Response steps
- 1
Block sign-in
Stop new sign-ins with the stolen password.
- 2
Revoke all sessions
End sessions the attacker already has, including on their devices.
- 3
Reset the password and MFA methods
Remove any sign-in method the person didn't add themselves.
- 4
Remove malicious inbox rules and forwarding
Look for rules that forward, redirect, delete or hide mail.
- 5
Review app consents
Remove apps the person didn't knowingly approve, especially ones with mail access.
- 6
Check what was sent
Review sent items and the audit log for messages sent during the compromise, and warn anyone who received a fraudulent request.
- 7
Restore access
Unblock the account and help the person sign in with their new password and MFA.
- 8
Close the gap
Find out how it happened, usually phishing or a missing MFA requirement, and fix it for everyone.
Doing it with TenantWard
The compromised-account runbook runs these six containment and cleanup steps from one page, with an investigation view of where the account signed in from and what was set up. On Protect, monitoring can contain the account automatically when it spots the signs.
Questions
- Does resetting the password sign the attacker out?
- Not reliably. Existing sessions and tokens can survive a password reset. Revoke sessions as well.
See where your company stands
Check a domain for free, then connect Microsoft 365 or Google Workspace for the full checkup. Every new workspace gets a 7-day trial, no card needed.