← All posts· Cloud & Infrastructure

Microsoft 365 Account Compromised: Immediate Recovery Checklist

October 9, 2026

A compromised Microsoft 365 account requires immediate, specific action. This checklist details the steps to contain the breach, investigate the attacker's actions, and securely recover the account.

If you suspect a Microsoft 365 business account has been compromised, you must act immediately to contain the threat. An attacker with access to a single user account can access sensitive data, impersonate the user to defraud employees and vendors, and establish persistent access in your environment. This guide provides a direct, actionable checklist for IT leaders and responders to follow the moment an account takeover is suspected.

Your goal is to revoke the attacker's access, investigate their activity, and restore normal operations securely. Do not simply reset the password; that is rarely sufficient. Attackers often create backdoors, such as inbox rules or registering their own devices, that allow them to regain access even after a password change.

For immediate 24/7 incident response assistance, visit our Business Email Compromise recovery page.

First Steps: How to Contain a Compromised Microsoft 365 Account

Your first priority is to lock the attacker out and prevent further damage. The following steps should be taken immediately for the suspected compromised account.

  1. Do Not Delete the Account: Deleting the account can permanently erase valuable forensic evidence, including logs and mailbox data, making a thorough investigation impossible. Instead, disable the account or block sign-ins.

  2. Reset the User's Password: Choose a long, complex, and unique password that has never been used before. Ensure the user is not reusing this password for any other service.

  3. Revoke All Active Sessions: A password reset alone does not terminate active sessions. An attacker could remain logged in. Use the Microsoft 365 Admin Center or PowerShell to "Sign out of all sessions" for the user. This forces reauthentication on all devices and services.

  4. Block the User's Sign-in: In the Microsoft 365 Admin Center, block the affected user's ability to sign in temporarily. This provides an additional layer of protection while you investigate, ensuring the attacker cannot simply re-authenticate with stolen credentials.

  5. Review and Remove Unrecognized MFA Methods: Attackers often add their own phone number or authenticator app as a Multi-Factor Authentication (MFA) method. This is a common technique called "MFA stuffing." Navigate to the user's authentication methods in Entra ID (formerly Azure Active Directory) and remove any devices or numbers you do not recognize.

Next Steps: How to Investigate the Compromise

After containing the immediate threat, you must investigate to understand the scope and impact of the incident. This is a critical step for determining if data was breached, what the attacker's motives were, and if other accounts are affected.

  1. Analyze Sign-in Logs: In the Microsoft Entra admin center, review the sign-in logs for the compromised account. Look for suspicious activity such as logins from unusual geographic locations, impossible travel (e.g., logins from two different continents in a short time), or unfamiliar IP addresses and user agents (browsers/devices). Note the time, location, and IP address of all suspicious sign-ins.

  2. Examine the Unified Audit Log: The Microsoft Purview Unified Audit Log is your primary source of truth for attacker activity. Search for all activities performed by the compromised user from the time of the first suspicious sign-in. Pay close attention to actions like New-InboxRule, Set-Mailbox, Add-MailboxPermission, file access (FileAccessed), and any sharing activities (FileShared). The availability and retention of these logs depend on your Microsoft 365 licensing level.

  3. Inspect Mailbox for Malicious Rules: Attackers frequently create inbox rules to auto-forward sensitive emails (like invoices or wire transfer requests) to an external address, often automatically deleting the forwarded message to hide their tracks. Carefully inspect the user's Outlook for any forwarding rules, especially those that act on keywords like "invoice," "payment," or "statement." Our guide on how to stop unauthorized email forwarding rules provides detailed instructions.

  4. Check for Malicious OAuth Applications: Attackers may trick users into granting consent to a malicious third-party application. These "rogue apps" can maintain access to mailbox data even after a password reset. In Entra ID, review the "Enterprise Applications" and "App registrations" for any applications with suspicious names or permissions that were granted access around the time of the compromise.

