How to Secure Your Microsoft 365 Account After a Phishing Email
Question details
The user received a suspicious email requesting Microsoft 365 and university credentials and needs to know how to secure their potentially compromised accounts.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Identifying a phishing scam and responding to compromised personal or banking credentials.
- Observed behavior
- Receiving urgent emails requesting sensitive information like passwords or financial details via suspicious links, putting the user's account and data at risk.
Do not click on any links or download attachments from the suspicious email. If you have already entered your credentials, ensure you use a trusted and secure device to perform the following recovery steps.
Reset Passwords and Enable Multi-Factor Authentication
Take immediate action to lock out unauthorized users and secure your Microsoft 365 or university accounts.
If you suspect your credentials have been compromised, the most critical step is to revoke the attacker's access by changing your passwords and adding a secondary layer of security.
Open a new browser window and type in the official Microsoft 365 login URL or your university's official portal. Navigate to your account settings and change your password to a strong, unique combination.
In your Microsoft 365 Security settings, turn on MFA (also known as Two-Step Verification). This requires a code sent to your phone or authentication app, blocking attackers even if they have your password.
Go to the 'My Sign-ins' section of your Microsoft account dashboard. Review the recent login locations and flag any unrecognized devices or IP addresses to ensure no unauthorized sessions are active.

Report Phishing and Secure External Accounts
Handle the malicious email properly and protect any financial data that may have been exposed.
Switch to WPS Office for a Secure, Lightweight Experience
While resolving online account security issues with Microsoft 365, consider exploring WPS Office as a free, lightweight alternative for your local document needs. It offers robust offline capabilities, ensuring your sensitive files stay on your device without relying on constant cloud syncing.
- 1. Download WPS Office: Visit the official WPS website to download the free installation package for your operating system.
- 2. Install and Launch: Run the installer and open WPS Office to access Writer, Spreadsheet, and Presentation tools securely.
- 3. Open existing files: Double-click your existing Microsoft Office files to seamlessly open and edit them offline in WPS Office.

Frequently Asked Questions
How can I tell if an email from my university is actually a phishing scam?
Official university or Microsoft emails will never ask for your password directly via an email link. Look for red flags such as generic greetings, urgent threats of account closure, misspelled sender addresses, and mismatched URLs when you hover your cursor over links.
Will Microsoft support contact me via email to verify my credentials?
No, Microsoft will never proactively contact you to ask for your password, verification codes, or personal information. Any email or phone call initiating contact and requesting this data is a scam.
What should I do if the hacker already changed my Microsoft 365 password?
If you are locked out and cannot reset the password yourself, you must contact your university's IT administrator or Microsoft 365 business support by phone immediately. They have the administrative tools required to override the hacker and restore your access.
Can I recover data if it was deleted by the attacker after a phishing breach?
Yes, in many cases, IT administrators can recover deleted emails or OneDrive files from Microsoft 365 within a certain retention window (usually 14 to 30 days). Report the breach to your admin as soon as possible to maximize the chance of data recovery.




