First page of Microsoft's 100,000-partner directory, sorted by responsiveness All 6 Microsoft Solutions Partner designations Microsoft Solutions Partner since 2006 1,100+ organizations under management
Home/Blog/Your Microsoft 365 account has been compromised.…

Your Microsoft 365 account has been compromised. What should you do next?

2026-06-16·IT PartnerMicrosoft 365Cloud SecuritySecurity

A compromised Microsoft 365 account is no longer just a password problem. In 2026, attackers may steal session tokens, register their own MFA method, grant OAuth app consent, create hidden mailbox rules, monitor conversations for business email compromise, or use the account to phish your customers and colleagues. The right response is fast containment, careful investigation, removal of persistence, safe recovery, and long-term hardening.

First: assume the attacker may have seen more than email

If a user’s Microsoft 365 credentials, session, or device has been compromised, assume the attacker may have accessed data available to that user: Exchange Online mailbox content, Teams chats and files, OneDrive for Business, SharePoint sites, contacts, calendar data, and any connected SaaS applications allowed by the user’s permissions.

Modern attacks often involve more than a stolen password. Common 2026 scenarios include phishing-resistant-looking sign-in pages, adversary-in-the-middle phishing kits that steal tokens, QR-code phishing, MFA fatigue or push bombing, malicious OAuth applications, compromised devices, and business email compromise where the attacker quietly studies invoice and payment conversations before acting.

Do not treat the event as resolved simply because the password was changed. A password reset is only one step.

Compromised-account response checklist

Timeframe What to do
First 15 minutes Block sign-in if the account is actively abused, revoke user sessions/refresh tokens, preserve key evidence, and check whether the user has administrative privileges.
First hour Reset the password, review and reset authentication methods, remove suspicious MFA methods, disable suspicious devices, check forwarding and inbox rules, and review recent sign-ins in Microsoft Entra ID.
Same day Investigate Microsoft Defender XDR incidents, Exchange message trace, Defender for Office 365 Explorer/Threat Explorer if licensed, Microsoft Purview audit logs, mailbox audit activity, OAuth app consent, enterprise applications, connectors, transport rules, and delegated mailbox permissions.
After recovery Notify affected parties where required, document the timeline, review financial fraud exposure, harden Conditional Access and MFA, disable legacy protocols, improve email protection, and run a Microsoft Secure Score review.

1. Contain the account immediately

Start with containment, but preserve evidence before deleting artifacts when possible.

Recommended actions:

  • In the Microsoft 365 admin center or Microsoft Entra admin center, block the user from signing in if the account is actively being used by an attacker.
  • Revoke sign-in sessions and refresh tokens so stolen sessions cannot continue to be used.
  • Reset the user’s password using a strong temporary process, then require the user to set a new password after the environment is safe.
  • Review the user’s registered authentication methods. Remove unknown phone numbers, authenticator apps, security keys, passkeys, or email addresses. Require MFA re-registration if there is any doubt.
  • Check whether the user has privileged roles, Exchange admin rights, SharePoint admin rights, application admin rights, or delegated admin access.
  • Disable or isolate suspicious registered devices. If Microsoft Defender for Endpoint is deployed, check device alerts and consider isolating the device.
  • If the account is sending spam or phishing, check Restricted entities in the Microsoft Defender portal and outbound spam policies.

If this is a high-risk user, an executive, a finance employee, or an administrator, escalate the response immediately.

2. Investigate what happened

The goal is to answer four questions: how the attacker got in, what they accessed, what they changed, and whether they spread to other accounts or systems.

