First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Business Email Compromise Investigation and Recovery
Security and Protection

Business Email Compromise Investigation and Recovery

Business Email Compromise Investigation and Recovery is an emergency engagement for organizations whose Microsoft 365 account — or several — has been taken over. IT Partner contains the attacker first (revoking sessions and tokens, resetting credentials in the right order, removing malicious inbox rules, forwarding, and rogue OAuth grants), then builds a timeline of attacker activity from Microsoft Entra sign-in logs and the Microsoft Purview unified audit log, hunts down every persistence mechanism, summarizes what was accessed or sent, and hands you a prioritized hardening plan. We prepare the evidence your bank, cyber-insurance carrier, and law enforcement will ask for — your counsel and carrier lead those tracks; we support them.

Timeline 5 daysService owner Dan ApplebyMicrosoft 365Exchange OnlineMicrosoft Entra ID

What this engagement is

A business email compromise rarely announces itself. It surfaces as a customer asking about changed bank details on an invoice, a vendor confirming a payment you never requested, inbox rules nobody created, or a wave of phishing sent from your own domain. By that point the attacker has usually been reading mail for days or weeks — and every hour of improvised cleanup can destroy the evidence that shows what they actually did. This engagement does the work in the right order. Containment first: revoke active sessions and refresh tokens, reset credentials for the accounts in scope, verify and clean up registered MFA methods, remove malicious inbox rules and mailbox or transport forwarding, and revoke attacker-consented OAuth applications. Investigation second: a timeline of attacker sign-ins and actions reconstructed from Microsoft Entra sign-in logs and the Microsoft Purview unified audit log, a systematic hunt for persistence — rules, delegations, added MFA methods, app registrations, new accounts, role changes — and an exposure review of what was read, searched, or sent, to the extent your licensing and retention captured it. Hardening third: a prioritized, owner-assigned list of the changes that would have prevented or shortened the incident, so the same door is not left open twice. Who this is for: organizations on Microsoft 365 that are mid-incident or have just closed one — including cases where fraudulent payment instructions already went out. Who it is not for: ransomware and endpoint malware response, on-premises server forensics, or litigation-driven forensic work — those need a different engagement, and we say so during intake rather than after. The engagement is scoped per incident, from $4,950, with the quote confirmed in writing before work begins. The defined investigation scope typically completes within five business days; containment actions start on day one.

Success criteria

01Attacker access to the in-scope accounts is terminated: active sessions and refresh tokens revoked, credentials reset in an approved order, and attacker-registered MFA methods and devices removed.
02Persistence mechanisms are identified and reverted for the in-scope tenant items: malicious inbox rules, mailbox and transport-rule forwarding, delegate and mailbox permissions, rogue OAuth application grants, attacker-created accounts, and unauthorized admin-role or authentication-method changes.
03A written timeline of attacker activity is delivered, reconstructed from Microsoft Entra sign-in logs and the Microsoft Purview unified audit log, with gaps caused by licensing or retention limits stated explicitly rather than papered over.
04An exposure review is delivered: which mailboxes were accessed, what the attacker sent, and — where MailItemsAccessed and related events are available in your tenant — which items were touched.
05Fraud-relevant evidence (message traces, sent fraudulent messages, timeline extracts, indicator lists) is packaged for your bank, cyber-insurance carrier, and law-enforcement filings, with the collection method documented.
06A prioritized post-incident hardening plan is delivered with owners and sequence, and any immediately agreed quick mitigations are applied during the engagement.
07Your administrators receive a walkthrough of what happened, what was changed in the tenant, and what to watch for re-compromise in the following weeks.

What you receive

Incident intake and scoping record: suspected accounts, first known indicators, business impact including any fraudulent payment instructions, and the approved containment order.
Containment action log with timestamps: session and token revocations, credential resets, MFA method cleanup, inbox-rule and forwarding removal, OAuth grant revocations, and connector and transport-rule review.
Attacker-activity timeline from Microsoft Entra sign-in logs and the Microsoft Purview unified audit log, covering the period your retention holds.
Persistence-hunt results and removal record across inbox rules, forwarding, delegations, OAuth grants and app registrations, MFA and recovery-method changes, new or modified accounts, and admin-role changes.
Exposure review: mailboxes and data accessed, searches run, and mail sent by the attacker, based on the audit events available under your licensing and configuration.
Evidence package and executive summary suitable for your bank's recall request, your cyber-insurance claim, and law-enforcement reporting (for example an IC3 filing) — prepared for your counsel and carrier to use.
Prioritized hardening plan mapped to concrete next steps — MFA coverage, Conditional Access, legacy authentication, mail-authentication and monitoring gaps — with owners and recommended order.
Administrator handoff session covering the timeline, the changes made, and re-compromise indicators to watch.

