How to Recover a Compromised Microsoft 365 Admin Account
Question details
The user needs to secure and recover a Microsoft 365 tenant after observing indicators of administrative account or tenant compromise.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Admin account or tenant compromise indicated by unexpected email accounts or missing SMS authentication codes.
- Observed behavior
- Unexpected accounts appear in the admin center, SMS authentication codes are missing, and unauthorized changes indicate a security breach.
Disconnect affected devices from the network if you suspect local malware, and ensure you have an alternative Global Administrator account ready to initiate the recovery process.
Contact Support and Contain the Account Breach
Act immediately by engaging Microsoft Support and locking down affected accounts to prevent further unauthorized access to your tenant.
As soon as you suspect a breach, immediate containment is crucial to protect your email, data, and administrative access. Because attackers might intercept authentication codes, official support intervention is highly recommended to secure the backend.
Have a Global Administrator log in using a secure account and immediately open a service request with Microsoft 365 Support to investigate the backend logs.
Reset the passwords for all affected administrator and user accounts to sever current unauthorized access.
Go to the Microsoft 365 Admin Center, locate the affected users, and revoke all active sessions to force sign-outs across all devices.
Navigate to user security settings and remove any unauthorized accounts, devices, and authentication methods added by the attacker.

Review Logs and Reconfigure Security Settings
Check for unauthorized backdoors left by attackers, such as malicious mail flow rules or elevated privileges.
Looking for a Secure, Lightweight Office Alternative?
While resolving cloud security issues with your Microsoft 365 tenant, you may need a reliable and independent productivity suite to keep your business running locally. WPS Office provides a robust, free, and lightweight alternative for editing documents securely offline.
- 1. Download and Install: Visit the official WPS website to download the free desktop application for your operating system.
- 2. Open Existing Documents: Launch WPS Office and directly open your Microsoft Word, Excel, or PowerPoint files without needing cloud authentication.
- 3. Work Securely Offline: Edit and save your documents locally on your device to maintain productivity while your cloud tenant is recovering.

Frequently Asked Questions
What are the common signs of a compromised Microsoft 365 account?
Common indicators include missing SMS authentication codes, unexpected email accounts appearing in the admin center, unrecognized mail forwarding rules in Exchange, and unusual sign-in activity from unknown geographical locations.
Can an attacker bypass SMS authentication?
Yes, attackers can intercept SMS codes through techniques like SIM swapping or SS7 exploitation. It is highly recommended to use an authenticator app or hardware token for stronger Multifactor Authentication (MFA).
How do I revoke active sessions for a user in Microsoft 365?
As a Global Administrator, go to the Microsoft 365 admin center, select the compromised user's profile, and click on 'Sign out of all sessions' in their account settings to force a sign-out across all devices and browsers.
What should I do if the only Global Administrator account is compromised and locked out?
If your only Global Admin account is locked out by an attacker, you must contact Microsoft Data Protection support by phone immediately or reach out to your federated partner/reseller to initiate emergency access recovery.




