top of page
Search

How to Verify Whether a Microsoft 365 Account Has Been Compromised

  • Hanna Korotka
  • 4 hours ago
  • 3 min read
How to Verify Whether a Microsoft 365 Account Has Been Compromised

Cybercriminals no longer need malware to compromise a business. In many Microsoft 365 incidents, attackers simply steal valid credentials and sign in like a legitimate user.


When that happens, there may be no ransomware, no antivirus alert, and no obvious warning. The first indication could be an unusual login, a suspicious email, or a report from a customer.


Knowing how to verify whether an account has actually been compromised is the first step toward an effective response.


Common Signs of Account Compromise


A single indicator does not necessarily confirm a compromise. However, several indicators occurring together should trigger an investigation.


Watch for:

  • Sign-ins from unexpected countries or regions

  • Impossible travel events

  • Logins outside normal business hours

  • MFA prompts the user did not initiate

  • Unexpected mailbox rules

  • Emails sent that the user does not recognize

  • Forwarding rules to external addresses

  • New administrator privileges

  • Password resets the user did not perform


These activities often appear before users realize anything is wrong.


Step 1: Review Microsoft Entra Sign-In Logs


The first place to investigate is the Microsoft Entra admin center.


Review:

  • Successful sign-ins

  • Failed sign-ins

  • IP addresses

  • Device information

  • Browser details

  • Authentication method

  • Conditional Access results


Ask questions such as:

  • Is the location expected?

  • Is the device recognized?

  • Was MFA successfully completed?

  • Was Conditional Access bypassed?


Unexpected patterns deserve further investigation.


Step 2: Review Mailbox Activity


A compromised mailbox is often used for Business Email Compromise (BEC).


Check for:

  • Inbox rules

  • Forwarding rules

  • Deleted audit records

  • Sent messages

  • Deleted messages

  • Delegate permissions


Attackers frequently create hidden forwarding rules so they can monitor conversations without being detected.


Step 3: Verify Administrative Changes


Review recent changes to the account, including:

  • Password resets

  • MFA method changes

  • Authentication method registrations

  • Role assignments

  • Security information updates


Changes to authentication settings are common persistence techniques.


Step 4: Review Device and Session Activity


Determine whether the user is actively using the account.


Look for:

  • Multiple simultaneous sessions

  • Unknown devices

  • Suspicious browsers

  • Long-lived refresh tokens

  • Recently registered devices


An attacker may continue accessing Microsoft 365 without repeatedly entering credentials.

 

Step 5: Correlate the Timeline


One event rarely tells the complete story.


Instead, build a timeline that includes:

  • Initial sign-in

  • MFA events

  • Mailbox activity

  • Administrative changes

  • Email activity

  • Conditional Access decisions


Understanding how these events relate to each other helps distinguish legitimate user behavior from malicious activity.

 

Don't Rely on a Single Alert


Microsoft Defender, Entra ID Protection, and Secure Score provide valuable signals, but no single alert confirms an account compromise.


Effective investigations combine evidence from multiple Microsoft 365 data sources before reaching a conclusion.

 

Respond Quickly


If you suspect an account has been compromised:

  • Revoke active sessions

  • Reset the password

  • Review MFA methods

  • Remove malicious inbox rules

  • Block suspicious sign-ins

  • Review privileged access

  • Continue monitoring the account


Early action can often prevent a minor incident from becoming a business email compromise or data breach.

 

Learn More About Microsoft 365 Investigations


Technical verification is only the first step. Effective incident response requires correlating sign-in logs, mailbox activity, Conditional Access decisions, and authentication events into a complete investigation timeline.


If you're interested in understanding how Microsoft 365 identity compromises are investigated, visit our Cleverina security and governance knowledge base. Our latest investigation guide is currently available in Spanish:


This guide explains how investigators move from individual identity and authentication events to a structured understanding of what happened during a Microsoft 365 incident.

 

About PlexHosted


PlexHosted helps organizations secure and manage Microsoft 365 environments through managed IT services, Microsoft security, compliance, and cloud operations. Whether you need assistance implementing Microsoft Defender, Microsoft Entra ID, Conditional Access, or responding to security incidents, our team can help strengthen your Microsoft 365 security posture.



 
 
 

Comments


Get the Latest News to Your Inbox

bottom of page