Testimony practice

Microsoft 365 Expert Witness

Correlate Microsoft 365 email, identity, file and application records to explain disputed activity, shared-data access and evidence limitations.

Bagged hard drive beside a forensic write blocker.

Explain what happened across Microsoft 365

A compromised mailbox may be only one part of a wider event. GDF examines available identity, email, application and file records to assess the activity at issue and the resources an account or application could reach.

A dispute may begin with an email but turn on a shared document or account permission. The examination therefore starts with the tenant, accounts, services and dates relevant to counsel’s questions. We distinguish the material supplied for review from records that may still need to be preserved or obtained.

Correlate the relevant services

Depending on scope and availability, the examination can involve Exchange Online, Entra ID, SharePoint, OneDrive and Teams records. The work separates permissions from observed actions and distinguishes an authentication event from evidence of content access.

If an employee is alleged to have taken files before leaving, access rights alone do not answer the question. The analysis needs to examine recorded activity, the files involved and possible routine synchronization. A successful sign-in is a useful event, but it does not establish every subsequent action or identify the person behind the session by itself.

Address the contested questions

Which records support the proposed timeline? Does an event establish a download, a share or another action? Could an application identity explain activity attributed to a user? What records were retained, and which questions remain unanswered?

Available records may differ in time format, identifiers and retention. Correlation requires explaining those differences and identifying the accounts, applications and resources involved. Missing events can limit an opinion; they should not be silently treated as proof that nothing happened.

Make the technical basis reviewable

Findings identify the source records, relevant configuration and collection limits. Licensing, retention and audit configuration can affect coverage. The absence of an event is not automatically proof that no access occurred.

Counsel receives an explanation of which events support the proposed sequence and where the sequence depends on inference. Exhibits can separate account access, mailbox activity and document events. The opinion should identify the relevant record and its meaning rather than treating every audit entry as interchangeable evidence of misconduct.

How the engagement runs

  1. Scope

    Discuss the disputed questions, relevant experience, potential conflicts and deadlines.

  2. Examine

    Review the available source records and document the methods used.

  3. Explain

    Prepare findings and exhibits that distinguish observations, opinions and unanswered questions.

Evidence we may examine

  • Available Exchange and Entra ID records
  • SharePoint, OneDrive and Teams activity
  • Application permissions and audit configuration

Work planned with counsel

  • Technical findings with supporting records and limitations
  • Timelines and exhibits suited to the disputed questions
  • Review of opposing technical opinions
  • Reports and testimony within the agreed scope

Common questions

Did the account access shared files as well as email?

We examine available Exchange, SharePoint, OneDrive, Teams and identity records. Access permissions and recorded file activity answer different questions.

Was that action taken by a user or an application?

An application can act with delegated or application permissions. We examine the relevant identity and event records before attributing activity to a person.

What can we establish if some logs are missing?

Retained records may support some conclusions while leaving others unresolved. Missing logs do not establish that no access occurred.

Reconstruct the event across the tenant

A sign-in, a mailbox action and a file download may describe different parts of the same incident. We define the accounts, applications, resources and time period at issue, then compare the records available from each service. The collection plan includes shared resources where relevant, not just the named user’s mailbox.

Microsoft publishes definitions for audit activities. An opinion should use those definitions together with the actual event fields and tenant configuration. A sharing event may establish a permissions change without proving the recipient opened a document. A successful sign-in does not identify every item subsequently accessed.

In an illustrative employee-departure dispute, counsel may ask whether documents were copied before access was revoked. We compare retained identity and file activity, application access and relevant endpoint records. We separate the files the account could reach from the files that records show were accessed or transferred.

Correlate identity, mail and shared-file activity

  1. Identity

    Accounts, applications and sign-in context.

  2. Mail and files

    Exchange, OneDrive, SharePoint and Teams records.

  3. Event sequence

    Compare timestamps, identifiers and resource activity.

  4. Scope opinion

    State observed actions and unresolved exposure.

Each conclusion should identify the records behind it and the limits of what they establish.

Meet the examiners

For microsoft 365 expert witness work, discuss the disputed questions and the experience needed before defining the engagement. Robert Knudsen is profiled in our expert directory. Meet the GDF team and discuss the technology, questions and availability with us. The expert selected for a matter depends on its scope and the required experience.

Talk with an examiner

Discuss Microsoft 365 Evidence

Tell us the systems, evidence and deadline. We can review relevant experience, potential conflicts and the scope before engagement.

Since 1992 · 24/7 dispatch · Court-tested experts

Or call 1-800-868-8189

Email or phone is required. A submission does not create an engagement. For an active incident, please call. Read what we send with the request.

Talk with an examiner

Discuss the matter and the next step.

Tell us what happened and what you need to find out. Speak with a GDF expert about how we can help.

24/7 hotline: 1-800-868-8189

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.