Home › Services › Incident response and hardening
Security · when prevention has already failed
Microsoft 365 account-compromise response, investigation and tenant hardening
Sessions revoked within the hour; a timeline you can hand to the insurer, the regulator and the customers who received the fraudulent mail; every backdoor the attacker left found and removed; and then the Conditional Access, device and Defender settings that would have ended the attack at the first replayed token — configured in report-only mode first, so nobody is locked out.
Why
The takeover we see most often does not defeat a control. A proxied sign-in page captures a legitimate session token, the attacker replays it from another country, registers their own authenticator within a minute, reads the mailbox for days and then answers customers’ questions from inside real threads. A password reset alone does not end it. What ends it is the order of the steps, the evidence the tenant kept, and the settings that were never switched on. The field report, hour by hour →
Every session revoked first, because a reset does not invalidate a stolen token. Password reset delivered out of band. Every MFA method removed and re-registered, including the device the attacker added. Sign-in blocked until the account and the endpoint are clean. The phishing message purged from every mailbox, the sender and the URL blocked, the other recipients found.
Message trace for what was sent and received and from which addresses. Entra sign-in logs, interactive and non-interactive, for the moment the token was stolen and every replay. Entra audit logs for the new authenticator, consents and forwarding. Purview audit for what was read, searched, deleted and downloaded. One timeline, one time zone, written down.
The controls that would have ended this attack at the first replay, configured for your tenant in report-only mode first: managed devices required, MFA registration protected, phishing-resistant sign-in for administrators and finance, legacy authentication blocked, sign-in locations restricted, Defender settings and alerting. Then switched on, one policy at a time, with a rollback.
What we do
Half of it is technical. The other half is the documents and calls that decide how the incident is remembered by the people who matter: the insurer, the supervisory authority and the fifty customers who got a fraudulent invoice.
Hidden inbox rules, external forwarding, delegate and send-as rights, mobile devices, OAuth application grants, sharing links created in OneDrive, new security-info registrations. Several of these survive a password reset, which is why a reset alone is not containment. Each one found, removed and recorded.
The whole tenant searched for the attacker’s addresses and the lure’s subject line, because one compromised account is rarely the only target. Every account that received the same message checked; every account that talked to the attacker’s sessions reviewed.
What was exposed, to whom, and whether it is a notifiable personal-data breach under GDPR — seventy-two hours from awareness. We prepare the assessment with the evidence from the logs so that your data-protection officer or legal adviser decides on facts, and we document the reasoning either way.
Who received fraudulent mail and who replied to it; a call script for the ones who replied; a fresh email, never a reply in the hijacked thread, for the rest; a note to the partner whose mailbox sent the lure, who usually has no idea. Drafted with you, sent by you.
If the attacker returns after a reset, the machine is the problem: an infostealer harvesting browser sessions. The device is checked in Defender, isolated and, if there is any doubt, reimaged through Intune rather than cleaned.
The two rules that stop the money leaving even when everything else fails: any change of bank details is verified by phone on a number already on file, and payments over a threshold need two people. Written for finance, agreed with the owner, and nobody is ever criticised for making the call.
The hardening
Each policy is created in report-only mode, run for a week against real sign-ins so that the report shows who would have been blocked, adjusted, and then enforced. Nobody is locked out of their own tenant by a security project.
Access to mail and files only from devices enrolled in Intune or joined to the domain. A token stolen from a compliant device is useless on the attacker’s own machine. The single most effective control, and it ends the case above at the first replay.
Registering or changing authentication methods allowed only from a trusted network or a compliant device. This stops the attacker’s own authenticator appearing on the account sixty seconds after the theft.
Passkeys, FIDO2 keys and Windows Hello are bound to the site they were registered for; a proxy page cannot replay them. Administrators and finance first, everyone else on a schedule.
The protocols that cannot do MFA are the usual entry for password spray. Blocked for every user and every application, with the exceptions written down.
Sign-in restricted to the countries you operate in, with a documented travel process; unmanaged devices get web-only access, no downloads and short sessions.
Safe Links, Safe Attachments and impersonation protection; zero-hour auto purge; external forwarding disabled; user consent to applications restricted; alerts on new MFA registrations, new inbox rules, anonymous or impossible-travel sign-ins and unusual sending volume, routed to someone who reads them.
The response works with whatever the tenant has. The hardening needs Entra ID P1 for Conditional Access and Intune for device compliance — both inside Business Premium and Microsoft 365 E3; on Business Standard and the Office 365 plans they are add-ons. Risk-based policies that block a suspicious sign-in on their own, and privileged identity management, come with Entra ID P2, in E5 or as an add-on.
Evidence is the part people discover at the worst moment. Standard auditing now records mailbox access, sends and searches for every licence, but the retention is a hundred and eighty days; Audit Premium keeps a year and adds the finer events. Sign-in logs are kept for seven days without Entra ID P1 and thirty with it. Investigation tooling — threat explorer, automated investigation — is Defender for Office 365 Plan 2. None of it can be bought back after the fact: what the tenant was keeping before the incident is what there is to read.
Same day
If it is happening now, call the number in the header and we start on the containment while the paperwork catches up. If it is not, tell us the headcount and the plan you are on, and we quote the hardening with the report-only week included.