Use the current Microsoft security portals and logs:

  • Microsoft Entra admin center: sign-in logs, audit logs, user risk, sign-in risk, authentication method changes, device registrations, and Conditional Access results.
  • Microsoft Defender portal: Defender XDR incidents, alerts, compromised user signals, email campaigns, Explorer/Threat Explorer, quarantine, submissions, and Restricted entities.
  • Exchange admin center: message trace, mailbox settings, mailbox permissions, delegates, Send As and Send on behalf permissions, transport rules, connectors, accepted domains, and remote domains.
  • Microsoft Purview portal: audit search, mailbox audit activity, eDiscovery and retention considerations where applicable.
  • Microsoft Defender for Cloud Apps: SaaS activity and session/app visibility when configured and licensed.
  • Microsoft Sentinel: cross-platform correlation and longer retention if your organization sends Microsoft 365 and Entra logs to Sentinel.

Look for suspicious sign-ins by location, device, IP address, user agent, impossible travel, unfamiliar device, legacy protocol, failed MFA patterns, and unusual successful sign-ins. Also review whether the attacker downloaded files, accessed SharePoint or OneDrive content, searched the mailbox, sent messages, or changed security settings.

3. Remove persistence

Attackers often leave behind access paths that survive a password reset. Check all of the following before returning the account to normal use:

  • Inbox rules, sweep rules, hidden or suspicious mailbox rules, and rules that delete, archive, mark as read, or forward messages.
  • Mail forwarding, both user-configured forwarding and mailbox-level forwarding.
  • Delegates, mailbox permissions, Send As, Send on behalf, and shared mailbox access.
  • Transport rules, connectors, accepted domains, remote domains, and outbound routing changes.
  • OAuth app consent, enterprise applications, service principals, and suspicious delegated permissions such as Mail.Read, Mail.Send, offline_access, Files.Read.All, or user impersonation permissions.
  • App passwords, if they still exist in the tenant.
  • Registered devices, joined devices, and suspicious device compliance state.
  • Authentication methods added shortly before or after the compromise.
  • Admin role assignments, Privileged Identity Management activations, and changes to Conditional Access or security defaults.

For tenants with many users, do not only inspect the compromised account. Search for similar indicators across the tenant, including the same IP addresses, phishing URLs, mailbox rules, OAuth applications, and message subjects.

4. Clean up malicious email and protect recipients

If the compromised account sent phishing or fraudulent messages, act quickly to limit damage.

Recommended actions:

  • Use Exchange message trace to identify recipients, timestamps, subjects, and delivery results.
  • Use Defender for Office 365 Explorer or Threat Explorer, if licensed, to investigate campaigns and related messages.
  • Use quarantine, Zero-hour Auto Purge, tenant allow/block list, and remediation actions where available and appropriate.
  • Submit phishing samples to Microsoft from the Defender portal so detections can improve.
  • Remove the user from Restricted entities after the cause is remediated and outbound abuse has stopped.
  • Notify internal recipients and, when appropriate, external recipients who may have received phishing or fraudulent instructions.
  • For business email compromise scenarios, alert finance, leadership, and affected vendors or customers to verify payment changes out of band.

Do not rely on a single recall action. Once email has left the organization, you may not be able to remove every copy or prevent forwarding.

5. Recover the user safely

After persistence is removed and the user’s device is considered safe, restore access in a controlled way.

Recovery steps:

  • Ensure the endpoint is patched and scanned. If the device is suspect, rebuild or replace it rather than trusting it.
  • Confirm Windows security controls are enabled, including firewall, endpoint protection, disk encryption where appropriate, and current updates.
  • Reset the password and require MFA using approved methods.
  • Re-enable sign-in only after sessions are revoked, authentication methods are verified, mailbox persistence is removed, and suspicious applications are revoked.
  • Monitor the account closely for several days, including sign-ins, email sending volume, rule creation, file access, and new consent grants.

If the user handles finance, payroll, HR, legal, executive communications, or sensitive customer data, continue enhanced monitoring and require independent verification for financial or data-release requests.

6. Handle legal, compliance, and business risk

A Microsoft 365 account compromise can become a reportable security incident. Requirements depend on your industry, location, contracts, data types, and cyber-insurance policy.

