What to Do After a Microsoft 365 Account Is Compromised - System Force IT

What to Do After a Microsoft 365 Account Is Compromised

Someone forwards you an email you did not send. Or a customer rings to query an invoice with bank details you do not recognise. Or a sign-in alert lands from a country none of your staff have visited. A Microsoft 365 account has been compromised, and the clock is now running on what the attacker does next.

This is the single most common serious incident we see at UK SMEs, and the good news is that it is usually recoverable if you act in the right order. This guide walks through exactly what to do, from confirming the compromise to locking the attacker out and checking what they touched. It is a companion to our full cyber incident response plan guide, focused specifically on a hacked Microsoft 365 or Entra ID account.

The most important thing to understand up front: resetting the password is not enough. An attacker with a live session or token can stay signed in even after the password changes. You have to revoke sessions as well. We come back to this below.

First, confirm it is actually a compromise

Not every odd email is a hack. Before you hit the panic button, confirm what you are dealing with. Signs of a genuine account compromise include: a sign-in from an unexpected location or device, multi-factor authentication (MFA) prompts the user did not trigger, emails in the Sent folder the user did not write, mailbox rules that quietly delete or move replies, or colleagues and customers receiving phishing or fake-invoice emails from the account. If you see any of these, treat it as a live incident and start an incident log with the current time.

Step 1: Contain the account

Your first job is to stop the attacker doing anything else while you investigate. In order:

  • Block sign-in for the affected account in the Microsoft 365 admin centre or Entra admin centre. This is faster and less disruptive than deleting anything.
  • Reset the password to something new and strong. Do not reuse an old one.
  • Revoke active sessions and refresh tokens. This is the step people miss. In Entra ID, “revoke sessions” (or “sign out everywhere”) kills the attacker’s existing logins, not just future ones. Without it, a stolen session token can keep them in for hours.
  • Re-secure MFA. Check the authentication methods registered on the account and remove any you do not recognise, because attackers often add their own phone number or authenticator so they can get back in.

Once the account is contained, you can investigate without the attacker moving the goalposts underneath you.

Step 2: Investigate what they did

An attacker in a mailbox is rarely just reading email. They set things up to profit and to keep access. Work through this list and record what you find:

What to check Why it matters
Recent sign-in logs Where and when they signed in, and how MFA was satisfied. This tells you the window of exposure.
Inbox and mailbox rules Attackers create rules that auto-delete or hide their replies, or forward everything to themselves. Delete any you do not recognise.
External forwarding A rule or setting quietly sending copies of mail to an outside address is a classic data-theft and fraud setup.
Delegated permissions Access they may have granted themselves or another account to the mailbox.
OAuth app consents Malicious third-party apps the user was tricked into approving can keep read access even after a password reset. Revoke anything suspicious.
Sent and deleted items What was sent from the account, and what they tried to hide.
SharePoint and OneDrive activity Which files were opened, downloaded or shared. This matters for assessing any data exposure.
Admin and directory changes New accounts, new admins, or new app registrations. A compromise that reaches admin level is far more serious.
If unified audit logging was switched off before the incident, some of these answers will not exist. That is worth fixing now for every tenant, because you cannot investigate what was never recorded. See our guide on the logs you need for a cyber investigation.

Step 3: Check for payment fraud and onward phishing

The most costly outcome of a mailbox compromise is usually not the mailbox itself, it is business email compromise: the attacker sits in the account, watches for an invoice or payment conversation, and steps in to redirect the money. Check specifically for:

  • Any emails about payments, invoices or changes to bank details, sent or received during the exposure window.
  • Phishing sent from the account to colleagues, customers or suppliers, so you can warn them.
  • Whether any payment or bank-detail change actually went through. If so, contact your bank immediately, as fast action can sometimes recall a payment.

Always verify any bank-detail change by phoning the other party on a known, trusted number, never using the contact details in the suspicious email.

Step 4: Check whether it spread

One compromised account is often the first of several. Ask: were other accounts phished the same way? Did the attacker use this mailbox to phish internally and harvest more credentials? Review sign-in patterns across the tenant for the same unusual locations or devices, and reset and re-secure any other account that looks affected. If the attacker reached an administrator account, treat the whole tenant as compromised and get expert help.

Step 5: Was personal data involved?

If the attacker read or took emails and files containing people’s personal data, this may be a personal data breach with reporting duties, separate from the technical incident. Do not assume it is or is not reportable, work it through: our data breach versus cyber incident guide explains the difference, and the free toolkit includes a personal data breach assessment form. Report to the ICO within 72 hours of becoming aware only where a notifiable breach has occurred. This is practical guidance, not legal advice.

Step 6: Prevent it happening again

Once the fire is out, close the door the attacker came through. The controls that stop most of these attacks are not exotic:

  • MFA on every account, ideally phishing-resistant methods rather than SMS codes.
  • Conditional access to block or challenge sign-ins from unexpected locations and risky conditions.
  • Turn on unified audit logging and keep it long enough to be useful.
  • Restrict who can consent to third-party apps, so a single click cannot hand over mailbox access.
  • Agree a payment-verification process so no bank-detail change is actioned on email alone.
  • Brief your team on what modern phishing looks like, since the bad spelling that used to give scams away is long gone.

Our Microsoft 365 security service and the free Cyber Incident Response Toolkit both help you put these in place.

Not sure your Microsoft 365 is properly locked down?

We can review your tenant’s identity, MFA, conditional access and logging, and give you a plain, prioritised list of what to fix, so a single phished password does not become a company-wide problem.

Book a free IT and security review

Frequently asked questions

How do I know if my Microsoft 365 account has been hacked?

Common signs are sign-ins from unexpected locations or devices, MFA prompts you did not trigger, emails in your Sent folder you did not write, mailbox rules that delete or move replies, and colleagues or customers receiving phishing or fake-invoice emails from your address. Any of these should be treated as a live incident.

Is resetting my password enough to lock the attacker out?

No. An attacker with a live session or stolen token can stay signed in even after the password changes. You must also revoke active sessions and tokens (sign out everywhere) and remove any authentication methods or app consents they added, otherwise they can walk straight back in.

Should I delete the compromised account?

Usually no. Blocking sign-in contains the account just as effectively and preserves the evidence and the mailbox you need to investigate and recover. Deleting it can destroy the very information you need to work out what the attacker did.

Do I have to report a compromised Microsoft 365 account to anyone?

It depends. If personal data was accessed or taken and there is a risk to the people involved, it may be a notifiable personal data breach for the ICO within 72 hours. If money or fraud is involved, tell your bank and Report Fraud. A significant attack can also be reported to the NCSC. Reporting to one body does not satisfy your duty to another.

Related reading: the full Cyber Incident Response Plan guide, our guide to preserving evidence, and the free Cyber Incident Response Toolkit, which includes a phishing and business email compromise playbook.

Practical guidance, not legal advice. Regulatory references were checked against current UK sources on 26 August 2026. From System Force IT, UKAS ISO/IEC 27001:2022 certified, supporting UK businesses since 2006.

Stay one step ahead of the threats

Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.

Get the free weekly briefing →

Table of Contents

Would you like to know how we can help?

Get in touch

Name