Skip to main content

Your First Hour After a Mailbox Compromise: Revoke, Reset, Audit

Media Your First Hour After a Mailbox Compromise Revoke, Reset, Audit

 

A compromised Microsoft 365 mailbox can become much more than an email problem.

An attacker may use it to send phishing messages, monitor invoices, create forwarding rules, steal documents, approve malicious applications or impersonate the employee in conversations with customers and colleagues.

Changing the password is necessary, but it is not enough.

The attacker may already have active tokens, registered authentication methods, mailbox rules or OAuth permissions that survive a password change. Microsoft’s current compromised-account guidance therefore combines access revocation, credential remediation, mailbox cleanup and investigation. 

The first hour should follow three priorities:

Revoke access. Reset trust. Audit the damage.

This guide provides a practical first-hour response plan for a suspected Microsoft 365 mailbox compromise.

Signs That a Mailbox May Be Compromised

Common warning signs include:

  • Unexpected messages in Sent Items
  • Colleagues receiving phishing from the user
  • Emails disappearing or moving into unusual folders
  • New forwarding or inbox rules
  • Unrecognised sign-ins
  • MFA prompts the user did not initiate
  • Unknown authentication methods
  • Replies to conversations the user never started
  • Suppliers receiving altered payment instructions
  • Sudden outbound-spam restrictions
  • Unfamiliar applications accessing the mailbox
  • Automatic replies or signatures being changed

Attackers frequently use compromised mailboxes to contact internal and external recipients, conceal replies and support business-email-compromise fraud. 

The First-Hour Incident Timeline

A disciplined response can be divided into four stages:

Time

Priority

First 10 minutes

Contain the account

10–25 minutes

Reset credentials and authentication

25–45 minutes

Remove persistence

45–60 minutes

Audit activity and determine impact

Containment should take priority over preserving the employee’s convenience.

When active fraud, mass phishing or privileged access is involved, temporarily blocking the account is usually safer than allowing continued access during the investigation.

First 10 Minutes: Revoke and Contain

1. Confirm the Correct User and Record the Incident Time

Before changing anything, record:

  • User’s full name
  • User principal name
  • Mailbox address
  • Time the incident was reported
  • Reporter’s name
  • Symptoms observed
  • Suspected phishing message or event
  • Whether the user is an administrator
  • Whether finance or payment activity is involved
  • Devices the user was using

The initial timeline will help correlate sign-ins, mailbox activity and audit events later.

Do not spend twenty minutes trying to prove the compromise before applying basic containment when the evidence is strong.

2. Block Sign-In When the Threat Is Active

Temporarily block sign-in when:

  • The attacker is sending messages
  • Fraudulent payment requests are being made
  • The account holds administrative privileges
  • The user cannot confirm recent activity
  • A malicious application appears to retain access
  • The affected device may still be compromised

Blocking sign-in prevents new authentication attempts while the investigation continues.

The user should regain access only after credentials, authentication methods, sessions and the device have been reviewed.

3. Revoke All Active Sessions

In the Microsoft Entra admin centre:

  1. Open Microsoft Entra ID.
  2. Go to Users.
  3. Select the affected user.
  4. Choose Revoke sessions.
  5. Confirm the action.

Microsoft recommends revoking user access during account compromise and warns that there may be a delay before every application and service fully reflects the revocation. Applications can also maintain their own sessions depending on how they authenticate. 

Revoking sessions is essential because changing the password alone does not guarantee that every existing token stops working immediately.

Revoke again after removing malicious authentication methods and application permissions when the incident is serious.

4. Disable or Isolate the Affected Device

If the employee entered credentials on a phishing page, opened a malicious attachment or allowed remote access, treat their device as potentially compromised.

Possible actions include:

  • Disconnect it from the network
  • Isolate it through Microsoft Defender for Endpoint
  • Disable its Entra device record temporarily
  • Ask the user to stop working on it
  • Preserve it for investigation
  • Provide a clean replacement device

Do not let the employee reset their password from a computer that may contain credential-stealing malware.

Use a known-clean administrative device or verified replacement device instead.

Minutes 10–25: Reset Credentials and Authentication

5. Reset the Password

Reset the password to a long, unique temporary value.

Do not:

  • Reuse a previous password
  • Send the password through the compromised mailbox
  • Ask the user to create a slight variation of the old password
  • Reset it from the suspicious endpoint
  • Share it through an unverified Teams conversation

Provide the temporary password through a trusted channel and require a secure change at the next sign-in where appropriate.

