Cybersecurity Services

Digital Forensics for Microsoft 365 & Google Workspace

IT Rapid Support provides digital forensics for businesses in Toronto, the GTA and Ontario, focused on Microsoft 365, Exchange Online and Google Workspace incidents such as business email compromise, suspicious sign-ins and departing-employee data theft. Digital forensics for a business means preserving and analyzing the records left by a suspected incident so you can establish what happened, which accounts and data were involved, and what the evidence can and cannot show. Find out what happened in a Microsoft 365, Exchange Online, or Google Workspace incident while the available evidence is still within reach. IT Rapid Support collects and analyzes cloud audit, identity, email, and file-access evidence for businesses across the Greater Toronto Area and Ontario, then documents the timeline, scope, findings, limitations, and recommended response actions.

Digital Forensics Done Right

Platform-specific collection, disciplined evidence handling, and findings that decision-makers can understand.

Microsoft 365 & Exchange Online

Analyze the Microsoft Purview unified audit log, mailbox auditing, Exchange message trace, inbox rules, forwarding, delegation, eDiscovery sources, and Entra ID sign-in evidence to reconstruct activity and determine affected accounts.

Google Workspace

Review Google Workspace Admin audit logs, Gmail log search, Vault data where available, OAuth grants and third-party application access, and Google Drive sharing and access activity.

Evidence & Findings

Preserve collected evidence with source notes, timestamps, hash manifests where applicable, and a documented chain of custody, then deliver a factual report suitable to share with counsel, insurers, and incident stakeholders.

What We Cover

Everything Your Digital Forensics Needs

The capabilities we manage end to end so this runs reliably for your business.

Microsoft 365 audit logsExchange mailbox forensicsEntra ID sign-in analysisGoogle Workspace audit logsGmail and Drive activityEvidence preservation and reporting

Not sure how much digital forensics you actually need?

Start with evidence rather than a sales conversation. Our free IT risk calculator scores fifteen weighted control areas and ranks your gaps by weight, so you can see whether digital forensics is the thing to buy first or whether something cheaper is holding you back. There is no sign-up and it runs entirely in your browser.

If email is anywhere in scope, run the free email spoofing check against your domain first. It reads your published SPF, DKIM and DMARC records and tells you whether your domain can be spoofed to your own clients. We built it after we reviewed the public DNS records of 118 GTA business domains and found only 40% fully protected. The follow-up work is published as our GTA small-business cybersecurity report and a scan of what 470 GTA business websites disclose about their own security.

Comparing us against another provider is fair and we would rather you did it properly. Our managed IT quote checker scores any written proposal against 22 items, and a free IT Health Check gets you a written summary of what we find, whoever you end up choosing.

What Is Cloud Digital Forensics?

Cloud digital forensics is the documented collection and analysis of audit, identity, email, and file-activity records from a cloud service after a suspected incident. For a Microsoft 365 or Google Workspace tenant, the goal is to reconstruct a timeline from the records the platform actually retained: who signed in, which settings changed, how messages moved, what files were accessed or shared, and which accounts or applications were involved. It is different from routine administration because the collection method, source, time, handler, and limitations are recorded so another decision-maker can understand what supports each finding. It is also different from a promise to recover everything. Licensing, retention, configuration, elapsed time, and actions taken after the event determine what evidence still exists, so a defensible investigation states both what the records establish and what they cannot establish.

IT Rapid Support focuses this service on Microsoft 365, Exchange Online, and Google Workspace evidence for business incidents. The result is a factual technical chronology for management, cyber insurers, and counsel—not a legal conclusion and not a guarantee that every deleted item or historical action can be recovered.

Microsoft 365 and Exchange Online Forensics

Microsoft 365 investigations start with the evidence sources that answer different parts of the event. Microsoft Purview audit records can include user and administrator operations across supported services. Exchange mailbox auditing can show events such as message access, SendAs or SendOnBehalf activity, and inbox-rule changes when those records are available. Exchange message trace follows mail flow within its retention window. Current and historical inbox rules, forwarding settings, mailbox delegation, transport configuration, and Purview content or eDiscovery searches help explain how a compromised account was used and what information may have been exposed.

Identity evidence matters just as much as mailbox evidence. We review the Entra ID sign-in and directory activity available to the tenant, including interactive and non-interactive sign-ins, source addresses, client applications, authentication results, and administrative changes. SharePoint and OneDrive audit events can add file access, download, deletion, sharing, and permission activity. The objective is a defensible timeline: how the account was accessed, what changed, which messages or files were involved, what the available records can establish, and where retention or licensing creates an evidence gap.

