incident-response-strategies

Microsoft 365 Account Takeover Recovery, Step by Step

Resetting the password does not evict an attacker from Microsoft 365. Here is the full eviction sequence, in the order that actually works.

Cyber Solutions engineersSeptember 16, 20266 min read

A password reset is the step everyone takes first and the step that fixes the least. An attacker holding a valid refresh token, a mailbox rule, and a consented application keeps working long after the password changes. Eviction takes all of the following, in order.

1. Reset credentials and revoke sessions

Change the password from a clean device, then revoke all active sessions and refresh tokens for the account. Until tokens are revoked, the attacker session survives the reset.

2. Remove attacker persistence in the mailbox

  • Delete forwarding addresses at both the mailbox and rule level.
  • Look for inbox rules that move mail to RSS Feeds, Archive, Notes, or a rule with a blank or single-character name. That is the classic hiding spot.
  • Check mailbox delegates and full access permissions added during the attacker window.

3. Pull OAuth application consents

This is the step most often missed. An attacker who talked the user into consenting to an application keeps mailbox access through that application even after every password and token change. Review enterprise applications and user consents granted during the incident window and revoke anything unrecognized.

4. Rebuild multi-factor authentication

Remove every authentication method registered on the account and re-enroll from scratch. Attackers routinely add their own phone number or authenticator app so they can walk back in through the front door.

5. Reconstruct what happened

Unified audit log and sign-in log data tell you which sessions were attacker-controlled, what was searched, what was downloaded, and what was sent. This is what your exposure scoping and any notification decision rest on, so pull it before retention windows close. Reporting duties are covered in our guide to a compromised business email.

6. Close the door behind you

Conditional access policies that block legacy authentication, require compliant devices, and challenge risky sign-ins stop the same attack path from working twice. Pair that with phishing-resistant authentication through identity and access management and tenant hardening through Microsoft 365 management.

Google Workspace follows the same logic with different menus: reset, sign out all devices, remove filters and delegates, revoke connected apps and app passwords, rebuild two-step verification, then audit the login history.

Related services

Get started

Ready to make IT a strategic advantage?

Get a 30-minute call with our sales or support team. No pitch. Just a real assessment of where your IT and security stand today.