How the work unfolds

Day 1 — Intake and containment

Confirm scope, access, and the containment order with your decision-maker, then execute it: revoke sessions and tokens, reset credentials, clean up MFA methods, remove malicious rules and forwarding, and revoke rogue OAuth grants. Preserve rule definitions, messages, and audit evidence before removing anything.

Days 1–2 — Persistence hunt and eviction

Sweep the tenant for everything an attacker leaves behind: inbox rules and transport rules, delegations and mailbox permissions, OAuth grants and app registrations, added MFA and recovery methods, new accounts, and admin-role changes. Revert what is malicious; record what is ambiguous for your review.

Days 2–4 — Timeline and exposure investigation

Reconstruct attacker activity from Entra sign-in logs and the unified audit log: initial access, sessions, mail access and searches, sent messages, and data touched. Identify affected third parties — customers or vendors who received fraudulent mail — so you can decide on notifications.

Day 4 — Evidence package and hardening plan

Assemble the evidence package for bank, carrier, and law enforcement, and draft the prioritized hardening plan with owners. Apply any quick mitigations you approve during the engagement.

Day 5 — Report and handoff

Deliver the incident report, walk your administrators through the timeline and the tenant changes, review re-compromise indicators, and agree the follow-on hardening or monitoring work if you want it.

Prerequisites

Emergency administrative access to the Microsoft 365 tenant — a Global Administrator session or an agreed delegated-access arrangement — available on day one.
A named decision-maker reachable during business hours who can approve credential resets, session revocations, and rule removals quickly; containment speed is set by approval speed.
The list of suspected accounts and first known indicators: the message, rule, sign-in alert, or customer report that started the investigation, with dates as precise as you have them.
If money moved: amounts, dates, beneficiary details, and your bank contact, so recall requests and filings can be prepared without delay.
No destructive cleanup before evidence is captured: do not delete inbox rules, purge mail, or wipe accounts before we record them — and if some cleanup already happened, tell us exactly what was done and when.
The tenant's logs as they exist. We work with your current licensing and retention: Microsoft Purview Audit (Standard) retains 180 days of activity for events generated since October 2023, and Entra sign-in log retention depends on your Entra ID license. We will state plainly what the logs can and cannot show.
Your decision on who else is engaged — cyber-insurance carrier, outside counsel, bank, law enforcement. Notifying them is your call and your counsel's; we produce what they need.
Availability of your IT contact for access questions, and your agreement that containment may sign users out and force re-authentication during business hours.

Who does what

IT Partner

  • Lead intake, scoping, and the approved containment sequence, starting with first response within one business hour of your request.
  • Execute containment: session and token revocation, coordinated credential resets, MFA method cleanup, malicious rule and forwarding removal, and OAuth grant revocation.
  • Preserve rule definitions, messages, and audit evidence before removal, and document every containment action with timestamps.
  • Hunt and revert persistence mechanisms across the in-scope tenant surfaces, recording ambiguous findings for your review.
  • Reconstruct the attacker-activity timeline and exposure review from Entra sign-in logs and the unified audit log, within your licensing and retention limits.
  • Prepare the evidence package and executive summary for your bank, carrier, counsel, and law-enforcement filings.
  • Deliver the prioritized hardening plan and apply approved quick mitigations during the engagement.
  • Conduct the administrator handoff and identify re-compromise indicators to watch.

Your team

  • Provide emergency administrative access and a decision-maker who can approve containment actions promptly.
  • Disclose everything known about the incident, including any cleanup already performed and any prior compromises.
  • Decide and execute notifications: customers and vendors who received fraudulent mail, your bank, your cyber-insurance carrier, counsel, and law enforcement.
  • Own all payment-recovery actions with your bank and law enforcement, using the evidence we prepare.
  • Communicate with affected employees, and handle HR or disciplinary matters if an insider is involved.
  • Approve the hardening plan priorities and own their implementation unless separately contracted.
  • Make legal determinations — including breach-notification obligations — with your counsel; we provide the factual record.
  • Review and approve the final report and deliverables against the published success criteria.