Consider these actions:

  • Preserve logs and document the incident timeline, including discovery, containment, investigation, remediation, and notifications.
  • Identify what data may have been accessed or exfiltrated from Exchange, Teams, SharePoint, OneDrive, and connected apps.
  • Involve legal, compliance, HR, privacy, and cyber-insurance contacts when sensitive data, regulated data, employee data, or customer data may be involved.
  • Review whether litigation hold, eDiscovery, or evidence preservation is required before deleting artifacts.
  • For business email compromise, verify wire transfers, invoice changes, payroll changes, vendor banking updates, and gift-card or procurement requests.

The technical cleanup and the business response should run in parallel.

7. Harden Microsoft 365 after the incident

The strongest outcome is not just restoring the user, but reducing the chance of the next compromise.

Recommended hardening actions:

  • Use Microsoft Secure Score as a prioritized improvement plan, but validate recommendations against your business requirements.
  • For small tenants without advanced identity management, enable Security Defaults if compatible with operations.
  • For managed environments, use Microsoft Entra Conditional Access policies with clear exclusions for monitored break-glass accounts.
  • Move toward phishing-resistant MFA: passkeys, FIDO2 security keys, Windows Hello for Business, certificate-based authentication, or Conditional Access authentication strengths where appropriate.
  • Keep number matching enabled for Microsoft Authenticator and reduce reliance on SMS and voice MFA for high-risk users.
  • If licensed for Microsoft Entra ID P2, use user-risk and sign-in-risk policies.
  • Disable legacy/basic authentication. Review SMTP AUTH exceptions, POP, IMAP, authenticated SMTP, and app passwords. Keep only documented exceptions and monitor them.
  • Deploy Defender for Office 365 policies such as Safe Links, Safe Attachments, anti-phishing protection, impersonation protection, user submissions, and attack simulation training where licensed.
  • Configure SPF, DKIM, and DMARC for your domains.
  • Use least privilege, separate admin accounts, Privileged Identity Management where available, and strong controls for break-glass accounts.
  • Review OAuth app consent settings and require admin approval for risky permissions.
  • Consider Defender for Cloud Apps, Defender for Endpoint, Microsoft Purview Audit capabilities, and Microsoft Sentinel based on your risk profile and retention needs.

Licensing and service options to consider

The right security stack depends on company size, regulatory requirements, and risk. Common Microsoft licensing paths include Microsoft 365 Business Premium for many SMB security baselines, Microsoft 365 E3 or E5 for larger organizations, Microsoft Entra ID P1 or P2 for Conditional Access and risk-based identity controls, Defender for Office 365 Plan 1 or Plan 2 for email security, Defender for Cloud Apps for SaaS visibility and control, Defender for Endpoint for device protection, Microsoft Purview Audit capabilities for investigation, and Microsoft Sentinel for SIEM and long-term correlation.

Under current CSP/NCE purchasing, it is important to match licenses to required features before an incident happens. Some investigation and remediation capabilities depend on licensing, configuration, audit retention, and whether logs were enabled before the compromise.

Key takeaways

  • Do not stop at a password reset. Revoke sessions, review authentication methods, and remove attacker persistence.
  • Use current Microsoft portals: Microsoft Entra admin center, Microsoft Defender portal, Microsoft Purview portal, Exchange admin center, and Microsoft 365 admin center.
  • Check for mailbox rules, forwarding, delegates, transport rules, connectors, OAuth app consent, suspicious devices, and changed MFA methods.
  • Modern MFA strategy should include Conditional Access and phishing-resistant options such as passkeys, FIDO2 security keys, Windows Hello for Business, or certificate-based authentication where appropriate.
  • Account compromise can create legal, compliance, cyber-insurance, and business email compromise risk, not just an IT cleanup task.

If you suspect a Microsoft 365 account compromise, IT Partner can help with incident response, Microsoft 365 security assessment, Conditional Access and MFA implementation, Defender for Office 365 deployment, and managed Microsoft 365 security. Start with our services page or contact us for help triaging the incident.

Questions this article didn’t answer?

Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.