads. That list is usually short and always worth reading.

It means sensitive content leaving the organization inside files that never existed in SharePoint or OneDrive - a spreadsheet exported from a system of record, a photographed contract, a database dump. In a typical tenant the shortlist for a month is a few dozen messages. A five-minute review resolves each one - once the list exists.

The conversation-level equivalent is the successful-phish check: Conversations tab, two-way exchange, inbound, phishing flag. Not the attempts the gateway bounced - the external senders who got answers. A message-level view cannot ask this, because the signal only exists once a thread has both directions in it.

The third is the cover-up trace: missing parent plus a phishing or malware flag. Threads where the incriminating original is already gone, but a reply still references it - which is itself a record that something was removed, and where.

In practice

Four sweeps worth saving as views

Each is a filter set on the Emails screen. Save it once and the second run costs nothing.

  1. 01

    BEC sweep

    Sending method "send as" or "delegate access", outbound, external recipients. Every delegated identity use to an outside address, ready to confirm or challenge. Typical result: a handful a week, most expected, occasionally not.

  2. 02

    Quiet forwarding

    Type "forward", external recipients, sensitive info. Internal material being passed outside one forward at a time - the leaver preparing their exit is the classic find.

  3. 03

    Living sensitive threads

    Conversations tab, with sensitive info, sorted by last activity. The exchanges still accumulating regulated content today, not the ones that died last quarter.

  4. 04

    Act on the selection

    Select messages or a mailbox and stage an automation - quarantine, flag, revoke a forwarding rule - behind the 72-hour review window. Mailbox actions quarantine or flag; nothing is permanently deleted.

The difference

What the outbound view adds

This sits beside your mail gateway rather than replacing it. The questions are different.

  • Outbound sensitive content as a filter, live - not reconstructed after the fact
  • How a message was actually sent - send as, on behalf, delegate - not just who it claims to be from
  • Files sent by mail that exist nowhere in your SharePoint or OneDrive
  • Whole threads as single rows, with participants and files summed across the exchange
  • External senders who received internal replies
  • Replies whose parent is missing from every scanned mailbox
  • The riskiest sending method used anywhere in a thread, marked on the thread
  • History kept up to three years - from a 90-day trace to three years of mail signals

Approach

Signals, not surveillance

The platform stores communication metadata and security detections - directions, participants, flags, sending method, sensitive-information matches. Bodies and attachments are analysed in a transient process and discarded. There is no browsable archive of message bodies, and it is not designed to become one.

  • 0
    message bodies stored - metadata and detections only
  • 3
    attachment kinds told apart: classic, cloud link, unique upload
  • 3 years
    of mail signals kept on standard licenses - from 90 days to three years

Related

Where this fits

Mail is one exit route. Sharing links are another, and sensitive data discovery is what makes both worth watching. Investigations tend to cross all three.

  • Sensitive data discovery

    The 300+ detectors behind "sensitive info" on a message, and where else in the tenant that data lives.

    See sensitive data
  • File permissions

    The other exit route: the thousands of anyone links and grants on the files themselves.

    See files
  • Unified audit log

    Up to three years of activity an email investigation usually continues into.

    See audit logs

FAQ

Questions teams ask first

Does this read employees' email?

It analyses messages to record signals - direction, sending method, participants, attachments, sensitive-information detections - and discards the content. There is no browsable archive of anyone's mail, deliberately: this is a security signal layer, not an inbox viewer.

How does it know a message was deleted?

By the gap it leaves. A reply carries header references to its parent. If that parent is absent from every scanned mailbox, the reply is evidence the original was removed or never passed through your tenant. The trace survives the deletion.

What is a unique upload?

A file that arrived or left by email and exists nowhere in your SharePoint or OneDrive. On outbound mail it is the strongest single exfiltration signal, because normal collaboration leaves a copy behind.

Does it need a premium license or Defender for Office 365?

No. Email monitoring runs on standard Microsoft 365 licenses through a separately consented email module on the read-only app. Defender keeps judging messages at the perimeter; this answers what left, how it was sent and what an exchange became.

Can it act, or only show?

Both. Selected messages and mailboxes can be handed to automations behind the review window - quarantine, flag, forwarding-rule removal. Mailbox actions never permanently delete, and every action is logged with who approved it.

See what left through email last month.

Connect read-only, enable the email module, and the exfiltration shortlist is four filters away the same day. Most teams find at least one thread they wish they had seen earlier.

Or keep answering outbound questions from a 90-day trace.