Google Workspace and Gmail Forensics

Google Workspace investigations use the Admin console audit and investigation data available to the organization. That can include administrator activity, login events, Gmail log search, Google Vault preservation and search, OAuth token and third-party application access, and Google Drive sharing or file-access activity. We correlate those sources instead of treating any single log as the whole story.

A Google Workspace review can identify suspicious logins, unauthorized mailbox or forwarding changes, risky OAuth grants, access by third-party applications, and unusual sharing or downloads. Availability depends on the organization's Workspace edition, audit settings, retention, and how quickly evidence is preserved, so scope begins with a source-and-retention check rather than a promise that every historical action can be recovered.

How a Cloud Forensic Investigation Works

First, scope and preserve. We identify the affected tenant, accounts, administrators, date range, known indicators, available licences, retention settings, and any legal or insurance instructions. Actions that could alter evidence are coordinated with containment rather than performed casually.

Second, collect and inventory. Relevant native exports and reports are gathered where practical, with source, method, time, account, filename or object, and handler recorded. Hashes are calculated for evidence files where that method applies, and custody transfers are logged.

Third, correlate and test. Sign-ins, mailbox events, message trace, rules, forwarding, delegation, OAuth access, and file activity are placed on one normalized timeline. A single IP address or log event is not treated as proof of a person; findings are tested against the other available sources.

Fourth, report and hand off. The report separates verified findings, interpretation, and unknowns, identifies affected identities or data supported by the evidence, records limitations, and lists containment or follow-up actions for the incident team, insurer, management, or counsel.

Business Email Compromise Investigation

Business email compromise is the most common reason to start: a mailbox sends fraudulent payment instructions, a hidden inbox rule diverts replies, or an attacker maintains access through forwarding, delegated permissions, or an OAuth application. We connect mail flow, mailbox activity, sign-ins, and configuration changes to determine the affected period and accounts, then tie the findings into containment and recovery through our cyber incident response service.

The questions are concrete: when did suspicious access begin, which authentication and client patterns were recorded, which rules or forwarding paths changed, which messages were sent or accessed, whether delegation or an application created another access path, and what evidence supports the end of the affected period. The investigation does not replace containment; it gives the response team a documented scope instead of relying on the first visible symptom.

Insider Data Theft, Departing Employees, and Ransomware Scoping

A departing-employee or suspected insider investigation asks what the available tenant records show before and after the relevant date: sign-ins, mailbox forwarding, external sharing, downloads, deletions, OAuth access, and administrative or permission changes. The records can establish activity tied to an account or application; they do not automatically establish who was physically at a keyboard or why an action occurred. That distinction belongs in the findings.

Ransomware scoping uses the same discipline when cloud identities or repositories may be involved. Entra ID or Google login activity, Microsoft 365 or Workspace audit events, mailbox changes, and file-access records can help establish which cloud accounts and data sources need attention. Endpoint containment, system recovery, and threat eradication remain part of incident response, while the forensic work preserves and reconstructs the evidence needed to understand the event.

Evidence Preservation, Chain of Custody, and Reporting

Collection is documented from the start: the tenant and source system, query or export method, date and time, account used, original filename or object, and the person handling it. Exports are retained in their native form where practical, and hashes are recorded for evidence files where that method applies. A chain-of-custody record documents who received or handled the material and why.

The report separates verified findings from interpretations and unknowns. It sets out the scope, evidence inventory, methods, timeline, affected identities or data, containment actions, limitations, and next steps. That format gives management a usable decision record and can be shared with cyber insurers, breach counsel, or litigation counsel without presenting legal conclusions that belong to counsel.

Digital Forensics vs Incident Response and eDiscovery

Digital forensics, incident response, and eDiscovery can touch the same tenant but answer different questions. Incident response is operational: contain the threat, remove access, restore systems, and reduce continuing harm. Digital forensics is evidentiary: preserve the available records, reconstruct what happened, test the scope, and document the support and limitations for each finding. The two streams often run together because a containment action can change evidence.

eDiscovery is collection and search for a legal matter under counsel's scope. A forensic investigation may use Purview eDiscovery, content search, Google Vault, or native exports as collection sources, but the forensic question is usually a chronology or incident hypothesis rather than legal responsiveness. IT Rapid Support can support documented collection and factual technical reporting; counsel controls legal strategy, privilege, responsiveness, and legal conclusions.

Managed security is the preventive and monitoring layer before an incident. Our managed security services reduce risk and watch for suspicious activity; this digital forensics service examines the retained evidence when the organization needs to establish what already happened.

