All Posts

Microsoft 365 Account Compromise: The First-Hour Checklist

25 August, 2026
#Managed IT
#Cybersecurity
#Microsoft 365
#Business Productivity
Microsoft 365 account compromise response and email security checklist for small businesses

Microsoft 365 Account Compromise: The First-Hour Checklist

An employee says they approved an unexpected MFA prompt. A customer received a strange invoice from a real company mailbox. Microsoft 365 shows a sign-in from an unfamiliar location. Messages are disappearing. A new forwarding rule sends email outside the company.

At that point, changing the password feels like the obvious fix.

It is an important step, but it is not a complete Microsoft 365 account-compromise response.

An attacker may already have an active session, a newly registered authentication method, a malicious inbox rule, an external forwarding address, an approved OAuth application, access to Teams, or copies of files from SharePoint and OneDrive. They may also have used the mailbox to contact customers, vendors, payroll, or finance employees.

For a small or midsize business, the first hour matters because a cloud identity is connected to real work. The goal is not only to get the user back into Outlook. The goal is to remove the attacker, understand what they reached, stop fraud, preserve useful evidence, and return the employee to work from a trusted state.

Why This Topic Is Timely

The buyer-relevant keyword cluster behind this post includes Microsoft 365 account compromise response, compromised Microsoft 365 account, Microsoft 365 hacked account, compromised email account checklist, revoke Microsoft 365 sessions, Microsoft 365 mailbox compromise, business email compromise response, MFA token theft, Microsoft Entra incident response, and small business email security.

These are high-intent searches. A business looking for this guidance may already be seeing suspicious activity, reviewing an incident, or questioning whether its IT provider has a repeatable response process.

The threat environment makes that concern reasonable.

Microsoft's July 2026 email threat landscape report said attackers were expanding into Teams-based social engineering and increasingly automated, multi-stage attack chains. In a separate campaign observed in April 2026, Microsoft reported that more than 35,000 users across over 13,000 organizations were targeted with polished compliance-themed phishing. The attack chain used adversary-in-the-middle infrastructure to capture authentication tokens and bypass non-phishing-resistant MFA.

Microsoft also updated its compromised cloud email account guidance in July 2026. The guidance does not stop at a password reset. It calls for disabling the affected account during investigation, revoking sessions, reviewing MFA devices, checking user-consented applications and administrative roles, removing suspicious forwarding, inspecting hidden inbox rules, and reviewing sign-in, audit, and message activity.

That is the practical lesson for SMBs: a compromised Microsoft 365 account is an identity, email, collaboration, and business-process incident—not just a password problem.

Signs a Microsoft 365 Account May Be Compromised

The first warning does not always come from a security alert.

Employees, customers, vendors, or the IT provider may notice:

  • unexpected MFA prompts or authentication-method changes
  • successful sign-ins from unfamiliar locations, devices, applications, or IP addresses
  • missing, moved, or deleted email
  • new inbox rules that hide replies or move messages into RSS, Notes, Junk, Archive, or Deleted Items
  • external forwarding that no one approved
  • suspicious messages in Sent Items or reports that messages were sent but do not appear there
  • a mailbox blocked from sending because of unusual outbound volume
  • a new email signature, contact detail, display name, or phone number
  • password resets or account lockouts the employee did not initiate
  • unfamiliar OAuth applications or connected services
  • unexpected guest invitations, file-sharing links, Teams messages, or OneDrive activity
  • vendors or customers receiving new payment instructions
  • payroll, direct deposit, invoice, gift card, W-2, or bank-change conversations the user does not recognize

One signal may have an innocent explanation. Several signals together should be treated as a potential compromise until the facts show otherwise.

Employees should have a clear Microsoft 365 phishing reporting workflow so a suspicious prompt, message, call, or sign-in reaches someone who can act quickly.

Why a Password Reset Alone Can Fail

A password reset addresses one credential. Modern Microsoft 365 access involves more than one credential.

After a successful sign-in, Microsoft Entra ID and connected applications use access tokens, refresh tokens, browser cookies, and application sessions to keep work moving without asking the employee to sign in for every action. That is useful for productivity. It also means a stolen session can remain valuable to an attacker after the original phishing event.

Microsoft documents that administrators can block new sign-ins and revoke refresh tokens, but access does not always disappear from every application at the same instant. Some applications issue and control their own session cookies. The time to effective revocation depends on the application, token type, synchronization, and whether the application supports controls such as Continuous Access Evaluation.

