Microsoft 365 Tenant Compromise: A Response Walkthrough

Most healthcare and senior-living organizations run on Microsoft 365: email, files, Teams, calendars and sign-in for many other apps. That makes a compromised account a serious event. A stolen password for one nurse manager's mailbox can lead to fraudulent invoices, forwarded resident information or access to shared files. A compromised administrator account can put the whole tenant at risk.

This walkthrough outlines the order of operations for a suspected account compromise. It is a general guide. If you have a cyber insurance policy or incident response retainer, contact them early, and involve your attorney if protected health information may be involved.

Signs of compromise

The user reports sign-in alerts or multi-factor prompts they did not initiate.

Colleagues or vendors receive strange emails from the account.

Inbox rules appear that forward or hide messages.

Sign-ins come from unusual locations or devices.

Unexpected app consents, new devices or changed security settings appear.

Files are accessed or shared in unusual ways.

Step 1: Assemble the team and start a log

Name an incident lead, loop in IT or your provider, and start a written timeline: who noticed what, and when. Record every action you take, because details will matter for insurance, regulators and later review.

Step 2: Contain the account

Reset the password from a trusted device.

Revoke active sessions and tokens, so the attacker is signed out everywhere. A password reset alone may not end an existing session.

Review and reset multi-factor methods. Remove any unknown phone numbers or authenticator apps the attacker added.

Block sign-in temporarily if you need time to investigate.

Disable the account for admins if you suspect higher-level compromise, and use a separate, protected emergency admin account.

Step 3: Hunt for persistence

Attackers often leave ways back in. Check for:

Mailbox rules that forward, delete or hide messages.

Forwarding addresses set at the mailbox or domain level.

Delegated access or added mailbox permissions.

Third-party app consents that grant ongoing access.

New devices registered to the user.

Newly created accounts or changes to roles and groups.

Changes to conditional access or security settings.

Remove what should not be there, and note each item in your log.

Step 4: Investigate scope

Use the audit and sign-in logs available in your Microsoft 365 plan to answer:

When did the attacker first sign in, and from where?

What did they access: mailboxes, files, shared sites?

Did they send messages, and to whom?

Did they touch other accounts?

Did any of the data include protected health information?

Log retention depends on your license, so preserve evidence quickly. Export logs and keep them in a secure location. If the scope is unclear, a forensic firm can help.

Step 5: Protect other accounts

Reset passwords for accounts the attacker may have reached.

Warn staff and partners about suspicious messages from the compromised account.

Review recent invoice or payment-change requests for fraud, and verify any bank changes by phone.

Check whether the same password was reused elsewhere.

Step 6: Assess notification duties

If protected health information was accessed or acquired, HIPAA's Breach Notification Rule may require notice to individuals and HHS, and potentially the media. A risk assessment determines whether a breach occurred. Work with counsel, and keep the 60-day outer limit in mind. Your insurer, contracts and state laws may add requirements.

Step 7: Recover and strengthen

Re-enable the account with a fresh password and verified multi-factor methods.

Require multi-factor authentication for everyone, preferably with number matching or phishing-resistant methods for administrators.

Block legacy sign-in methods that bypass modern protections.

Apply conditional access policies for location, device state and risk.

Limit administrator roles, and use separate admin accounts without mailboxes.

Enable alerts for suspicious rules, sign-ins and app consents.

Turn on and extend audit logging.

Step 8: Review what happened

Hold a short review. How did the attacker get in, and how did you notice? What took too long? Update training, policies and monitoring. Share the lessons with staff without blaming the individual.

Practice before you need it

Include a Microsoft 365 compromise in your next tabletop exercise. Confirm who can reset passwords and revoke sessions, who holds the emergency admin account and how quickly you can pull logs.

UnityCare IT helps healthcare and senior-living organizations in Oklahoma, Texas and Arkansas harden Microsoft 365 and respond when something goes wrong. If you want to check your settings before an incident, we can review them with you.

Related service

Microsoft 365, cloud storage and tested backups with access controls built in.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172