What Evidence Limitations Mean in a Forensic Report

Cloud evidence is bounded by the tenant that produced it. Licence level, audit configuration, retention, the incident date, administrator actions, application behaviour, and any delay before preservation all affect what remains. A log can show that an account or application performed an action; it may not prove the identity or intent of the person behind it. An empty search can mean no recorded event, but it can also mean the event was outside retention or never logged by that source.

That is why the initial source-and-retention check matters. The final report identifies the systems and date ranges searched, the evidence found, the evidence expected but unavailable, time-zone handling, and any assumption needed to interpret the chronology. Unknowns are not filled with speculation. They are listed so management, the insurer, incident responders, and counsel can make decisions with the same boundary around the facts.

What to Do Before the Forensic Investigation Starts

The first hours after a suspected compromise decide how much evidence survives. Do not delete the affected user, mailbox, or suspicious messages, and do not wipe or rebuild a laptop that may be involved. Write down what was noticed, when, and by whom, and keep a list of every change made since, such as password resets, disabled accounts, or removed inbox rules, with the time each was made.

Containment still matters, and it should not wait for the investigation. Resetting a password, revoking sessions, or disabling forwarding can be done in a way that is recorded and coordinated with preservation, so the response team and the forensic work are not undoing each other. If your organization has cyber insurance, notify the insurer early, because many policies set out how incident response and investigation providers are engaged. Our cyber incident response page explains how containment runs alongside the investigation.

Scoping a Microsoft 365 Email Compromise Investigation

Scope sets what the investigation will examine and what question it is meant to answer. For a Microsoft 365 email compromise that usually means the mailboxes thought to be affected, the date range around the first suspicious activity, the known indicators such as a fraudulent payment request or an unfamiliar sign-in location, and the specific concern: payment fraud, exposure of client or personal information, or onward phishing sent from your domain.

The scope is agreed in writing before analysis begins and revisited if the evidence points elsewhere, for example to a second compromised account, a malicious application with mailbox permissions, or an administrator account. Expanding scope is a decision for the organization, not something that happens quietly, so the time and effort involved stay visible.

When Businesses Typically Ask for a Cloud Forensic Investigation

Most requests start from one of a few situations. A finance team discovers that a supplier or client paid money to the wrong account after an email that appeared genuine. Customers report receiving phishing messages sent from a real staff mailbox. An employee has left for a competitor and management wants to know what was shared, forwarded, or downloaded beforehand. Or an insurer, auditor, or counsel asks the organization to document what happened and which data was involved.

In each case the work is the same in principle: identify the evidence sources that still exist, preserve them, reconstruct the activity, and report findings with their limits. The investigation describes what the records show. Decisions about notification, recovery of funds, employment action, or legal steps remain with the organization and its advisers.

Audit and Retention Settings to Check Before You Need Them

Much of what a forensic investigation can establish is decided long before an incident, by how the tenant was configured. Before something goes wrong, confirm that Microsoft Purview audit logging is turned on, that mailbox auditing is active, what audit and sign-in retention your licences provide, and whether retention policies or holds apply to mail and files. In Google Workspace, check the edition's audit and investigation features and whether Vault retention is configured.

These settings cost little to review and can make the difference between a documented answer and an evidence gap. Reviewing them is part of the tenant administration we carry out for clients on our Microsoft 365 managed services, and the same review is the starting point when an incident has already occurred.

Do You Need Digital Forensics, or Is Containment Enough?

Not every security event needs a forensic investigation. A single phishing email that nobody acted on, or a password reset after a blocked sign-in attempt, is usually handled by containment and a short review. A documented investigation earns its cost when someone needs a factual answer about what happened: money was paid to the wrong account, client or patient information may have been exposed, customers received fraudulent messages from a real mailbox, a cyber insurer or lawyer has asked for a timeline, or management needs to know what a departing employee took.

If you are unsure which side of that line you are on, preserve first and decide afterwards. Keeping the mailbox, the messages and a record of every change costs very little, and it keeps the option of an investigation open. Deleting the account or rebuilding the laptop closes it permanently.

How a Digital Forensics Engagement Is Priced

Digital forensics is security work and is billed by the hour. The effort depends on the number of accounts involved, the length of the date range, which evidence sources are available and how many questions the investigation has to answer, so the scope is agreed in writing before analysis begins and revisited only with your approval if the evidence points somewhere new.

