What to do when a Microsoft 365 account is hacked

Move fast, in the right order. The goal is to cut the attacker off, undo what they set up and find out what they did.

Updated October 4, 2026

Response steps

  1. 1

    Block sign-in

    Stop new sign-ins with the stolen password.

  2. 2

    Revoke all sessions

    End sessions the attacker already has, including on their devices.

  3. 3

    Reset the password and MFA methods

    Remove any sign-in method the person didn't add themselves.

  4. 4

    Remove malicious inbox rules and forwarding

    Look for rules that forward, redirect, delete or hide mail.

  5. 5

    Review app consents

    Remove apps the person didn't knowingly approve, especially ones with mail access.

  6. 6

    Check what was sent

    Review sent items and the audit log for messages sent during the compromise, and warn anyone who received a fraudulent request.

  7. 7

    Restore access

    Unblock the account and help the person sign in with their new password and MFA.

  8. 8

    Close the gap

    Find out how it happened, usually phishing or a missing MFA requirement, and fix it for everyone.

Doing it with TenantWard

The compromised-account runbook runs these six containment and cleanup steps from one page, with an investigation view of where the account signed in from and what was set up. On Protect, monitoring can contain the account automatically when it spots the signs.

Questions

Does resetting the password sign the attacker out?
Not reliably. Existing sessions and tokens can survive a password reset. Revoke sessions as well.

See where your company stands

Check a domain for free, then connect Microsoft 365 or Google Workspace for the full checkup. Every new workspace gets a 7-day trial, no card needed.