Call NowFree Quote
Cybersecurity

Microsoft 365 Account Compromised: What to Do Immediately

A compromised Microsoft 365 account is one of the most time-sensitive incidents a business can face - attackers often set up mail forwarding rules or send fraudulent invoices to contacts within minutes of gaining access. Here's the exact sequence to follow, in order.

Step 1: Revoke Active Sessions Immediately

In the Microsoft 365 admin centre, go to the affected user and revoke all active sessions. This forces the attacker's current session to end immediately, even before you've changed the password - do this first, not last.

Step 2: Reset the Password

Reset to a strong, unique password. Do not reuse anything close to the old one - if the attacker gained access through a leaked or guessed password, a similar new one offers little real protection.

Step 3: Check and Remove Malicious Inbox Rules

Attackers commonly set up rules to forward incoming mail to an external address, or to automatically delete replies to fraudulent emails they've sent, hiding their activity from the account owner. Check the mailbox rules in Outlook or the admin centre and remove anything unfamiliar.

Step 4: Review Sign-In Logs

Check Entra ID sign-in logs for the account to understand when the compromise likely started, from what location, and what was accessed during that window. This helps scope how far the incident actually goes.

Step 5: Check Connected Apps and OAuth Grants

Attackers sometimes grant a malicious third-party app access to the account rather than relying solely on the password - this access can persist even after a password reset. Review and revoke any unfamiliar app permissions under the user's account settings.

Step 6: Confirm MFA Is Properly Enforced

If MFA wasn't enabled, or was enabled but not enforced via Conditional Access, this is the moment to fix that - both for the affected account and as a broader check across the organisation. See our guide on MFA setup for Perth businesses.

Step 7: Check Who Else Might Have Been Targeted

A compromised account is often used to send convincing phishing or invoice fraud emails to the victim's own contacts, since they come from a trusted, legitimate address. Warn colleagues, clients, and suppliers who may have received something from the account during the compromise window. See our guide on business email compromise and invoice fraud for how this scam typically plays out.

Step 8: Determine Notification Obligations

If client or personal data may have been accessed or exposed, this can trigger reporting requirements under the Notifiable Data Breaches scheme. See our guide on the Notifiable Data Breaches scheme for what qualifies and the timeframes involved.

After the Immediate Response

Once the account is secured, review how the compromise happened in the first place - a phishing click, a leaked credential from another breach, or an MFA gap - so the same path can't be used again. See our guide on cyber attack response for Perth businesses for the broader incident response process beyond this specific scenario.

Frequently Asked Questions

How do I actually know if an account has been compromised?

Common signs include unexpected sign-ins from unfamiliar locations in the sign-in logs, unexplained inbox rules forwarding mail externally, colleagues or clients reporting strange emails from that address, or MFA prompts the user didn't trigger themselves. Any one of these is worth investigating immediately, not waiting to confirm further.

Should I change the password first, or revoke sessions first?

Do both essentially at once - changing the password alone doesn't end an already-active session, so an attacker with an open session can remain logged in even after the password changes. Revoking sessions forces re-authentication everywhere, which is what actually locks them out.

Is it safe to keep using the account once the password is reset?

Only once you've also checked for and removed any malicious inbox rules, reviewed connected apps and OAuth grants for anything unfamiliar, and confirmed MFA is properly configured. A password reset alone doesn't undo changes the attacker may have made while they had access.

Do I need to notify anyone outside the business?

If client or personal data may have been accessed, this can trigger obligations under the Notifiable Data Breaches scheme. See our guide on the scheme for when notification to the OAIC and affected individuals is required.

We provide 24/7 incident response for compromised Microsoft 365 accounts - session revocation, rule cleanup, and scoping, fast.

Emergency IT Support →

Think an account may be compromised right now?

Call 0433 087 091 immediately - every minute matters with an active account compromise.

Get Emergency Help Now

For related reading, see our guides to what to do in the first hour of an IT emergency and business email compromise and invoice fraud.

Share this article