Back to blog
SecurityPublished on August 28, 20268 min read

Compromised Microsoft 365 Account: How to Respond

A hacked Microsoft 365 account steals data and scams your contacts. Revoke sessions, reset, MFA, review rules: the action plan to take back control.

A fraudulent invoice email goes out from an employee's address. A client flags a strange message. A partner receives an unusual wire-transfer request. These signals often reveal a compromised Microsoft 365 account: someone else is signed in, reading emails, watching your habits, and preparing fraud in your company's name. How fast you react changes everything, because every extra hour widens the damage.

A compromised mailbox is not just a problem for its owner: it is a bridgehead into the whole organization and its network of contacts. The attacker can impersonate the employee, divert an invoice, reach shared documents, or pivot to other accounts. Worse, they often stay quiet for days, reading correspondence and learning your habits before striking, which is why the damage is frequently discovered only once fraud is already in motion. Reacting in the right order lets you take back control, close the backdoors, then stop it from happening again.

Take back control immediately

The first goal is to sign the attacker out and stop them from signing back in. These four moves take only a few minutes from the admin console, and the order matters.

  1. 1Reset the affected account's password with a strong, unique one.
  2. 2Revoke all active sessions in Entra ID to sign the attacker out at once.
  3. 3Check and re-enable MFA if it was bypassed or turned off.
  4. 4Temporarily block the account if doubt remains about its integrity.

Why revoking sessions is essential

Changing the password is not enough: existing session tokens stay valid and let the attacker keep acting despite the new password. Revoking sessions in Entra ID invalidates those tokens and forces a full new authentication, MFA included. It is this often-forgotten step that truly cuts off the access in progress.

Reset and revoke sessions: cut off the attacker's access.

Hunt down the backdoors the attacker left

Reclaiming the password is not enough. A seasoned attacker plants ways to keep access, even after your intervention. Systematically review the following before you consider the incident closed.

  • Inbox rules that quietly forward or delete emails.
  • Auto-forwarding addresses added to the mailbox.
  • Unknown MFA methods (phone, authenticator app) registered recently.
  • OAuth apps and permissions granted to suspicious third parties.
  • Sign-in logs: unusual locations, IP addresses, and devices.

These hidden rules are the signature of a compromise: they let the attacker keep reading your correspondence and intercept messages even after a password change. A rule that moves every email containing the words "invoice" or "payment" to an obscure folder, for instance, exists to hide an ongoing fraud. Removing them is essential to truly close the incident and avoid a relapse a few days later.

Manage the shock wave beyond the account

Think, too, about the shock wave beyond the account itself. Warn the contacts who may have received fraudulent messages, especially your clients and financial partners, so they do not act on a fake payment request. Check whether other accounts in the organization shared the same password and change them right away. Finally, assess whether any personal data was exposed: a mailbox compromise can amount to a breach that must be documented, and possibly notified within 72 hours under GDPR.

Document every step of your response as you go: time of detection, indicators observed, actions taken, estimated scope. That trail will prove invaluable in the event of a later audit or investigation, and it turns a chaotic incident into a controlled, defensible one.

After recovery: hunt suspicious rules, forwards, and MFA methods.

A concrete example

An SMB's accountant gets a call from a supplier puzzled by a change of bank details. Checking it, management discovers that an email sent from an employee's account had asked to change the IBAN for an upcoming payment. The account had been compromised through a fake sign-in portal, and an inbox rule quietly moved supplier replies to a hidden folder.

The response was methodical: password reset, sessions revoked, MFA verified, the malicious rule and auto-forward deleted, OAuth consents reviewed. The affected suppliers were called back by phone, not by email, to block any fraudulent transfer while the attacker might still be watching the mailbox. The incident was logged and the GDPR analysis carried out. Thanks to a fast, thorough response, no transfer went through and the attacker permanently lost access. A single missed step, such as forgetting to revoke sessions or leaving the hidden rule in place, would have let the fraud continue for days.

Common mistakes to avoid

Handling a compromised account often fails because people stop halfway. Here are the pitfalls that leave the door ajar.

  • Changing the password without revoking sessions, leaving active tokens valid.
  • Forgetting to check inbox rules and auto-forwards.
  • Not reviewing registered MFA methods, including one added by the attacker.
  • Neglecting OAuth consents, which grant persistent access with no password.
  • Warning no one, leaving contacts exposed to the ongoing fraud.

How AuPoint prevents the next compromise

To prevent the next compromise, Conditional Access and mandatory MFA neutralize nearly all stolen-password attacks before they even reach a mailbox. AuPoint is a SaaS that makes Intune security and compliance easy, with no PowerShell. The platform deploys these protections in a few clicks, continuously monitors your accounts' compliance, alerts you to risky configurations such as unexpected forwarding rules, and gives you an impact preview before applying plus one-click rollback. Instead of reacting to each incident under pressure, you close the door in advance and keep it closed, staying aligned with ISO 27001, NIS2, and GDPR.

Frequently asked questions

How do I know if an account is really compromised?

Typical signals are sign-ins from unusual locations or devices in the Entra ID logs, inbox rules the user did not create, emails sent without their knowledge, or reports from contacts. When in doubt, treat the account as compromised: resetting and revoking sessions only costs a few minutes.

MFA was enabled, so how was the account hacked?

Modern phishing can bypass classic MFA by intercepting the code in real time or tricking the user into approving a prompt. That is why you must check registered MFA methods after an incident, and favor phishing-resistant methods combined with a compliant-device requirement.

Do I have to notify the authority of a mailbox compromise?

It depends on whether personal data was exposed and the risk to individuals. A mailbox often contains personal data, so the question must be taken seriously and cannot simply be dismissed. Document the analysis in your breach register and notify within 72 hours if a risk to people's rights and freedoms is likely; if you conclude no notification is needed, keep the reasoning on file so the decision stays defensible later.

Connect your Microsoft tenant to AuPoint and harden your Microsoft 365 accounts in minutes, with an impact preview and guaranteed rollback, no PowerShell. Start free at aupoint.io.

Secure your tenant in 15 minutes

Free trial