Recon360 is a forensic investigations platform built for Microsoft 365 — designed for the security teams, investigators, and compliance professionals who need to understand what actually happened inside a tenant.

It connects directly to Exchange Online, SharePoint, Microsoft Teams, Entra ID, Microsoft Purview, and Defender XDR. From there it reconstructs timelines, traces actors across audit logs and signals, and produces evidence packages with a chain of custody intact — no agents installed, no data leaving the tenant boundary.

What this site is

This site is a public development log. As Recon360 gets built, updates are posted here: what shipped, what is in progress, what changed, and why. It is not a launch page — it is a running record of building something in the open.

If you work in security, forensics, compliance, or legal operations at an organisation running Microsoft 365 and this sounds like a problem you have run into, register your interest to get updates as the product develops.

Timeline

Recon360 is currently in active development, targeting private preview in Fall 2026.