  5. Review Deleted Items and Sent Items: Scour the user's mailbox, including the Sent Items, Deleted Items, and Recoverable Items folders. Look for emails the attacker may have sent, such as messages to perpetrate CEO fraud or vendor email compromise. Also look for phishing emails the attacker may have sent to other employees from the trusted internal account.

When Do I Need Outside Incident Response Help?

Deciding to engage an external incident response firm is a critical business decision. While your internal IT team may be skilled, specialized expertise is often required to ensure a comprehensive and defensible response.

Consider calling for help if:

  • You suspect financial loss. If a wire transfer was misdirected or funds were stolen, you need immediate, experienced guidance. Time is critical for working with financial institutions and law enforcement. We detail this in our guide to wire fraud after an email hack.
  • You suspect multiple accounts are compromised. If the compromise has spread beyond a single user, the incident is more complex than a simple account takeover. A broader investigation and remediation effort is required.
  • You need to determine notification requirements. If sensitive data (PII, PHI, financial records) was potentially accessed, you may have legal or contractual obligations to notify affected individuals or regulators. An experienced firm can help you and your legal counsel understand the scope of the breach to make an informed decision. Learn more about email breach notification requirements.
  • You lack the necessary tools or expertise. A proper investigation requires deep knowledge of the Microsoft 365 and Entra ecosystems and specialized forensic tools. If your team is unfamiliar with the Unified Audit Log, PowerShell scripting for forensics, or advanced threat hunting, an expert team like Lyra Recovery can execute a more thorough and rapid investigation.
  • The attacker is still in your environment. If you have followed the basic steps and still see signs of attacker activity, you are dealing with a persistent adversary who needs to be professionally evicted.

Frequently Asked Questions

How do I know if a Microsoft 365 account is compromised?

Common signs include user reports of being locked out, receiving unexpected MFA prompts, finding emails in their Sent or Deleted folders they didn't write, or contacts reporting strange messages from them. Our guide on the signs your business email has been hacked covers this in detail.

Can I recover funds lost to a wire transfer fraud?

Recovery is possible but never guaranteed. Success depends on acting extremely quickly. You must immediately contact your bank's fraud department and report the incident to the FBI via the Internet Crime Complaint Center at ic3.gov. The faster you act, the higher the chance of the financial institution clawing back the funds.

Is a compromised email account a data breach?

It can be. If the attacker accessed emails or files containing sensitive information—such as customer lists, employee W-2s, patient health information (PHI), or credit card numbers—it likely constitutes a data breach with legal notification requirements. The answer depends heavily on the facts and applicable laws. You can read more here: Can a Hacked Email Lead to a Data Breach?

How can I prevent this from happening again?

Prevention focuses on layered security. The single most important step is to enforce phishing-resistant MFA for all users. Beyond that, a robust security program includes user security awareness training, advanced threat protection for email, Conditional Access policies to block risky sign-ins, and regular log review. This is the core of our Business Email Compromise Recovery Guide.

What do I tell the employee whose account was hacked?

Communicate clearly and calmly. Explain what happened in simple terms, instruct them on the new password, and let them know you are investigating. Use the incident as a training opportunity later, but your immediate focus should be on securing the account and investigating the breach, not assigning blame.


Following these steps will put you on the path to recovering a compromised Microsoft 365 account. However, evicting a skilled attacker and ensuring no backdoors remain requires specialized expertise. If you have experienced a financial loss, suspect a widespread compromise, or need to determine your data breach notification obligations, it is critical to act decisively.

For expert assistance in investigating and remediating a Microsoft 365 account compromise, contact the Lyra Recovery incident response team through our recovery intake form.

microsoft 365incident responsebusiness email compromiseaccount takeoverbusiness-email-compromise

24 / 7 Recovery

When the worst day hits, every minute matters.

Our breach team is standing by — call, email, or submit a request and we respond within minutes.