If the employee reused the password elsewhere, those accounts should also be reviewed.

6. Review Every Registered Authentication Method

Attackers sometimes add their own authentication method after gaining access.

Review the affected user’s:

  • Microsoft Authenticator registrations
  • Telephone numbers
  • Passkeys
  • FIDO2 security keys
  • Software tokens
  • Email recovery information
  • Temporary Access Passes

Remove anything the user cannot positively identify.

Microsoft Entra administrators can reset passwords, require MFA re-registration and revoke sessions from the user’s authentication-management controls. 

For a high-confidence compromise, it may be safer to require the user to register authentication methods again rather than trusting the existing list.

7. Re-Register MFA Securely

After removing suspicious methods:

  1. Confirm the employee’s identity through the approved help-desk process.
  2. Issue a short-lived Temporary Access Pass where appropriate.
  3. Register MFA from a clean device.
  4. Prefer a phishing-resistant method.
  5. Confirm that no old methods remain.
  6. Revoke sessions once more.

Suitable phishing-resistant methods may include:

  • Device-bound passkeys
  • FIDO2 security keys
  • Windows Hello for Business
  • Certificate-based authentication

Do not restore the account using only the same authentication method involved in the compromise without understanding how the attack succeeded.

8. Review Administrative Roles

Immediately check whether the account holds:

  • Global Administrator
  • Exchange Administrator
  • SharePoint Administrator
  • Teams Administrator
  • Security Administrator
  • Conditional Access Administrator
  • Authentication Administrator
  • Billing Administrator
  • Azure roles
  • Privileged Identity Management eligibility

Remove unnecessary active or eligible roles during the investigation.

A compromised privileged account may expose far more than its own mailbox.

Minutes 25–45: Remove Attacker Persistence

Attackers often create mechanisms that continue working after the password is changed.

This is why mailbox remediation must go beyond resetting credentials.

9. Inspect Inbox Rules

Review every mailbox rule for actions that:

  • Delete messages
  • Mark messages as read
  • Move messages into hidden or unusual folders
  • Forward or redirect messages
  • Target words such as “invoice,” “fraud,” “security” or “payment”
  • Hide replies from customers or colleagues
  • Redirect messages to an external address

Attackers commonly use rules to conceal alerts, replies and finance-related communications. Microsoft provides audit procedures for identifying who created, modified or removed mailbox rules. 

Delete malicious rules, but first record:

  • Rule name
  • Conditions
  • Actions
  • Destination address
  • Creation or modification details
  • Screenshots or exported evidence

10. Check Mailbox Forwarding

Review both user-visible rules and administrator-level mailbox forwarding.

Check for:

  • ForwardingSMTPAddress
  • ForwardingAddress
  • DeliverToMailboxAndForward
  • External forwarding through inbox rules
  • Mail-flow rules affecting the user
  • Delegates with unexpected access

Remove unapproved forwarding immediately.

A forwarding rule can continue leaking email even after the attacker stops signing in interactively.

11. Review Mailbox Delegation

Check who has:

  • Full Access
  • Send As
  • Send on Behalf
  • Folder-level permissions
  • Shared-mailbox access
  • Calendar delegation

Remove unknown or unexplained delegates.

Attackers may grant another identity access so they can return after the original user’s password is reset.

12. Review OAuth Applications and Consent

A malicious OAuth application may retain authorised access without knowing the user’s new password.

Inspect:

  • Enterprise application assignments
  • User consent grants
  • Delegated Microsoft Graph permissions
  • Applications with Mail.Read
  • Applications with Mail.Send
  • Applications with offline access
  • Newly added or unfamiliar apps

Revoke suspicious consent and disable or remove malicious service principals.

Microsoft’s guidance for illicit consent attacks recommends reviewing and revoking suspicious OAuth grants rather than relying only on password changes. 

Look especially closely at applications approved shortly before suspicious mailbox activity began.

13. Check Automatic Replies, Signatures and Connected Accounts

Attackers may alter:

  • Automatic replies
  • Email signatures
  • Reply-to information
  • Connected accounts
  • Mobile-device partnerships
  • POP or IMAP settings
  • SMTP authentication use

A malicious automatic reply may direct customers to another address or bank account.

A changed signature may include a fraudulent telephone number or payment instruction.

14. Remove Outbound-Spam Restrictions Carefully

Microsoft may restrict an account after detecting suspicious outbound email.

Do not immediately unblock the user just to restore mail flow.

First complete:

  • Session revocation
  • Password reset
  • MFA review
  • Rule cleanup
  • Consent review
  • Device investigation

Only then restore normal sending, following the appropriate Microsoft 365 restricted-user process.

