Cybersecurity Services

Digital Forensics for Microsoft 365 & Google Workspace

Find out what happened in a Microsoft 365, Exchange Online, or Google Workspace incident while the available evidence is still within reach. IT Rapid Support collects and analyzes cloud audit, identity, email, and file-access evidence for businesses across the Greater Toronto Area and Ontario, then documents the timeline, scope, findings, limitations, and recommended response actions.

Digital Forensics Done Right

Platform-specific collection, disciplined evidence handling, and findings that decision-makers can understand.

Microsoft 365 & Exchange Online

Analyze the Microsoft Purview unified audit log, mailbox auditing, Exchange message trace, inbox rules, forwarding, delegation, eDiscovery sources, and Entra ID sign-in evidence to reconstruct activity and determine affected accounts.

Google Workspace

Review Google Workspace Admin audit logs, Gmail log search, Vault data where available, OAuth grants and third-party application access, and Google Drive sharing and access activity.

Evidence & Findings

Preserve collected evidence with source notes, timestamps, hash manifests where applicable, and a documented chain of custody, then deliver a factual report suitable to share with counsel, insurers, and incident stakeholders.

What We Cover

Everything Your Digital Forensics Needs

The capabilities we manage end to end so this runs reliably for your business.

Microsoft 365 audit logsExchange mailbox forensicsEntra ID sign-in analysisGoogle Workspace audit logsGmail and Drive activityEvidence preservation and reporting

What Is Cloud Digital Forensics?

Cloud digital forensics is the documented collection and analysis of audit, identity, email, and file-activity records from a cloud service after a suspected incident. For a Microsoft 365 or Google Workspace tenant, the goal is to reconstruct a timeline from the records the platform actually retained: who signed in, which settings changed, how messages moved, what files were accessed or shared, and which accounts or applications were involved. It is different from routine administration because the collection method, source, time, handler, and limitations are recorded so another decision-maker can understand what supports each finding. It is also different from a promise to recover everything. Licensing, retention, configuration, elapsed time, and actions taken after the event determine what evidence still exists, so a defensible investigation states both what the records establish and what they cannot establish.

IT Rapid Support focuses this service on Microsoft 365, Exchange Online, and Google Workspace evidence for business incidents. The result is a factual technical chronology for management, cyber insurers, and counsel—not a legal conclusion and not a guarantee that every deleted item or historical action can be recovered.

Microsoft 365 and Exchange Online Forensics

Microsoft 365 investigations start with the evidence sources that answer different parts of the event. Microsoft Purview audit records can include user and administrator operations across supported services. Exchange mailbox auditing can show events such as message access, SendAs or SendOnBehalf activity, and inbox-rule changes when those records are available. Exchange message trace follows mail flow within its retention window. Current and historical inbox rules, forwarding settings, mailbox delegation, transport configuration, and Purview content or eDiscovery searches help explain how a compromised account was used and what information may have been exposed.

Identity evidence matters just as much as mailbox evidence. We review the Entra ID sign-in and directory activity available to the tenant, including interactive and non-interactive sign-ins, source addresses, client applications, authentication results, and administrative changes. SharePoint and OneDrive audit events can add file access, download, deletion, sharing, and permission activity. The objective is a defensible timeline: how the account was accessed, what changed, which messages or files were involved, what the available records can establish, and where retention or licensing creates an evidence gap.

Google Workspace and Gmail Forensics

Google Workspace investigations use the Admin console audit and investigation data available to the organization. That can include administrator activity, login events, Gmail log search, Google Vault preservation and search, OAuth token and third-party application access, and Google Drive sharing or file-access activity. We correlate those sources instead of treating any single log as the whole story.

A Google Workspace review can identify suspicious logins, unauthorized mailbox or forwarding changes, risky OAuth grants, access by third-party applications, and unusual sharing or downloads. Availability depends on the organization's Workspace edition, audit settings, retention, and how quickly evidence is preserved, so scope begins with a source-and-retention check rather than a promise that every historical action can be recovered.

How a Cloud Forensic Investigation Works

First, scope and preserve. We identify the affected tenant, accounts, administrators, date range, known indicators, available licences, retention settings, and any legal or insurance instructions. Actions that could alter evidence are coordinated with containment rather than performed casually.

Second, collect and inventory. Relevant native exports and reports are gathered where practical, with source, method, time, account, filename or object, and handler recorded. Hashes are calculated for evidence files where that method applies, and custody transfers are logged.

Third, correlate and test. Sign-ins, mailbox events, message trace, rules, forwarding, delegation, OAuth access, and file activity are placed on one normalized timeline. A single IP address or log event is not treated as proof of a person; findings are tested against the other available sources.

Fourth, report and hand off. The report separates verified findings, interpretation, and unknowns, identifies affected identities or data supported by the evidence, records limitations, and lists containment or follow-up actions for the incident team, insurer, management, or counsel.