Attackers can also establish persistence outside the password by:

  • registering a new MFA method or device
  • gaining user consent for a malicious application
  • adding mailbox forwarding
  • creating visible or hidden inbox rules
  • changing recovery or contact information
  • adding delegated mailbox permissions
  • abusing a connected SaaS application
  • creating file-sharing links or downloading data
  • compromising the employee's browser or endpoint

This is why containment must address the identity and its connected services, not only the password.

The First-Hour Microsoft 365 Response

The exact steps depend on licensing, hybrid identity, business impact, and the available security tools. The sequence below is a practical starting point for SMB leadership and IT providers.

1. Move the Conversation to a Trusted Channel

Do not coordinate the response through the mailbox or Teams account that may be compromised.

Contact the employee through a known phone number, in person, or through another trusted method. Confirm what happened without asking the employee to repeat sensitive information in email.

Record:

  • when the suspicious event occurred
  • what the employee clicked, scanned, opened, entered, approved, installed, or shared
  • the device and browser involved
  • whether a password, MFA prompt, device code, passkey setup, QR code, or remote-support session was involved
  • whether financial or sensitive business requests were sent
  • who reported the issue and when IT began containment

If the employee is unsure, treat the wider possibility as in scope until it can be ruled out.

2. Disable or Block the Account During Investigation

Microsoft recommends disabling a compromised account until the investigation is complete. That creates business disruption, but temporary disruption is usually safer than allowing an attacker to keep using the account.

If the identity is synchronized from on-premises Active Directory or uses federation, containment must include the authoritative identity system. A cloud-only password change may not be enough for a hybrid account.

The response team should also determine whether the account has administrative, finance, HR, payroll, executive, shared-mailbox, remote-access, or application-management privileges. Higher privilege increases the likely blast radius and urgency.

Do not send replacement credentials through the affected mailbox.

3. Revoke Active Sessions

Revoke Microsoft Entra sessions and refresh tokens in addition to resetting the password.

This is especially important after:

  • adversary-in-the-middle phishing
  • device code phishing
  • suspicious MFA approval
  • stolen browser cookies or session tokens
  • infostealer malware
  • an unfamiliar OAuth sign-in
  • confirmed access to Outlook, Teams, SharePoint, or OneDrive

Session revocation is a containment control, not proof that every connected application session ended immediately. Review critical SaaS applications and line-of-business systems separately when they issue their own sessions or allow direct credentials.

4. Review Authentication Methods and Devices

An attacker may add a phone number, Authenticator registration, passkey, FIDO2 key, software token, Temporary Access Pass, or device so they can return later.

Review the user's registered authentication methods and devices. Remove anything unrecognized. If trust is uncertain, rebuild the user's authentication methods through the company's verified enrollment process rather than assuming old methods are safe.

Identity verification matters here. A criminal who has access to the mailbox may be able to answer email-based questions or impersonate the employee through Teams. Use the company's known verification process before allowing new MFA enrollment.

This is also a reason to adopt phishing-resistant MFA for administrators and high-risk business roles.

5. Review Applications, Consent, Roles, and Delegation

Check whether the user approved a new application or whether an existing application now has suspicious access to mail, files, contacts, calendars, or other Microsoft 365 data.

Review:

  • user-consented applications
  • enterprise application permissions where relevant
  • OAuth grants and connected SaaS tools
  • Microsoft Entra administrative roles
  • Exchange mailbox delegation and send-as rights
  • SharePoint, OneDrive, and Teams ownership or elevated permissions
  • newly created guests, invitations, or sharing links

A Microsoft 365 app permission review should be part of incident response because revoking sessions does not make a malicious consent grant legitimate.

6. Check Mailbox Rules, Forwarding, and Outbound Messages

Attackers often manipulate a mailbox so they can watch conversations or hide replies.

Review:

  • mailbox-level forwarding
  • all inbox rules, including hidden rules
  • rules that delete, archive, redirect, or move messages
  • automatic replies and signatures
  • delegates and shared-mailbox access
  • Sent Items, Deleted Items, Recoverable Items, and suspicious folders
  • message trace and outbound volume
  • messages sent internally and externally during the suspected compromise window
  • whether the mailbox appears on Microsoft's restricted entities list after sending spam

Do not assume a clean Sent Items folder proves nothing was sent. Use message trace and audit evidence where available.

Our detailed guide to Microsoft 365 mailbox rule abuse explains why hidden forwarding and message-moving rules can survive an incomplete cleanup.