Minutes 45–60: Audit the Compromise

Containment stops continuing damage. Auditing determines what has already happened.

15. Review Microsoft Entra Sign-In Logs

Examine sign-ins for at least the period surrounding the suspected compromise.

Review:

  • Date and time
  • IP address
  • Country and location
  • Application
  • Client type
  • Device
  • Operating system
  • Browser
  • Authentication method
  • MFA result
  • Conditional Access result
  • Risk detections
  • Interactive and non-interactive activity

Look for:

  • Sign-ins from unfamiliar countries
  • Unknown devices
  • Unexpected legacy clients
  • Device code flow
  • New applications
  • Sign-ins outside working hours
  • Activity continuing after the password reset
  • Policies that unexpectedly did not apply

A successful MFA result does not automatically prove the activity was legitimate. The victim may have approved the attacker’s transaction, or a token may have been stolen.

16. Search Microsoft Purview Audit

Microsoft Purview Audit can help investigate:

  • Mailbox access
  • Inbox-rule creation
  • Mail forwarding
  • Message actions
  • File access
  • Application consent
  • Administrative changes
  • Authentication-related activity

Microsoft provides specific Purview audit scenarios for investigating compromised accounts and common mailbox issues. 

Record the search date range and export relevant events before retention windows expire.

17. Use MailItemsAccessed Where Available

The MailItemsAccessed audit action can help determine whether an attacker accessed mailbox data.

Microsoft explains that this event can be used to investigate which mailbox data was accessed by mail clients and protocols, helping estimate the scope of an email-data breach. 

This can help answer:

  • Did the attacker access only the inbox?
  • Were finance conversations opened?
  • Were particular customer messages accessed?
  • Was access broad or limited?
  • Did activity continue over several days?

The exact detail available depends on licensing, audit configuration and the way the mailbox was accessed.

18. Review Messages Sent by the Attacker

Search:

  • Sent Items
  • Deleted Items
  • Recoverable Items
  • Message trace
  • Defender Explorer
  • Mail-flow logs
  • User-reported messages

Identify:

  • Internal recipients
  • External recipients
  • Links sent
  • Attachments sent
  • Payment requests
  • Requests for credentials
  • Changes to bank details
  • Messages deleted after sending

Do not assume Sent Items provides a complete record. Attackers may delete messages, use applications or employ methods that do not leave the expected visible copy.

19. Search the Tenant for Matching Phishing Messages

If the compromised mailbox sent malicious messages:

  1. Identify the subject, sender, URLs and attachments.
  2. Search for every recipient.
  3. Remove malicious copies where supported.
  4. Notify affected users.
  5. Identify anyone who clicked or replied.
  6. Investigate secondary compromises.
  7. Block the malicious domains, URLs or files.

The first compromised mailbox may be only the start of the incident.

20. Review SharePoint, OneDrive and Teams Activity

An attacker with a valid Microsoft 365 identity may also access:

  • OneDrive
  • SharePoint sites
  • Teams messages
  • Shared files
  • Customer documents
  • Internal contact lists

Look for:

  • Large downloads
  • New sharing links
  • External invitations
  • File deletions
  • Unusual search activity
  • Access to finance, HR or legal sites
  • New Teams conversations
  • Messages sent to colleagues

Microsoft’s compromised-identity incident-response guidance recommends assessing the full blast radius across email, files, collaboration tools, applications and privileged resources. 

Questions the First-Hour Audit Must Answer

By the end of the initial investigation, establish:

  • When did unauthorised access begin?
  • How did the attacker gain access?
  • Which IP addresses and devices were used?
  • Did the attacker complete or bypass MFA?
  • Were tokens or OAuth applications involved?
  • Were authentication methods added?
  • Were mailbox rules created?
  • Was forwarding enabled?
  • Which messages were read?
  • Which messages were sent?
  • Were files downloaded or shared?
  • Were payments or bank details discussed?
  • Were other accounts targeted?
  • Did the account hold privileged roles?
  • Is the affected endpoint trustworthy?

You may not answer every question during the first hour, but the investigation should be structured around them.

What to Tell the User

Ask the employee:

  • Did you enter your password on an unusual website?
  • Did you approve an unexpected MFA request?
  • Did you scan a QR code?
  • Did you enter a device code?
  • Did you install remote-support software?
  • Did you open an attachment?
  • Did you grant an application permission?
  • Did you receive warnings from colleagues?
  • Did you reuse the password elsewhere?
  • Which devices have you used recently?

