TL;DR: Visibility into Azure Files activity, high-risk Exchange Online mailbox actions, Microsoft Copilot activity, and Azure SQL is added through new add-ons, with a live demo showing how faster filtering and cancellation can speed response and investigation, according to Netwrix. The governance question is not whether visibility improves, but whether identity teams can turn that telemetry into timely control decisions before risky changes become incidents.
At a glance
What this is: This on-demand webinar covers Netwrix Auditor 10.8 and its new visibility features for Azure Files, Exchange Online, Microsoft Copilot and Azure SQL, with a focus on faster investigation and response.
Why it matters: It matters because IAM and security teams need telemetry that surfaces risky identity-linked activity quickly enough to support containment, audit review and governance decisions.
Context
Visibility gaps in identity-adjacent activity become operational problems when teams cannot see risky changes soon enough to act. In cloud and SaaS environments, the challenge is not simply collecting more logs but making relevant activity searchable, attributable and usable for response.
This webinar is about Netwrix Auditor 10.8 and the kinds of events identity and security teams most often need to inspect: Azure Files activity, Exchange Online mailbox changes, Microsoft Copilot usage and Azure SQL actions. The governance question is whether those signals arrive in time to influence access decisions, incident triage and compliance review.
For IAM and security operations, the practical problem is not feature coverage alone. The question is whether the visibility layer reduces the time between a risky action and a defensible control response.
Key questions
Q: How can teams tell whether observability is improving identity governance?
A: Teams can tell observability is improving governance when it changes decisions, not just dashboards. Look for fewer unknown access paths, faster investigation of anomalous identity actions, and better prioritisation of recertification and privilege cleanup. If visibility does not change remediation, it is only producing more telemetry.
Q: Why do mailbox rule changes and mass deletions matter for IAM teams?
A: Because they often signal that a user or delegated identity is changing how information is hidden, retained or removed. Those events can reveal misuse, concealment or an early compromise path. IAM teams should treat them as governance-relevant actions, not just application activity, because they can change the security outcome of an account or session.
Q: What are the signs that visibility tooling is actually helping investigations?
A: Analysts can move from alert to explanation faster, relevant events are searchable across services, and filtering does not force them to wade through unrelated noise. If the team still struggles to connect cloud file activity, mailbox actions and database events into one timeline, the monitoring layer is incomplete.
Q: What should security teams do when AI-assisted activity falls outside the monitoring model?
A: Bring AI-assisted actions into the same audit and response workflow as other identity-linked events. If Copilot usage can influence access, content handling or data queries, it belongs in the investigation path. Otherwise teams will keep a blind spot exactly where new operational behaviour is emerging.
Background and context
How visibility gaps appear across cloud and SaaS activity
Identity telemetry breaks down when key administrative and data-access events sit across separate services, consoles or audit trails. Azure Files, Exchange Online, Microsoft Copilot and Azure SQL each generate different activity records, which means investigators can miss the sequence of a change if they rely on one log source or one query pattern. Searchability matters because investigations are usually time-bound and context-sensitive, not just retrospective compliance exercises. Enhanced filtering and cancellation are operational features, but the real mechanism is whether the audit layer makes relevant events retrievable before the trail goes cold.
Practical implication: build investigation workflows around correlated audit sources, not isolated service logs.
Why mailbox actions and file activity are high-risk identity signals
Mailbox rule changes and mass deletions are not merely user actions, they are control-relevant identity events because they can indicate concealment, data removal or delegated misuse. The same is true for file activity in Azure Files when changes affect access paths, exposure or integrity. In identity governance terms, these events matter because they often sit at the intersection of entitlement, delegation and data movement. A tool that flags them only after the fact is useful for forensics, but a platform that makes them visible early can support containment before a routine action becomes an incident.
Practical implication: prioritise alerting on changes that alter access paths, retention behaviour or data exposure.
What Copilot and Azure SQL monitoring adds to the governance picture
Monitoring Microsoft Copilot and Azure SQL extends visibility into newer layers of user and workload activity. That matters because identity teams increasingly need to understand not only who acted, but which services, assistants or data platforms were touched during the session. This is less about novelty than about governance completeness: when AI-assisted usage and database activity are absent from the monitoring model, teams lose the ability to explain how data was accessed, transformed or queried. The control value comes from making these activities inspectable within the same response and audit workflow as the rest of the environment.
Practical implication: extend identity monitoring to AI-assisted and database activity so investigations do not stop at the user session boundary.
NHI Mgmt Group analysis
Visibility is now a control problem, not a reporting problem. Netwrix is pointing at a familiar but still under-solved gap: teams often have logs, yet they do not have operational visibility into the actions that matter most for identity governance. When file activity, mailbox changes, AI-assisted usage and database events live in separate audit views, the security team inherits delay instead of decision support. The practitioner conclusion is simple: visibility only has value when it shortens the time to action.
