๐Ÿ“‹ GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROCโ€ฆSaaS discovery for data governanceFree enriched web chat widget๐Ÿš€ Enriched remote support without your laptop

Microsoft 365 Breach Console

Triage suspected Microsoft 365 account compromises, with a plain-language explanation of what happened and what to do next.

Where to find it
Opened from Microsoft 365 โ€บ Microsoft 365 (Open Breach Console)
Who can use it
Anyone who can see the page
Plan
Microsoft 365 monitoring
For
Everyone

What the page is for

Lavawall watches your Microsoft 365 sign-ins and activity for signs that an account has been taken over. Rather than showing every alert, it groups related evidence into incidents and only puts an incident in Needs action when it is backed by several independent kinds of evidence. Weaker patterns go on the Watchlist, and noise is removed automatically.

Open an incident to see What happened, Why we flagged it and What to do next, followed by the evidence in the order it happened. Badges show when Microsoft's own security systems also flagged it, when a hidden network such as a VPN, Tor or proxy was involved, and when an AI analysis is available.

When you decide, mark the incident as a Real threat, Normal activity or Wrongly flagged. Lavawall can remember a pattern you mark as normal so it isn't flagged again. MSPs can view a summary of incidents across all companies.

What you see

The Microsoft 365 Breach Console page, with the summary figures, queue filters, incident list, incident details, decision bar and analysis & response tools numbered 1 to 6.
The Microsoft 365 Breach Console page. Numbers match the list below.
  1. Summary figures: Needs action, Watchlist, Users affected, Noise removed (30d) and Resolved (7d). Click a figure to show that list.
  2. Queue filters: Needs action, Watchlist, All open and Recently closed; Group by user; a sort order; search; and refresh.
  3. Incident list: one row per incident (or per person when grouped) with risk, badges and an investigate button. Load more shows older items.
  4. Incident details: AI analysis, What happened, Why we flagged it, What to do next, Full user timeline, Search everything for this user, and the evidence list.
  5. Decision bar: Remember this pattern as normal, Notes (optional), PDF report, Real threat, Normal activity and Wrongly flagged.
  6. Analysis & response tools: an expandable section with user timelines, sign-in analysis, suspicious IPs and account locks.

How to triage an incident

  1. Start on Needs action, sorted Highest risk first.
  2. Click the investigate button on an incident.
  3. Read What happened and Why we flagged it, then review the evidence in order.
  4. Follow the steps in What to do next. Use Full user timeline or Search everything for this user for more context.
  5. Choose a decision:
    • Real threat: this is a real security problem; start your response.
    • Normal activity: a person did this legitimately, for example while travelling or on a new device.
    • Wrongly flagged: the detection itself was wrong.
  6. Optionally tick Remember this pattern as normal and add Notes before deciding.

How to find a specific incident

  1. Choose All open or Recently closed.
  2. Type a user, name, title, type, country or IP address in the search box.
  3. Change the sort to Newest activity first, Most evidence first, Highest confidence first or User Aโ†’Z as needed.
  4. Turn off Group by user to see each incident on its own row.

How to share an incident report

  1. Open the incident.
  2. Click PDF report to open a print-ready report you can save or send.

Tips

  • An empty Needs action list is good news: only incidents with several kinds of evidence appear there.
  • An MS badge means Microsoft's security systems agreed. A Hidden network badge means the activity came through a VPN, Tor or proxy.
  • Use Remember this pattern as normal for recurring, legitimate activity such as a known travel location so you get fewer false alarms.
  • To lock an account or revoke sessions, Lavawall needs Read + Write access. Re-authorize from the Microsoft 365 dashboard if needed.
  • Times are shown in your browser's time zone.

Troubleshooting

  • "Nothing needs action right now." No incident currently has enough independent evidence. Check Watchlist for weaker signals.
  • "No incidents match this filter." Clear the search box or choose another list.
  • "Microsoft 365 Not Connected." Connect Microsoft 365 for this company first.
  • "Could not load this incident: please try again." Refresh the page and open the incident again.

Task guides that use this page

Still need help?

Search the support centre, or contact our support team and tell us which page you were on.

Names, companies, devices and figures in the pictures are examples. Other product and company names are trademarks of their respective owners.