logo
search
Account Security Problems

How to Automatically Block Compromised Microsoft 365 Accounts Sending Spam

Maira MehtabMaira Mehtab Sep 22, 2026 869 views

Question details

The user needs to automatically detect and block compromised Microsoft 365 accounts that are sending large volumes of outbound spam through Exchange Online.

Product
Microsoft 365 / Exchange Online
Device & OS
not provided
Scenario
An account takeover has occurred, resulting in the compromised account sending bulk spam messages.
Observed behavior
The compromised account sends outbound spam, which can damage the organization's email reputation if not automatically restricted and blocked.
Before you start

Ensure you have Exchange Administrator or Security Administrator privileges in your Microsoft 365 tenant to modify outbound spam policies and investigate compromised user accounts.

Solution 1Recommended

Configure Outbound Spam Policies in Defender

Set up Microsoft Defender for Office 365 outbound spam policies to detect suspicious activity and automatically restrict users from sending further emails.

Microsoft 365 uses outbound spam policies to monitor the volume and content of outgoing messages. By configuring these policies, you can automatically block accounts that exceed your defined thresholds.

1
Access Microsoft Defender

Log in to the Microsoft 365 Defender portal and navigate to the Email & Collaboration section, then select Policies & Rules.

2
Edit Outbound Spam Policies

Go to Threat policies, click on Anti-spam, and select the Anti-spam outbound policy (Default) or create a custom policy.

3
Set Sending Limits

In the policy settings, define the limits for external, internal, and total messages per hour or day.

4
Configure Restriction Actions

Under 'Action when a user exceeds the limits', choose 'Restrict the user from sending mail' to automatically disable their sending capabilities.

Web Browser Issues: If you encounter network fluctuations or formatting issues while configuring these policies online, try opening the Defender portal in an InPrivate or Incognito browsing window.
Free Microsoft Office alternative

Looking for a Secure, Lightweight Office Suite? Try WPS Office

While resolving enterprise Exchange Server issues requires complex admin configurations, your daily document tasks shouldn't be difficult. WPS Office is a fast, lightweight, and free alternative to Microsoft Office, offering robust local document security and seamless compatibility with Word, Excel, and PowerPoint files.

  1. 1. Download WPS Office: Visit the official WPS Office website and download the free installation package.
  2. 2. Install the Suite: Run the installer and follow the on-screen instructions to set up WPS Office on your device.
  3. 3. Open Your Documents: Launch WPS Office and instantly open your existing Microsoft Office files without any formatting loss.
Fully compatible with Microsoft Office formats (DOCX, XLSX, PPTX).Secure built-in local document encryption to protect sensitive data.Lightweight and fast, utilizing minimal system resources.All-in-one suite combining documents, spreadsheets, presentations, and PDFs in a single window.
microsoft office alternative - wps office

Frequently Asked Questions

What happens when Microsoft 365 restricts a user for sending spam?

When restricted, the user can still sign in and receive emails, but all outgoing messages will be blocked and bounce back with a Non-Delivery Report (NDR). An administrator must manually unblock the account from the Restricted users portal.

Can I prevent legitimate bulk emails from triggering the spam policy?

Yes. If your organization legitimately sends bulk emails, you should route them through a dedicated third-party bulk email service rather than using standard Exchange Online mailboxes, which are strictly monitored by Defender outbound spam policies.

How can I tell if an email account has been compromised?

Signs of compromise include unexpected rules in the mailbox forwarding emails externally, unusual sign-in locations in Entra ID logs, missing sent items, and alerts from Defender regarding anomalous sending patterns.