What to Do When a Microsoft 365 Account Is Compromised at Your Business
A password reset does not remove an attacker from a compromised Microsoft 365 mailbox. Here is the order operations actually has to follow, and the legal clock that starts.
Your controller calls you on a Tuesday morning and says something is wrong with her email. Messages she never opened are marked as read. A client replied to a thread she does not remember starting. There is a sent message to a vendor she has not spoken to in a year, and it is asking that vendor to update banking details.
You do what almost every business owner does. You reset her password, you tell her to change it on her phone too, and you get back to running the company. And in most of the cases we get called into, the attacker is still reading her mail an hour later.
That is the part nobody explains to non-technical decision makers. A compromised Microsoft 365 account is not a password problem that a password fixes. It is an access problem, and access can survive a password change. What follows is the plain-English version of what actually has to happen, in what order, and where businesses in McKinney and across Collin County lose this fight before they even understand they are in one.
Why Resetting the Password Does Not Kick the Attacker Out
When you log into Microsoft 365 in the morning, you type a password and you approve a prompt on your phone. Microsoft then hands your laptop something called a session token. A session token is a small file that says "this person already proved who they are, let them keep working without asking again." It is the reason you are not typing your password every twenty minutes.
Attackers figured out that stealing the token is better than stealing the password. If they hold a valid session token, they never see a login screen and they never trigger your multi-factor prompt, because from Microsoft's point of view they are not logging in at all. They are already logged in. We covered how attackers get those tokens in our guide to how attackers bypass multi-factor authentication, and 2026 has made it worse. Several of the server flaws that hit the news this summer let an attacker steal the cryptographic keys a company's own server uses to sign those tokens, which means the attacker can manufacture valid tokens on demand for any account they want. No password, no prompt, no failed login for anyone to notice.
So when you reset the password, you have closed one door. The token in the attacker's browser is a different door, and it stays open until somebody explicitly revokes it. On a default Microsoft 365 setup, that revocation can take up to an hour to take effect even after you trigger it, and nobody triggers it if they do not know it exists.
This is the single most common failure we see. The business believes it handled the incident on Tuesday morning. The attacker is quietly reading the accounts payable thread until Friday, when the wire goes out.
The First Hour and What Actually Has to Happen
There is a correct order to this, and the order matters more than the speed.
First, you revoke every active session for that account, not just the password. In Microsoft 365 this is a specific administrative action that invalidates the tokens, and it is the step that actually removes the attacker's hands from the keyboard. Second, you reset the password to something the user has never used anywhere else. Third, and this is the step most businesses skip, you delete and re-register the multi-factor authentication methods on that account. Multi-factor authentication simply means proving who you are with a second thing beyond a password, usually a code or an approval on your phone. If the attacker had control of the mailbox for even a few hours, they may have quietly added their own phone number or authenticator app as an approved second factor. Reset the password without clearing that, and you have handed them a permanent, legitimate way back in that will pass every security check you have.
Fourth, you check whether the account has administrative rights, and you check what the account could reach. A compromised mailbox belonging to a receptionist is a bad day. A compromised mailbox belonging to your controller, your office manager, or anyone with global administrator rights in Microsoft 365 is a company-wide event, because that account can create new accounts, disable logging, and grant itself access to every other mailbox in the tenant.
Fifth, and only now, you tell the user they can go back to work. Not before. We have watched businesses in Plano put a user back on a laptop that still had the attacker's tooling on it, which re-stole the new credentials within the hour.
Everything above assumes you know the compromise happened. That assumption is the weak point, and it is why continuous monitoring through a managed security operations center changes the math. A security operations center, or SOC, is a team of analysts watching your systems around the clock. The difference is not that they know a better password reset procedure. The difference is that they see the impossible login from two countries in nine minutes at 3 a.m. on a Sunday, and they revoke the session before the mailbox rules ever get written.
The Hidden Changes an Attacker Leaves Behind
An attacker who gets into a business mailbox almost never just reads mail. They set up persistence, which means they make changes designed to keep giving them value after they lose access. You have to go find those changes by hand, and there are four places to look.
Mailbox forwarding rules come first. The attacker creates a rule that quietly copies every incoming message to an outside address. Do this well and you get the flow of the business forever, even after you are locked out. The rules are usually named something forgettable like a single period or a single letter so they do not catch the eye in a list.
Inbox rules that hide evidence come second. A favorite pattern is a rule that takes any message containing the words invoice, wire, payment, or bank and files it into a rarely-opened folder such as RSS Subscriptions. Now the attacker sees the accounting conversation and the real employee does not. This is the mechanic that makes business email compromise and wire fraud work, and it is why the fraud usually surfaces after the money is gone rather than before.
Third-party application consent comes third, and it is the one almost nobody checks. Microsoft 365 lets an outside application request ongoing permission to read a user's mail. If your employee ever clicked approve on a convincing-looking prompt, that application keeps its access after the password reset, after the session revocation, and after the multi-factor reset, because it was granted separately and legitimately. It has to be revoked as its own step.
Delegate and shared-mailbox access comes fourth. An attacker in an administrative account can grant a low-profile user account permission to read the executive mailbox. Reset the executive, miss the delegate, and the exposure continues from a direction nobody is watching. Shared mailboxes deserve extra attention because they frequently have no owner, no multi-factor enrollment, and no one who would notice anything unusual. We walked through that whole category of gaps in our Microsoft 365 security gaps guide.
What Your Audit Log Will and Will Not Tell You
Now you need to answer the question your attorney, your insurance carrier, and your biggest client are all going to ask. What did they see, and for how long.