A narrowly scoped question, such as whether one mailbox had a forwarding rule added and when, takes far less time than reconstructing several months of activity across a tenant. Telling us early what decision the report needs to support, such as an insurance claim, a conversation with a client or an employment matter, helps keep the scope to the evidence that actually answers it.

Breach Notification Decisions: Where the Forensic Report Fits

Organizations subject to PIPEDA must report a breach of security safeguards involving personal information to the Office of the Privacy Commissioner of Canada and notify affected individuals when it creates a real risk of significant harm, and must keep a record of every such breach. Health information custodians in Ontario have their own notification duties under PHIPA. Whether those duties apply depends on facts, such as which records were accessed and by whom, that are often unknown in the first days after an incident.

A forensic report does not make that decision. It supplies the facts: which accounts and data the evidence shows were involved, over what period, and what the records cannot establish. The notification decision stays with the organization and its legal advisers, who can make it on documented evidence instead of assumptions.

After the Investigation: Closing the Gaps the Evidence Found

Most investigations end with a short list of causes that can be fixed: an account without multi-factor authentication, legacy sign-in methods still enabled, an application granted mailbox access nobody remembers approving, forwarding to outside addresses allowed by default, or audit retention too short to answer the next question. The report lists those findings so they can be closed in order of risk.

Closing them is ordinary security work rather than forensics. For organizations that want it handled on an ongoing basis, our managed security services cover the controls and monitoring, and Microsoft 365 managed services cover the tenant configuration. If an incident is still active, the cyber incident response line is available 24/7.

Digital Forensics Across the GTA and Ontario

IT Rapid Support is based at 7810 Keele Street in Vaughan and provides digital forensic services across the Greater Toronto Area and Ontario. The site's established service footprint includes Vaughan, Toronto, Mississauga, Brampton, Oakville, Markham, Richmond Hill, Burlington, and Hamilton.

Microsoft 365 and Google Workspace evidence collection is usually remote because the evidence sits in the cloud tenant, but an incident may also require endpoint triage or on-site coordination. The initial scope identifies the relevant accounts, devices, dates, administrators, legal or insurance contacts, and any action that could alter evidence before collection begins.

Digital Forensics FAQs

What is cloud digital forensics?

Cloud digital forensics is the documented collection and analysis of audit, identity, email, configuration, and file-activity records from services such as Microsoft 365 and Google Workspace. It reconstructs a timeline from the evidence the tenant retained and states both what the records establish and where retention, licensing, or logging leaves a gap.

What can Microsoft 365 digital forensics show?

Depending on licensing, logging, and retention, Microsoft 365 evidence can show sign-ins, administrator changes, mailbox operations, message flow, inbox rules, forwarding, delegation, file access, sharing, and other activity recorded in Microsoft Purview, Exchange Online, Entra ID, SharePoint, and OneDrive. The first step is to confirm which sources and date ranges are actually available.

Can you investigate a compromised Microsoft 365 mailbox or business email compromise?

Yes. The investigation can correlate Entra ID sign-ins, Microsoft Purview audit activity, Exchange message trace, mailbox audit records, inbox rules, forwarding, delegation, and relevant messages to establish the affected period, attacker actions, and response steps supported by the available evidence.

Do you provide Google Workspace and Gmail forensics?

Yes. Google Workspace work can include administrator and login audit logs, Gmail log search, Google Vault data where available, OAuth grants and third-party application access, and Google Drive sharing and access activity. Available history varies by Workspace edition and retention.

Can digital forensics help with a departing employee or suspected data theft?

Yes. Where the platform retained the evidence, an investigation can examine sign-ins, mailbox and file activity, forwarding, external sharing, downloads, deletions, OAuth access, and administrative changes around the employee's departure. Findings are limited to what the tenant and preserved devices actually recorded.

Can deleted Microsoft 365 or Google Workspace email be recovered?

Sometimes, but not always. Recovery depends on the platform, deletion method, retention settings, holds, backups, licensing, and how much time has passed. Even when message content is no longer recoverable, message trace, audit, sign-in, rule, forwarding, or other records may still document part of the activity. The source-and-retention check determines what is actually available before any recovery claim is made.

How quickly should cloud evidence be preserved after an incident?

As soon as practical. Cloud logs, message traces, deleted items, and other records have different retention windows, and containment changes can alter the evidence. Preserve the relevant tenant, account, date range, and known indicators early, while coordinating any urgent containment with the people responsible for the investigation, cyber insurance, and legal response.

How long does a digital forensic investigation take?

There is no honest standard duration. Timing depends on the number of tenants, accounts, devices or data sources in scope, the date range, export availability, evidence volume, and whether new findings expand the investigation. A focused mailbox investigation can be narrower than a multi-user insider or ransomware matter; the initial source-and-retention review is used to define the scope before analysis proceeds.