Identity telemetry must cover the places where governance assumptions break. Azure Files, Exchange Online, Microsoft Copilot and Azure SQL represent different kinds of control surface, but the common issue is whether a risky change is visible early enough to be attributable. That is where identity programmes either stay administrative or become operational. Teams should treat visibility gaps as governance gaps because the absence of a searchable event trail is often the difference between response and explanation.
Event coverage without investigation speed still leaves exposure on the table. Faster filtering and cancellation matter because security teams do not fail only on missed events, they also fail on slow event handling. The market is moving toward telemetry that supports triage, not just retention. The practitioner takeaway is to measure whether monitoring reduces mean time to understand, not merely whether it stores more records.
Named concept: visibility-to-decision latency. The most important metric in this kind of capability is not raw log volume but the elapsed time between a risky action and a defensible response. If teams cannot turn new activity into a control decision quickly, the added visibility remains a reporting layer rather than a security control. The practical conclusion is to evaluate every visibility investment by how much decision latency it removes.
Identity programmes need a broader monitoring boundary. Microsoft Copilot and Azure SQL show why identity governance can no longer stop at human login events or classic admin actions. As assistants and data platforms become part of the same operational path, the monitoring model has to follow the activity chain across services. The practitioner conclusion is to align audit scope with the full path of access, not with legacy assumptions about where identity ends.
From our research library:
- Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
- Read next: Identity Security Posture Management (ISPM) Guide
What this signals
Visibility-to-decision latency: the operational test is not whether a platform collects more events, but whether analysts can turn those events into a defensible control action before the window of exposure closes. If investigation still depends on manual correlation across Azure Files, Exchange Online, AI-assisted usage and SQL activity, the monitoring layer has not yet become a governance control.
Identity teams should expect monitoring scope to keep expanding across cloud services, assistants and databases because identity behaviour no longer ends at login or mailbox administration. The programme question is whether the audit model follows the full access path, or leaves newer activity outside the decision loop.
For practitioners
- Expand audit scope beyond core admin logs Include Azure Files, Exchange Online, Microsoft Copilot and Azure SQL activity in the identity monitoring baseline so investigations do not depend on a single service view.
- Prioritise risky mailbox and file events Treat mass deletions and inbox rule changes as high-priority signals because they can indicate concealment, delegated misuse or data removal.
- Measure investigation latency Track how long it takes analysts to move from event detection to a defensible decision, and use that metric to test whether visibility improvements are operationally real.
- Extend monitoring to AI-assisted activity Add Microsoft Copilot usage to the same review path as user and workload activity so AI-assisted actions do not sit outside governance workflows.
Key takeaways
- The core issue is not a lack of telemetry, but the gap between collecting identity-linked events and using them quickly enough to change a security outcome.
- Netwrix highlights visibility into Azure Files, Exchange Online, Microsoft Copilot and Azure SQL, which reflects how broad the modern monitoring boundary has become.
- Teams should judge visibility investments by whether they shorten investigation and response cycles, not by how many additional event sources they can store.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP API Security Top 10 addresses the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and CSA Cloud Controls Matrix set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | DE.CM-01 — Networks and systems monitored to detect potential cybersecurity events | The article centers on monitoring cloud and SaaS activity for risky changes. |
| PR.AA-05 — Access Permissions, Entitlements and Authorizations | Mailbox and file actions reflect changes in entitlements and delegated access. | |
| Recommendation — Map cloud and SaaS audit coverage to DE.CM-01 so risky changes are detectable in time. Review access-related events against PR.AA-05 to catch permission changes that alter exposure. | ||
| CIS Controls v8 | CIS-5 — Account Management | The article focuses on identity-linked activity that account governance must surface. |
| Recommendation — Use CIS-5 to monitor account activity that changes access, retention or data exposure. | ||
| OWASP API Security Top 10 | API9 — Improper Inventory Management | The monitoring problem includes incomplete coverage of new activity surfaces and services. |
| Recommendation — Inventory monitored services and activity sources so new telemetry surfaces are not missed. | ||
| CSA Cloud Controls Matrix | SEF — Security Incident Event Management | The webinar is fundamentally about event visibility and investigation workflows in cloud services. |
| Recommendation — Align event monitoring and investigation workflows to SEF so cloud activity is actionable. | ||
Key terms
- Visibility-to-decision latency: The time between a security-relevant event being generated and a team being able to make a defensible control decision from it. In identity programmes, short latency matters more than raw log volume because visibility only helps when it can change containment, investigation or access outcomes.
- Identity Telemetry: Identity telemetry is the collection of signals generated by authentication, session, and access events across human and non-human identities. It becomes useful for governance when teams can baseline normal behavior and detect drift in source, privilege, or access frequency.
- Audit coverage boundary: The set of systems, services and actions included in monitoring and review. When that boundary stops at legacy admin events and excludes assistants, databases or file services, governance gaps appear even if the organisation believes it has full visibility.
- Governance-relevant activity: An event that can change access, exposure, retention or accountability, even when it looks like routine system use. Identity teams should classify such activity separately because the same action can be operationally normal and security-relevant at the same time.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org