How to Verify Whether a Microsoft 365 Account Has Been Compromised
- Hanna Korotka
- 4 hours ago
- 3 min read

Cybercriminals no longer need malware to compromise a business. In many Microsoft 365 incidents, attackers simply steal valid credentials and sign in like a legitimate user.
When that happens, there may be no ransomware, no antivirus alert, and no obvious warning. The first indication could be an unusual login, a suspicious email, or a report from a customer.
Knowing how to verify whether an account has actually been compromised is the first step toward an effective response.
Common Signs of Account Compromise
A single indicator does not necessarily confirm a compromise. However, several indicators occurring together should trigger an investigation.
Watch for:
Sign-ins from unexpected countries or regions
Impossible travel events
Logins outside normal business hours
MFA prompts the user did not initiate
Unexpected mailbox rules
Emails sent that the user does not recognize
Forwarding rules to external addresses
New administrator privileges
Password resets the user did not perform
These activities often appear before users realize anything is wrong.
Step 1: Review Microsoft Entra Sign-In Logs
The first place to investigate is the Microsoft Entra admin center.
Review:
Successful sign-ins
Failed sign-ins
IP addresses
Device information
Browser details
Authentication method
Conditional Access results
Ask questions such as:
Is the location expected?
Is the device recognized?
Was MFA successfully completed?
Was Conditional Access bypassed?
Unexpected patterns deserve further investigation.
Step 2: Review Mailbox Activity
A compromised mailbox is often used for Business Email Compromise (BEC).
Check for:
Inbox rules
Forwarding rules
Deleted audit records
Sent messages
Deleted messages
Delegate permissions
Attackers frequently create hidden forwarding rules so they can monitor conversations without being detected.
Step 3: Verify Administrative Changes
Review recent changes to the account, including:
Password resets
MFA method changes
Authentication method registrations
Role assignments
Security information updates
Changes to authentication settings are common persistence techniques.
Step 4: Review Device and Session Activity
Determine whether the user is actively using the account.
Look for:
Multiple simultaneous sessions
Unknown devices
Suspicious browsers
Long-lived refresh tokens
Recently registered devices
An attacker may continue accessing Microsoft 365 without repeatedly entering credentials.
Step 5: Correlate the Timeline
One event rarely tells the complete story.
Instead, build a timeline that includes:
Initial sign-in
MFA events
Mailbox activity
Administrative changes
Email activity
Conditional Access decisions
Understanding how these events relate to each other helps distinguish legitimate user behavior from malicious activity.
Don't Rely on a Single Alert
Microsoft Defender, Entra ID Protection, and Secure Score provide valuable signals, but no single alert confirms an account compromise.
Effective investigations combine evidence from multiple Microsoft 365 data sources before reaching a conclusion.
Respond Quickly
If you suspect an account has been compromised:
Revoke active sessions
Reset the password
Review MFA methods
Remove malicious inbox rules
Block suspicious sign-ins
Review privileged access
Continue monitoring the account
Early action can often prevent a minor incident from becoming a business email compromise or data breach.
Learn More About Microsoft 365 Investigations
Technical verification is only the first step. Effective incident response requires correlating sign-in logs, mailbox activity, Conditional Access decisions, and authentication events into a complete investigation timeline.
If you're interested in understanding how Microsoft 365 identity compromises are investigated, visit our Cleverina security and governance knowledge base. Our latest investigation guide is currently available in Spanish:
• Cómo investigar un compromiso de Microsoft Entra ID paso a paso (available in Spanish)
This guide explains how investigators move from individual identity and authentication events to a structured understanding of what happened during a Microsoft 365 incident.
About PlexHosted
PlexHosted helps organizations secure and manage Microsoft 365 environments through managed IT services, Microsoft security, compliance, and cloud operations. Whether you need assistance implementing Microsoft Defender, Microsoft Entra ID, Conditional Access, or responding to security incidents, our team can help strengthen your Microsoft 365 security posture.





Comments