Use a trusted communication channel.

Do not ask these questions through the potentially compromised mailbox or an unverified Teams chat.

What to Tell Customers and Suppliers

Notify external contacts promptly when the attacker may have sent:

  • Changed bank details
  • Fraudulent invoices
  • Payment requests
  • Malicious links
  • Requests for credentials
  • Confidential information

Contact them through a previously verified telephone number or established channel.

A useful notification should state:

  • The mailbox was compromised
  • The suspicious time window
  • Which messages should be ignored
  • That payment changes must be independently verified
  • Where to report interaction
  • The correct contact details

Avoid continuing the conversation inside the compromised email thread.

What Not to Do

Do Not Change Only the Password

Existing tokens, mailbox rules, authentication methods or OAuth permissions may remain.

Do Not Trust the User’s Device Immediately

The device may contain malware or a malicious browser extension.

Do Not Delete Evidence Before Recording It

Capture rules, forwarding addresses, consent grants and suspicious events before removing them.

Do Not Re-Enable the Account Too Quickly

Confirm that:

  • Sessions are revoked
  • Authentication methods are clean
  • Mailbox rules are clean
  • Forwarding is removed
  • OAuth consent is reviewed
  • The device is safe
  • Sign-in logs have been examined

Do Not Focus Only on Email

Check SharePoint, OneDrive, Teams, applications and administrative resources too.

Do Not Assume MFA Prevented Access

Attackers may use adversary-in-the-middle phishing, device code phishing, token theft or social engineering.

After the First Hour

The incident is not complete when the user can sign in again.

Follow-up work should include:

  • Full endpoint investigation
  • Expanded audit-log review
  • Data-access assessment
  • Regulatory and legal evaluation
  • Customer or supplier notification
  • Removal of malicious messages
  • Review of other targeted users
  • Conditional Access analysis
  • Authentication-method improvements
  • Post-incident review
  • Updated security awareness training

Where compromise is confirmed, consider requiring phishing-resistant MFA and reviewing whether unmanaged devices, legacy authentication or weak application-consent settings contributed to the attack.

First-Hour Mailbox Compromise Checklist

Revoke

  • Record the incident time.
  • Block sign-in if activity is ongoing.
  • Revoke all active sessions.
  • Isolate the affected endpoint.
  • Remove active privileged access.

Reset

  • Reset the password securely.
  • Remove unknown authentication methods.
  • Require MFA re-registration.
  • Register new methods from a clean device.
  • Prefer phishing-resistant authentication.
  • Revoke sessions again after remediation.

Remove Persistence

  • Delete malicious inbox rules.
  • Remove external forwarding.
  • Review mailbox delegation.
  • Revoke malicious OAuth consent.
  • Review connected applications.
  • Check automatic replies and signatures.
  • Review mobile and legacy access.

Audit

  • Review Entra sign-in logs.
  • Search Purview Audit.
  • Review mailbox access.
  • Trace sent phishing messages.
  • Search for affected recipients.
  • Review SharePoint, OneDrive and Teams activity.
  • Identify financial or data exposure.
  • Preserve evidence.

Final Thoughts

The first hour after discovering a mailbox compromise determines how much further damage the attacker can cause.

The response should not begin and end with a password change.

Start by revoking sessions and blocking active abuse. Reset credentials and authentication methods from a clean device. Remove inbox rules, forwarding, delegates and malicious OAuth consent. Then use Entra sign-in logs, Microsoft Purview Audit and mailbox activity to determine what the attacker accessed and who else may be affected.

The three priorities are simple:

Revoke access. Reset trust. Audit everything.

A rapid, documented response can prevent one compromised mailbox from becoming an organisation-wide phishing campaign, data breach or invoice-fraud incident.

Has a Microsoft 365 Mailbox Been Compromised?

Hamilton Group can help your business contain and investigate Microsoft 365 account compromises.

Our experts can help you:

  • Block accounts and revoke sessions
  • Reset passwords and authentication methods securely
  • Remove malicious forwarding and inbox rules
  • Investigate OAuth consent and connected applications
  • Review Microsoft Entra sign-ins
  • Search Microsoft Purview audit activity
  • Trace phishing messages and affected recipients
  • Investigate SharePoint and OneDrive access
  • Secure compromised endpoints
  • Build a documented incident-response process
  • Strengthen Conditional Access and phishing-resistant MFA

Visit hgmssp.com, call Hamilton Group on 0330 043 0069, or book a meeting with one of our experts for urgent Microsoft 365 security support.