That answer lives in the Microsoft 365 audit log, and here is the problem that surprises people. In a lot of tenants, the detailed mailbox activity logging that would tell you which individual messages were opened is not turned on by default, and it is not retroactive. Turning it on today tells you nothing about last month. Depending on the license your business bought, retention may be ninety days rather than a year, so an intrusion that started in March may already be unanswerable in July.
That gap is not a technicality. It is the difference between telling a client "we confirmed the attacker never opened the folder containing your data" and telling them "we cannot rule it out." Those two sentences produce very different outcomes for your contract, your reputation, and your legal exposure, and you do not get to choose which one you say. The logging configuration you set up months ago chose for you.
If you take one preventive action from this article, make it verifying that audit logging is enabled and retained in your tenant right now, while nothing is on fire. It costs nothing and it is the evidence base for every question that follows an incident. It is a standard part of the tenant review we run during a security assessment.
How You Determine Whether Data Actually Left
There is a meaningful difference between an attacker reading email and an attacker taking data, and your notification obligations often hinge on it.
You look for volume and pattern. Large numbers of messages accessed in a short window, an unusual export or archive operation, a sudden download of a shared document library, a spike in traffic to an address nobody recognizes. You also look outside your own walls. If credentials or company files from the incident show up for sale, that is direct evidence of exfiltration, and it usually appears in criminal marketplaces before it appears anywhere you would think to look. This is the practical case for dark web monitoring, which watches those markets for your domain and your employee credentials so the discovery is not left to chance.
Two more things belong in this phase. Confirm your backups are intact and, more importantly, that you have restored from them recently enough to know they work. Mailbox and file recovery after a destructive incident is a very different experience depending on whether anyone ever tested the backup and recovery process. And review whether the entry point was actually the mailbox at all. In a meaningful share of the cases we handle, the mailbox was the second stop, and the first was an unpatched server or an exposed remote access service. Finding that entry point is what penetration testing and continuous vulnerability management through CyberSphere are for, because closing the mailbox while leaving the front door open just resets the clock.
The Legal and Insurance Clock That Starts the Moment You Know
Here is where the technical event becomes a business event, and where the costs stop being hypothetical.
Texas requires notification to affected individuals without unreasonable delay and no later than sixty days after determining that a breach of sensitive personal information occurred, and notification to the Attorney General when the count reaches two hundred fifty Texas residents. If your business handles medical information, protected health data carries its own federal timeline. If you serve clients under contract, read your agreements, because many of them impose a notification window measured in days, sometimes as few as three, and that clock frequently runs faster than the statutory one. Regulated industries add another layer, which we cover under compliance.
Your cyber insurance policy has its own requirements, and they are stricter than most owners realize. Many policies require notice to the carrier within a short window and require you to use their approved incident response vendor. Bring in your own consultant first, do the cleanup yourself, and you may have complicated or voided the claim on the largest expense of the entire event. Call the carrier early, even when you are not sure yet whether you have a reportable incident.
Then there is the cost you cannot insure against. A twenty-person firm in Frisco that has to email three hundred clients explaining that a mailbox containing their financial documents was accessible to a stranger for six weeks does not lose money on the remediation invoice. It loses money on the four clients who quietly do not renew, and on the two years it takes for referrals to recover. Downtime is measured in hours. Trust is measured in quarters.
Why Businesses Lose This Fight at Two in the Morning
Read back through the sequence. Revoke sessions, reset credentials, clear and re-enroll the second factor, audit administrative rights, hunt four categories of persistence, preserve and interpret the audit log, determine exfiltration, notify the carrier inside its window, and calculate your notification obligations against both state law and every client contract you have signed. Then do all of it correctly, in order, under time pressure, most likely on a weekend, because attackers deliberately work when your office does not.
That is not a reasonable expectation for an office manager with a help desk phone number, and it is not what most general IT support is set up to deliver. Standard managed IT keeps systems running and users working, which is genuinely valuable and genuinely different from intrusion response. We drew that line clearly in our comparison of MSP monitoring versus a managed SOC. If your current provider is strong on operations, the answer is usually not replacing them. It is adding a security layer alongside them, which is exactly how our MSP integration work is structured.
The businesses that come out of a Microsoft 365 compromise cleanly have three things in place beforehand. They have someone actually watching, so the compromise is caught in hours instead of the industry-typical weeks. They have email security controls that make the initial theft harder, including hardened sign-in rules that reject a session from an unmanaged device or an unexpected country. And they have a written response plan that names who calls the insurance carrier and who calls the attorney, so nobody is improvising the legal sequence at 2 a.m. Our guide to the first twenty-four hours after an attack is a reasonable starting template for that document.
The businesses that come out of it badly are not less careful people. They are people who found out on Tuesday, believed a password reset settled it, and learned six weeks later from a client that it had not.
Get a Plan Before You Need One
If you suspect a Microsoft 365 account in your business is compromised right now, stop reading and call us at 512-518-4408. Session revocation is time-sensitive in a way that almost nothing else in your technology stack is.
If nothing is wrong today, this is the cheap moment to act. We will review your Microsoft 365 tenant for the specific gaps described above, confirm your audit logging is on and retained, check for forwarding rules and application consents that should not be there, and give you a written response sequence you can hand to your team. Start with a security assessment, or contact our McKinney office and we will talk through where your business actually stands. We work with companies throughout Collin County, from McKinney to Allen, and across the wider DFW area, and we would rather meet you before the Tuesday morning phone call than after it.
Need Help With This?
Innovation Network Design helps businesses across McKinney, Dallas, and nationwide with expert cybersecurity services.
Mark Sullivan
Innovation Network Design
With nearly a decade in cybersecurity and IT infrastructure, our team delivers expert insights to help businesses in McKinney, Dallas, and across DFW make informed security decisions. Have a question? Get in touch.
Ready to Secure Your Business?
Get a free security assessment and find out where your organization stands.