Common questions
BEC investigation and containment FAQ
Can MSPControl help investigate business email compromise?
Yes, for the supported Microsoft 365 account-investigation path. The user-log workflow collects available sign-ins, audit activity and associated mailbox rules and attempts to attach separate Excel reports to a ConnectWise ticket. Review source availability and errors before drawing conclusions. BEC involving impersonation alone may not involve a compromised account to contain.
Can VirtuBot automatically contain a compromised user?
VirtuBot has configurable controls for disabling the user, revoking sign-in sessions and resetting the password, with separate test modes and evidence/confidence thresholds. Availability depends on the deployed workflow and configuration. Verify each action and the resulting Microsoft state; this is not a promise of universal or immediate containment.
Does the evidence collection provide a complete forensic archive?
No. The collector requests a seven-day lookback for sign-ins and audit activity, can reuse shared data for up to 15 minutes, and depends on available source data. Ticket attachments are not a claim of immutable storage, legal preservation, complete retention or chain of custody.
Does an empty report mean the account is safe?
No. Missing permissions, unavailable sources or collection errors can produce empty results. Check the task error, source availability, timestamps and expected attachments. A completed task is not the same as complete evidence or a successful security outcome.
Does containment also remove every persistence mechanism?
No. The disable-user method in this path selects account disabling. Mailbox rules, forwarding, authentication methods, application consent, devices and application-owned sessions need the appropriate separate review and action. Use the linked response checklist and Microsoft guidance.
Is this a fully autonomous BEC investigation and recovery service?
No. This page describes supported evidence collection and configurable containment capabilities, not an end-to-end autonomous service. Human review, incident ownership, outcome verification and remaining recovery work are still required. No measured customer result or response-time guarantee is presented.