Microsoft 365 access and recovery record Dyasol ยท 2026-09-13 Working template. Adapt to the agreed scope. Store evidence references, not credentials. 1. Incident lead / trusted communication channel: 2. Account, tenant, affected resources and discovery time: 3. Known facts / working hypotheses / unavailable evidence: 4. Containment action / authorisation / time / result: 5. Authentication-method, mailbox and application-permission findings: 6. Resource checked / expected behaviour / observed result / evidence reference: 7. Restoration approver / remaining exceptions / next review: https://dyasol.com/microsoft-365-compromised-account