What is the difference between digital forensics and incident response?

Incident response contains the threat, removes unauthorized access, restores systems, and reduces continuing harm. Digital forensics preserves and analyzes the available evidence to reconstruct what happened, test the scope, and document findings and limitations. They often run together because containment is urgent but can also change evidence.

Is digital forensics the same as eDiscovery?

No. eDiscovery collects and searches information for a legal matter under counsel's scope. Digital forensics usually reconstructs an event or tests an incident hypothesis. The same tools or exports, including Purview eDiscovery, content search, Google Vault, or native platform exports, can support both, but counsel controls legal strategy, privilege, responsiveness, and legal conclusions.

How do you preserve chain of custody for cloud evidence?

Collection notes identify the source, method, time, account, and handler. Native exports are preserved where practical, evidence files are hashed where applicable, and transfers or handling are recorded. The final evidence inventory links collected items to the findings that rely on them.

Is the forensic report suitable for a cyber insurer or lawyer?

The report is written as a factual technical record with scope, methodology, evidence inventory, timeline, findings, limitations, containment actions, and next steps. It can be shared with insurers and counsel, while legal opinions and privilege decisions remain with the organization's lawyer.

What should we do first if we think a Microsoft 365 mailbox has been compromised?

Keep the evidence and contain the access at the same time. Do not delete the mailbox, the user, or the suspicious messages. Record what was noticed and when, then reset the password, revoke active sessions, and check for new inbox rules or forwarding, noting the time of each change. Contact your insurer if you have cyber coverage, and arrange preservation of the audit and sign-in records before they age out.

Should we delete the compromised account or wipe the affected laptop?

Not before the evidence has been preserved. Deleting an account, mailbox, or device image can remove records that show how access was gained and what was done. Accounts can usually be disabled or have their sign-ins blocked instead, and a device can be isolated from the network while it is kept for examination.

What access do you need to investigate our Microsoft 365 or Google Workspace tenant?

Usually a dedicated administrator or audit-reader account granted by your organization for the investigation, with the permissions needed to search audit logs, sign-in records, message trace, and mailbox configuration. The account used, the permissions granted, and the dates of access are recorded in the collection notes, and access is removed when the work ends.

How much does a digital forensics investigation cost?

Digital forensics is billed by the hour. The total depends on how many accounts are involved, the date range, which evidence sources are available and what questions the report must answer, so the scope is agreed in writing before analysis begins.

We have already reset the password. Is a forensic investigation still useful?

Usually, yes. A password reset is containment, and it does not remove the audit, sign-in and mailbox records an investigation relies on. What matters is that the mailbox and messages were not deleted and that the time of each change is written down, so the investigation can separate attacker activity from your own response.

Does a forensic report decide whether we have to report a privacy breach?

No. The report sets out which accounts and data the evidence shows were involved, over what period, and what the records cannot establish. Whether a notification duty under PIPEDA or PHIPA applies is a decision for your organization and its legal advisers, made on those documented facts.

Where does IT Rapid Support provide digital forensic services?

IT Rapid Support provides Microsoft 365, Exchange Online, and Google Workspace digital forensic services across the Greater Toronto Area and Ontario, including Vaughan, Toronto, Mississauga, Brampton, Oakville, Markham, Richmond Hill, Burlington, and Hamilton.

Compliance-Aware IT

Built with Compliance in Mind

We help GTA businesses work toward the privacy regulations, security frameworks, and insurer requirements that apply to them:

PIPEDAPHIPAPCI-DSSSOC 2NIST CSFCyber Insurance Requirements
Getting Started

How Onboarding Works

A structured, documented onboarding so nothing about your environment lives in one person's head.

1

Assess

We review your current environment: systems, security posture, pain points, and risks.

2

Plan

You get a clear onboarding plan and roadmap — what changes, when, and why.

3

Onboard

We document everything, deploy monitoring and security tooling, and introduce your team to the helpdesk.

4

Operate

24/7 support and proactive management, with regular reviews so IT keeps pace with your business.

No Surprises

Transparent, Predictable Pricing

Managed IT should be a predictable monthly cost tied to outcomes — not surprise invoices. See how managed IT is priced across the industry and what to look for in a quote.

Read Our Pricing Guide

Ready to talk about a digital forensic investigation?

Tell us what happened, which cloud platform is involved, and when the suspected activity began. We will scope the evidence sources that may still be available and the safest next step.