Business Email Compromise Response for Microsoft 365
If a mailbox, login, or user account looks compromised, we help Sydney businesses contain it promptly. Revoke sessions. Reset access. Remove the persistence mechanisms attackers leave behind. We'll document our response so you know what happened and what to do next.
This is focused containment for Microsoft-first businesses on Microsoft 365, not a generic cyber security discussion.
Microsoft 365, Entra ID, Exchange Online, Teams, SharePoint, and OneDrive coverage
Focused on quickly containing the incident
Built for small and mid-sized Microsoft-first businesses
What Attackers Do After Getting In
- Stay signed in: Resetting the password doesn't kill active sessions. Refresh tokens keep the attacker authenticated for hours or days.
- Hide their activity: Inbox rules named “.” forward mail externally or delete security alerts on arrival. These survive a password reset.
- Plant persistence: OAuth app consents, registered devices, MFA method changes. Secondary access paths to get back in after you reset the password.
- Move laterally: Teams messages, SharePoint files, OneDrive, shared mailboxes. If they had admin privileges, the exposure widens significantly.
A password reset alone is not enough. You need to revoke sessions, check for persistence, and review the full scope of what was accessed.
Why a Compromised Mailbox Is Not Just an Email Problem
Most businesses think they've taken care of a compromised account once they reset the password. That is not the case.
If an attacker got in through a phishing link or a stolen credential, they've probably done more than read a few emails. Here's what we commonly find when we investigate:
- The attacker is still signed in: Resetting a password doesn't kill active sessions. If the attacker authenticated before the reset and grabbed a refresh token, they can stay signed in for hours or days afterwards. You need to revoke sessions explicitly.
- Inbox rules are hiding activity: Attackers create forwarding rules that copy inbound email to an external address or set up rules that move specific messages into a folder the user never checks. These rules survive a password reset.
- Repercussions extend beyond the mailbox: A compromised M365 account also gets access to Teams messages, SharePoint files, and OneDrive documents. If they had admin privileges, the exposure widens significantly and requires further escalation.
- Devices may be affected: If the compromise came through a phishing link clicked on a company laptop, cached credentials, browser sessions, and saved passwords may be affected.
- The attacker may have planted persistence: OAuth app consents, registered devices, MFA method changes. Attackers often create secondary access paths to regain entry.
What We Contain First
We get on a phone call (15 minutes, usually less), confirm what you're seeing, and start working.
Immediate Actions
- Account Restriction and Session Kill: Disable or restrict the affected account. Revoke all active sessions and refresh tokens.
- Password and MFA Review: Reset the password and review registered MFA methods to ensure the attacker hasn't added their own.
- Mailbox Inspection: Check for inbox rules that forward mail externally or hiding messages, review sent items and deleted items for signs of outbound phishing.
- Entra Sign-In Review: Review sign-in logs and risk signals from Entra ID.
- Broader Tenant Check: Review OAuth app consents, connected applications, and admin role assignments.
- Device Assessment: Check compliance state for managed devices and trigger actions like wipe, retire, or lock as needed.
- Written Summary: Get a written summary of what happened, what we did, and the findings.
When This Service Fits
- A user clicked a phishing link and entered their credentials.
- A mailbox is sending email the user didn't write.
- Microsoft sent you a security alert for a potentially compromised account.
- You suspect the attacker might still have access.
- Leadership requires documentation of the incident.
What You Receive
- An urgent response and scoping call (same-day, often within hours).
- Containment actions executed in your M365 tenant.
- A confirmed checklist of every action completed during the initial response.
- A short findings summary covering what happened and what was accessed.
- Follow-up recommendations if broader remediation is needed.
M365 Breach Containment First. Then Broader Remediation Second.
What's included in the initial response
- Account restriction and session revocation
- Mailbox and identity review
- Persistence checks in M365
- Managed-device actions where Intune is already in place
- Written findings summary
What may need following up
- Full digital forensics for complex compromises.
- Endpoint investigations beyond what is visible.
- Third-party SaaS compromise reviews.
- Tenant-wide security hardening and awareness training.
Pricing
Fixed-fee for standard Microsoft 365 environments. Scope confirmed on the call.