Business Email Compromise Investigation

Business email compromise is the most common reason to start: a mailbox sends fraudulent payment instructions, a hidden inbox rule diverts replies, or an attacker maintains access through forwarding, delegated permissions, or an OAuth application. We connect mail flow, mailbox activity, sign-ins, and configuration changes to determine the affected period and accounts, then tie the findings into containment and recovery through our cyber incident response service.

The questions are concrete: when did suspicious access begin, which authentication and client patterns were recorded, which rules or forwarding paths changed, which messages were sent or accessed, whether delegation or an application created another access path, and what evidence supports the end of the affected period. The investigation does not replace containment; it gives the response team a documented scope instead of relying on the first visible symptom.

Insider Data Theft, Departing Employees, and Ransomware Scoping

A departing-employee or suspected insider investigation asks what the available tenant records show before and after the relevant date: sign-ins, mailbox forwarding, external sharing, downloads, deletions, OAuth access, and administrative or permission changes. The records can establish activity tied to an account or application; they do not automatically establish who was physically at a keyboard or why an action occurred. That distinction belongs in the findings.

Ransomware scoping uses the same discipline when cloud identities or repositories may be involved. Entra ID or Google login activity, Microsoft 365 or Workspace audit events, mailbox changes, and file-access records can help establish which cloud accounts and data sources need attention. Endpoint containment, system recovery, and threat eradication remain part of incident response, while the forensic work preserves and reconstructs the evidence needed to understand the event.

Evidence Preservation, Chain of Custody, and Reporting

Collection is documented from the start: the tenant and source system, query or export method, date and time, account used, original filename or object, and the person handling it. Exports are retained in their native form where practical, and hashes are recorded for evidence files where that method applies. A chain-of-custody record documents who received or handled the material and why.

The report separates verified findings from interpretations and unknowns. It sets out the scope, evidence inventory, methods, timeline, affected identities or data, containment actions, limitations, and next steps. That format gives management a usable decision record and can be shared with cyber insurers, breach counsel, or litigation counsel without presenting legal conclusions that belong to counsel.

Digital Forensics vs Incident Response and eDiscovery

Digital forensics, incident response, and eDiscovery can touch the same tenant but answer different questions. Incident response is operational: contain the threat, remove access, restore systems, and reduce continuing harm. Digital forensics is evidentiary: preserve the available records, reconstruct what happened, test the scope, and document the support and limitations for each finding. The two streams often run together because a containment action can change evidence.

eDiscovery is collection and search for a legal matter under counsel's scope. A forensic investigation may use Purview eDiscovery, content search, Google Vault, or native exports as collection sources, but the forensic question is usually a chronology or incident hypothesis rather than legal responsiveness. IT Rapid Support can support documented collection and factual technical reporting; counsel controls legal strategy, privilege, responsiveness, and legal conclusions.

Managed security is the preventive and monitoring layer before an incident. Our managed security services reduce risk and watch for suspicious activity; this digital forensics service examines the retained evidence when the organization needs to establish what already happened.

What Evidence Limitations Mean in a Forensic Report

Cloud evidence is bounded by the tenant that produced it. Licence level, audit configuration, retention, the incident date, administrator actions, application behaviour, and any delay before preservation all affect what remains. A log can show that an account or application performed an action; it may not prove the identity or intent of the person behind it. An empty search can mean no recorded event, but it can also mean the event was outside retention or never logged by that source.

That is why the initial source-and-retention check matters. The final report identifies the systems and date ranges searched, the evidence found, the evidence expected but unavailable, time-zone handling, and any assumption needed to interpret the chronology. Unknowns are not filled with speculation. They are listed so management, the insurer, incident responders, and counsel can make decisions with the same boundary around the facts.

Digital Forensics Across the GTA and Ontario

IT Rapid Support is based at 7810 Keele Street in Vaughan and provides digital forensic services across the Greater Toronto Area and Ontario. The site's established service footprint includes Vaughan, Toronto, Mississauga, Brampton, Oakville, Markham, Richmond Hill, Burlington, and Hamilton.

Microsoft 365 and Google Workspace evidence collection is usually remote because the evidence sits in the cloud tenant, but an incident may also require endpoint triage or on-site coordination. The initial scope identifies the relevant accounts, devices, dates, administrators, legal or insurance contacts, and any action that could alter evidence before collection begins.

Digital Forensics FAQs

What is cloud digital forensics?

Cloud digital forensics is the documented collection and analysis of audit, identity, email, configuration, and file-activity records from services such as Microsoft 365 and Google Workspace. It reconstructs a timeline from the evidence the tenant retained and states both what the records establish and where retention, licensing, or logging leaves a gap.

What can Microsoft 365 digital forensics show?