7. Preserve Evidence While Containing the Threat

Containment comes first, but the response should avoid destroying the information needed to understand the incident.

Preserve or document:

  • Entra interactive and non-interactive sign-in logs
  • risk detections and identity alerts
  • Microsoft 365 unified audit events
  • Defender alerts and incidents where licensed
  • message trace results
  • suspicious email, headers, URLs, attachments, and QR codes
  • inbox rules, forwarding, delegates, and consent grants before removal
  • relevant Teams, SharePoint, OneDrive, and application activity
  • endpoint detection alerts and browser history where appropriate
  • a timestamped incident timeline and every containment action

Start the search just before the earliest known suspicious event. If the first clue is a fraudulent email sent Tuesday morning, the attacker may have gained access on Monday or earlier.

Avoid filtering the initial investigation so narrowly that earlier reconnaissance, failed sign-ins, consent activity, or a second affected user is missed.

8. Scope Email, Collaboration, Data, and Endpoint Activity

A Microsoft 365 identity can reach much more than Outlook.

Ask:

  • Which mailboxes and shared mailboxes could the user access?
  • What email was read, searched, deleted, forwarded, or sent?
  • Were customer, vendor, payroll, tax, legal, HR, or financial conversations exposed?
  • Were files downloaded, shared, deleted, synchronized, or moved in SharePoint and OneDrive?
  • Were Teams chats, channels, meetings, calls, or external contacts used?
  • Were new guests, sharing links, applications, or automation connections created?
  • Did the account access password managers, accounting, CRM, payroll, remote support, backup, or other SaaS systems?
  • Was the endpoint infected, remotely controlled, or used to steal browser data?
  • Were other users targeted from the compromised account?

The answer determines whether this is a single-account cleanup, a broader Microsoft 365 incident, a financial fraud event, a privacy issue, or the start of a larger intrusion.

Protect the Business Process, Not Only the Mailbox

Technical containment does not reverse a fraudulent payment or warn a customer who received fake instructions.

If the compromised account could influence money, payroll, contracts, customer data, or vendor relationships, involve the relevant business owner immediately.

Check for:

  • changed vendor bank details
  • payroll or direct-deposit changes
  • fake invoices or payment links
  • wire, ACH, refund, or gift-card requests
  • requests for W-2s, customer lists, AR aging reports, or tax records
  • altered signatures or phone numbers
  • customer or vendor replies hidden by inbox rules
  • confidential documents shared externally

Use known contact details—not details from the suspicious email thread—to verify transactions and warn affected parties. If funds may have moved, contact the financial institution and appropriate authorities quickly. Follow the company's incident response, cyber insurance, legal, regulatory, contractual, and notification requirements based on the facts.

Email can initiate a sensitive request. It should not be the only approval channel for a change involving money, access, or confidential data.

Recover the User From a Trusted State

Do not restore access merely because the password was changed.

Before re-enabling the account, confirm that:

  • the attacker no longer controls a trusted authentication method
  • sessions and tokens were revoked as far as the environment supports
  • suspicious consent grants, roles, delegates, forwarding, and rules were removed
  • the password was reset in the correct authoritative identity system
  • the user's device is trusted or has been investigated and remediated
  • connected business applications were reviewed
  • financial and external communications were addressed
  • monitoring is in place for renewed suspicious activity

Have the employee register approved MFA methods through a verified process. Prefer phishing-resistant options such as passkeys, FIDO2 security keys, or Windows Hello for Business where practical and properly managed.

Expect the user to sign in again across devices and applications. That inconvenience is part of removing stale access. Give the employee clear instructions so they do not mistake legitimate reauthentication for another attack.

Improvements to Make After the Incident

An incident should produce more than a closed ticket.

Use the findings to improve:

  • Conditional Access or Security Defaults coverage
  • phishing-resistant MFA for administrators, finance, HR, executives, and other high-risk roles
  • administrator account separation and least privilege
  • Defender for Office 365, Safe Links, Safe Attachments, impersonation protection, and user reporting where licensed
  • external forwarding restrictions and mailbox-rule monitoring
  • OAuth consent governance and application reviews
  • SharePoint, OneDrive, and Teams external-sharing controls
  • endpoint detection, browser protection, patching, and local administrator restrictions
  • payment, payroll, bank-change, and help-desk verification workflows
  • logging retention and incident-response access
  • contact lists for banks, insurers, legal counsel, customers, vendors, and law enforcement
  • a written account-compromise runbook with named owners

The goal is not to blame the employee. It is to reduce the chance that the same technique works again and to make the next response faster, calmer, and more complete.

