The departing employee: tracing exfiltration through Purview, OneDrive and Teams.
A composite scenario drawn from the pattern we see most often in corporate instructions, details altered, the method real.
Method
- 01Preserve first. A litigation hold was placed on the director's mailbox, OneDrive and Teams data through Purview before anything was examined, and before his account reached the offboarding queue that would have wiped it.
- 02Pull the audit trail. The tenant's unified audit log was exported for the director's final ninety days. It showed a pattern invisible to colleagues: bulk file access in SharePoint areas outside his role, a spike of OneDrive sync activity to a device ID never seen before, and mass download events on two consecutive Sunday evenings.
- 03Tie cloud to keyboard. The unknown device ID resolved to a personal laptop. Sign-in logs put it on his home IP address at the times of the downloads. On the company laptop he returned, OneDrive sync artefacts and USB connection records corroborated the same file set moving twice.
- 04Read the conversations. Preserved Teams messages showed the director asking a junior colleague, still employed, to "grab the Q3 renewals sheet" a week after his own access was curtailed, widening the matter from one leaver to an ongoing leak.
Outcome
The findings were reported with a full custody record and exhibit set: audit-log extracts, sign-in correlations, device artefacts and message threads on a single timeline. The company's solicitors used the report to obtain undertakings and delivery-up without a contested hearing, the evidence was specific enough that the former director's advisers did not dispute it.
Lesson
Audit logs on standard Microsoft 365 licences are retained for a limited window. Had the company waited two more months to seek advice, the Sunday-evening downloads would have aged out of the log, and the case would have rested on inference instead of records. Preserve before you investigate, and investigate before the logs expire.