Depending on licensing, logging, and retention, Microsoft 365 evidence can show sign-ins, administrator changes, mailbox operations, message flow, inbox rules, forwarding, delegation, file access, sharing, and other activity recorded in Microsoft Purview, Exchange Online, Entra ID, SharePoint, and OneDrive. The first step is to confirm which sources and date ranges are actually available.

Can you investigate a compromised Microsoft 365 mailbox or business email compromise?

Yes. The investigation can correlate Entra ID sign-ins, Microsoft Purview audit activity, Exchange message trace, mailbox audit records, inbox rules, forwarding, delegation, and relevant messages to establish the affected period, attacker actions, and response steps supported by the available evidence.

Do you provide Google Workspace and Gmail forensics?

Yes. Google Workspace work can include administrator and login audit logs, Gmail log search, Google Vault data where available, OAuth grants and third-party application access, and Google Drive sharing and access activity. Available history varies by Workspace edition and retention.

Can digital forensics help with a departing employee or suspected data theft?

Yes. Where the platform retained the evidence, an investigation can examine sign-ins, mailbox and file activity, forwarding, external sharing, downloads, deletions, OAuth access, and administrative changes around the employee's departure. Findings are limited to what the tenant and preserved devices actually recorded.

Can deleted Microsoft 365 or Google Workspace email be recovered?

Sometimes, but not always. Recovery depends on the platform, deletion method, retention settings, holds, backups, licensing, and how much time has passed. Even when message content is no longer recoverable, message trace, audit, sign-in, rule, forwarding, or other records may still document part of the activity. The source-and-retention check determines what is actually available before any recovery claim is made.

How quickly should cloud evidence be preserved after an incident?

As soon as practical. Cloud logs, message traces, deleted items, and other records have different retention windows, and containment changes can alter the evidence. Preserve the relevant tenant, account, date range, and known indicators early, while coordinating any urgent containment with the people responsible for the investigation, cyber insurance, and legal response.

How long does a digital forensic investigation take?

There is no honest standard duration. Timing depends on the number of tenants, accounts, devices or data sources in scope, the date range, export availability, evidence volume, and whether new findings expand the investigation. A focused mailbox investigation can be narrower than a multi-user insider or ransomware matter; the initial source-and-retention review is used to define the scope before analysis proceeds.

What is the difference between digital forensics and incident response?

Incident response contains the threat, removes unauthorized access, restores systems, and reduces continuing harm. Digital forensics preserves and analyzes the available evidence to reconstruct what happened, test the scope, and document findings and limitations. They often run together because containment is urgent but can also change evidence.

Is digital forensics the same as eDiscovery?

No. eDiscovery collects and searches information for a legal matter under counsel's scope. Digital forensics usually reconstructs an event or tests an incident hypothesis. The same tools or exports, including Purview eDiscovery, content search, Google Vault, or native platform exports, can support both, but counsel controls legal strategy, privilege, responsiveness, and legal conclusions.

How do you preserve chain of custody for cloud evidence?

Collection notes identify the source, method, time, account, and handler. Native exports are preserved where practical, evidence files are hashed where applicable, and transfers or handling are recorded. The final evidence inventory links collected items to the findings that rely on them.

Is the forensic report suitable for a cyber insurer or lawyer?

The report is written as a factual technical record with scope, methodology, evidence inventory, timeline, findings, limitations, containment actions, and next steps. It can be shared with insurers and counsel, while legal opinions and privilege decisions remain with the organization's lawyer.

Where does IT Rapid Support provide digital forensic services?

IT Rapid Support provides Microsoft 365, Exchange Online, and Google Workspace digital forensic services across the Greater Toronto Area and Ontario, including Vaughan, Toronto, Mississauga, Brampton, Oakville, Markham, Richmond Hill, Burlington, and Hamilton.

Compliance-Aware IT

Built with Compliance in Mind

We help GTA businesses work toward the privacy regulations, security frameworks, and insurer requirements that apply to them:

PIPEDAPHIPAPCI-DSSSOC 2NIST CSFCyber Insurance Requirements
Getting Started

How Onboarding Works

A structured, documented onboarding so nothing about your environment lives in one person's head.

1

Assess

We review your current environment: systems, security posture, pain points, and risks.

2

Plan

You get a clear onboarding plan and roadmap — what changes, when, and why.

3

Onboard

We document everything, deploy monitoring and security tooling, and introduce your team to the helpdesk.

4

Operate

24/7 support and proactive management, with regular reviews so IT keeps pace with your business.

No Surprises

Transparent, Predictable Pricing

Managed IT should be a predictable monthly cost tied to outcomes — not surprise invoices. See how managed IT is priced across the industry and what to look for in a quote.

Read Our Pricing Guide

Ready to talk about a digital forensic investigation?

Tell us what happened, which cloud platform is involved, and when the suspected activity began. We will scope the evidence sources that may still be available and the safest next step.

We value your privacy

This website uses cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies. Read our Cookie Policy and Privacy Policy.