What's not included

Legal, regulatory, and insurance counsel — we prepare evidence and the factual record, but breach-notification determinations, regulatory filings, insurance-claim strategy, and negotiations belong to your counsel and carrier. We coordinate with them; we do not replace them.
Litigation-grade forensics — bit-for-bit imaging, chain-of-custody procedures for court, certified forensic laboratory analysis, and expert-witness testimony. If litigation is anticipated, engage a forensics firm through counsel; our report and evidence package are built for operational recovery and can be handed to that firm.
Guaranteed recovery of transferred funds — wire and ACH recalls are decided between your bank, the receiving bank, and law enforcement. Acting within hours materially improves the odds, and we make sure the evidence is ready fast, but no one can honestly promise recovery.
Endpoint, network, and on-premises response — malware reverse-engineering, ransomware response and negotiation, workstation and server forensic imaging, and non-Microsoft-365 SaaS investigations are separately scoped work.
Ongoing detection and full hardening implementation — continuous monitoring is Multi-Platform Managed Detection and Response (MDR); tenant-wide hardening implementation is Microsoft 365 Security Baseline and Secure Score Remediation, Enable MFA for All Users, and Conditional Access Policy Implementation; smaller defined-scope investigations outside an emergency are Security Managed Service: Incident Response.
Mass user communications, PR and reputation management, data reconstruction beyond what your retention policies preserved, and hands-on remediation of customer or vendor tenants that received fraudulent mail.

Limitations & technical notes

!The logs bound the investigation. Activity that was never logged, or that has aged past retention, cannot be reconstructed: Microsoft Purview Audit (Standard) retains 180 days for events generated since October 2023, and Entra sign-in log retention depends on your license. If the compromise predates retention, the timeline will have gaps, and the report will say exactly where.
!Exposure detail varies by tenant. Mailbox-item-level access events (MailItemsAccessed) have been extended by Microsoft to standard licensing tiers, but availability and coverage vary with license and configuration history; where item-level events are absent, exposure is stated conservatively rather than guessed.
!Containment is disruptive by design: revoking sessions and resetting credentials signs users out and forces re-authentication. We sequence actions to minimize business interruption, and every disruptive step is approved by your decision-maker first.
!Eviction is established to high confidence, not metaphysical certainty — a sufficiently early or sophisticated compromise can leave traces below the logging floor. That is exactly why the engagement ends with a hardening plan and, where wanted, monitoring, rather than a declaration of invulnerability.
!Response-time commitment is our published support SLA — first response within one business hour — with monthly statistics, including the months we missed, published on our site. We do not claim a guaranteed 24/7 dispatch.
!The five-business-day duration covers the defined per-incident scope confirmed in the written quote. Additional compromised accounts, a longer attacker dwell time, or extension into endpoints and other systems change the scope through a written, approved re-quote — never silently.
!Engagement pricing starts from $4,950 and is scoped per incident; the quote is confirmed in writing before work begins, and you pay after you approve delivery.
!Technical content reviewed August 2026 against Microsoft Purview audit and Microsoft Entra documentation.

Frequently asked questions

We think our Microsoft 365 account is compromised — what should we do right now?

Three things before anything else. First, if fraudulent payment instructions went out, call your bank now and ask for a recall — hours matter more than anything an investigator does later. Second, stop the improvised cleanup: do not delete inbox rules, purge messages, or wipe the account, because that destroys the record of what the attacker did. Third, contact us with what you know — which accounts, since when, what tipped you off. Containment (revoking sessions, resetting credentials, removing rules and rogue app grants) starts on day one, in an order that preserves evidence.

How fast do you respond?

Our published support SLA is first response within one business hour — and we publish our monthly support statistics for every month since December 2023, including the months we missed, so you can check the record rather than take the claim on faith. We do not advertise a guaranteed 24/7 emergency dispatch, because we would rather publish a number we can prove.

Can you tell us exactly which emails the attacker read?