Questions Leadership Should Ask the IT Provider

Business owners do not need to operate the Microsoft Defender or Entra portals themselves. They do need clear answers.

Ask:

  • Who can disable an account and revoke sessions after hours?
  • How quickly can we investigate a suspicious Microsoft 365 sign-in?
  • Do we review MFA methods, devices, OAuth apps, roles, forwarding, hidden rules, and delegates?
  • Can we trace messages sent from a compromised mailbox?
  • Can we investigate SharePoint, OneDrive, Teams, and connected SaaS activity?
  • How long are the logs we need retained?
  • What changes when the affected user is an administrator, owner, finance employee, or executive?
  • Who contacts customers, vendors, the bank, cyber insurer, and legal counsel when needed?
  • How do we verify an employee before rebuilding MFA?
  • What evidence shows the account is safe to re-enable?
  • What control improvements are tracked after the incident?

If the response is "we reset the password and watch it," the business has an incident-response gap.

Microsoft 365 Account Compromise Checklist

Use this condensed list as a planning aid:

  • Move communication away from the affected account.
  • Record what happened, when, and on which device.
  • Disable or block the account during investigation.
  • Reset credentials in the authoritative identity system.
  • Revoke Microsoft Entra sessions and refresh tokens.
  • Review and rebuild authentication methods as needed.
  • Remove unrecognized devices, applications, consent grants, roles, and delegates.
  • Check forwarding and visible and hidden inbox rules.
  • Review message trace, sent mail, deleted mail, and outbound activity.
  • Preserve sign-in, audit, email, collaboration, application, and endpoint evidence.
  • Investigate SharePoint, OneDrive, Teams, shared mailboxes, and connected SaaS systems.
  • Check for payment, payroll, invoice, customer, vendor, and data exposure.
  • Notify the right internal and external parties based on verified impact.
  • Remediate the endpoint before trusted access resumes when device compromise is possible.
  • Re-enable the user only after access and persistence paths are addressed.
  • Monitor for recurrence and document control improvements.

This checklist does not replace an incident-specific technical, legal, insurance, or regulatory assessment. It gives the business a better starting point than an improvised password reset.

How CybarWorks Can Help

CybarWorks helps small and midsize businesses prepare for and respond to Microsoft 365 account compromise without losing sight of business operations.

We can review Microsoft 365 identity and email security, strengthen MFA and Conditional Access, tune Defender for Office 365, assess mailbox rules and forwarding, review OAuth applications, improve SharePoint and OneDrive sharing controls, connect endpoint monitoring to cloud investigation, and build a practical account-compromise runbook around the people who own finance, payroll, customer communication, and IT response.

The right plan should answer three questions quickly: How do we remove the attacker? What business activity may be affected? What evidence tells us it is safe to resume work?

If your business is seeing suspicious Microsoft 365 activity—or wants a response plan before that happens—contact CybarWorks. We can help you contain the immediate risk, investigate the right systems, and reduce the chance that one compromised account becomes a larger business incident.

Frequently Asked Questions

Is changing the Microsoft 365 password enough after phishing?

No. A password reset is important, but the response should also revoke sessions, review MFA methods and devices, remove suspicious application consent, check roles and delegation, inspect forwarding and hidden inbox rules, investigate cloud activity, and assess connected applications and endpoints.

What should a small business do first after a Microsoft 365 account compromise?

Move communication to a trusted channel, document the event, disable or block the account, and revoke active sessions. Then reset credentials through the authoritative identity system and investigate persistence, email activity, collaboration data, connected applications, endpoints, and business fraud.

Does revoking sessions immediately sign the user out of every application?

Not always. Revocation prevents new tokens and invalidates Microsoft Entra refresh tokens, but some applications control their own session cookies or may not reevaluate access immediately. Critical connected applications should be reviewed and revoked separately when necessary.

What mailbox settings should be checked after compromise?

Review external forwarding, visible and hidden inbox rules, delegates, send-as permissions, automatic replies, signatures, Sent Items, Deleted Items, message trace, outbound volume, and the restricted entities list. Look for rules that hide customer or vendor replies.

When is a compromised account safe to re-enable?

Re-enable it only after credentials and authentication methods are trusted, sessions are revoked, persistence mechanisms are removed, relevant activity is investigated, the device is remediated when necessary, business impact is addressed, and monitoring is ready for recurrence.

Works Cited

Ready to transform your business with our IT expertise?