Often yes, sometimes partially. Microsoft 365 records mailbox activity in the unified audit log, and item-level access events (MailItemsAccessed) — once reserved for premium licensing — have been extended by Microsoft to standard tiers, though coverage depends on your license and configuration history. Where item-level events exist, we can list what was accessed and searched; where they do not, we reconstruct exposure conservatively from sign-ins, sync activity, and sent items, and the report states the confidence level explicitly.

Money was wired to the attacker. Can you get it back?

We will not promise that, and you should be suspicious of anyone who does. Recalls are decided between your bank, the receiving bank, and law enforcement, and success drops sharply with every passing hour. What we do: help you move immediately — bank recall request, evidence for an IC3 (FBI Internet Crime Complaint Center) filing, message traces and timeline extracts your bank and investigators will ask for — prepared fast and documented properly. Recovery actions themselves belong to your bank and law enforcement.

Will you work with our cyber-insurance carrier and our lawyer?

Yes — in a support role. Your carrier and counsel lead the claim and the legal determinations, including whether the incident triggers breach-notification obligations. We produce what they need: the factual timeline, containment log, exposure summary, and evidence package, with the collection method documented. If your policy requires using a carrier-approved response panel, engage the carrier first and we will coordinate with whoever they appoint.

Is this a certified forensic investigation we could use in court?

No, and we say that plainly. This is an operational investigation and recovery engagement: its job is to evict the attacker, establish what happened, and harden the tenant. We document our methods and preserve evidence carefully, and our output can be handed to a forensics firm — but bit-for-bit imaging, formal chain of custody, and expert-witness work are a different discipline that should be engaged through your counsel if litigation is anticipated.

The attacker emailed our customers with fake invoices. What do we do about that?

The investigation identifies which external parties received attacker mail — recipients, messages, and send times — so the notification decision is made on facts rather than guesswork. We help you pull the affected-recipient list and draft the technical explanation of what happened; deciding whom to notify, and sending those communications, stays with you and your counsel, because notification carries legal and commercial judgment we should not make for you.

Will containment lock our whole company out of email?

No. Containment is targeted at the accounts in scope: their sessions are revoked, their credentials reset, their attacker-registered MFA methods removed. Those users re-authenticate and keep working; the rest of the organization is not touched unless the investigation shows the compromise is wider. Every disruptive action is approved by your decision-maker before it runs.

We already reset the password. Are we safe now?

Usually not, and this is the most common mistake we see. A password reset alone does not revoke existing sessions and refresh tokens, does not remove an authenticator app the attacker registered, and does not touch inbox rules, mailbox forwarding, delegate permissions, or OAuth applications the attacker consented to — any one of which keeps them reading your mail after the reset. The persistence hunt exists precisely because attackers assume you will change the password and stop there.

What if we only have basic Microsoft 365 licensing — is an investigation still possible?

Yes. Microsoft Purview Audit (Standard), included with business and enterprise plans, retains 180 days of activity for events generated since October 2023, and Microsoft has extended previously premium item-level events to standard tiers. Sign-in log depth depends on your Entra ID license. The practical effect of lighter licensing is coarser detail in places, not an impossible investigation — and the report will distinguish what the logs prove from what they merely suggest.

What does "from $4,950" actually cover?

The base engagement covers a defined per-incident scope — confirmed in your written quote before work begins — including containment, the persistence hunt, the audit-log timeline and exposure review, the evidence package, the hardening plan, and the handoff, typically within five business days. What moves the price up: more compromised accounts, longer attacker dwell time to reconstruct, or extension beyond Microsoft 365 into endpoints and other systems. Any change is a written, approved re-quote, and you pay after you approve delivery.

How do we keep this from happening again?

The engagement ends with a prioritized hardening plan — typically MFA coverage gaps, Conditional Access, legacy authentication, mail-authentication records, and alerting — with owners and order. Implementation is available as follow-on work: Microsoft 365 Security Baseline and Secure Score Remediation for tenant-wide hardening, Enable MFA for All Users and Conditional Access Policy Implementation for identity, Microsoft Defender for Office 365 Implementation for mail-borne threats, and Managed Detection and Response for continuous monitoring.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

From $4,950 (scoped by incident)
5 days
Get incident help now