What to Do About a Suspected Microsoft 365 Account Compromise
Question details
The user needs to know the correct protocol and immediate actions to take when a Microsoft 365 or Azure account is suspected of being compromised.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Experiencing multiple unexpected issues across Microsoft 365, Azure, devices, or networks that indicate a broader security incident.
- Observed behavior
- Unauthorized access and abnormal network or device activities that require immediate security containment rather than standard software troubleshooting.
Immediately isolate any affected devices by disconnecting them from your network to prevent the potential compromise from spreading. Ensure you have access to a known, completely clean device before attempting to log in and secure your accounts.
Contain the Compromise and Secure Your Account
Take immediate action to lock out unauthorized users by isolating devices and resetting your credentials from a secure environment.
When dealing with a suspected account compromise, immediate containment is critical. Do not continue normal troubleshooting on an infected device, as this can give attackers more time to access sensitive data or spread laterally across your network.
Unplug ethernet cables and disable Wi-Fi on any computer, tablet, or smartphone showing suspicious behavior to cut off the attacker's access.
Obtain a secondary, secure device that is not connected to the compromised network to perform your recovery steps.
Log into your Microsoft 365 account from the clean device and immediately change your password to a strong, unique passphrase.
Access the Microsoft 365 Admin Center or your account security settings to force a sign-out of all current active web and app sessions.
Check your Multi-Factor Authentication (MFA) settings to ensure no unauthorized phone numbers, email addresses, or authenticator apps have been added by the attacker.
Contact your tenant administrator immediately. If you suspect a widespread compromise across your organization, consult a qualified incident-response professional.

Switch to a Secure, Offline-Capable Office Alternative
If you are locked out of Microsoft 365 during a security incident, WPS Office provides a highly reliable, offline-capable alternative to keep your work moving. It offers full compatibility with Microsoft formats without relying on constant cloud connectivity.
- 1. Download the software: Visit the official WPS website from your clean device and download the free installation package.
- 2. Install locally: Run the installer and set up WPS Office on your secure machine. You can use it entirely offline.
- 3. Access your files securely: Open your existing Microsoft Word, Excel, and PowerPoint files directly in WPS Office to continue working without interruptions.

Frequently Asked Questions
What are the common signs of a Microsoft 365 account compromise?
Common signs include unexpected password reset emails, unfamiliar messages sent from your account, missing or deleted files, unrecognized devices appearing in your active sessions, and unusual inbox forwarding rules.
Can a compromised Microsoft 365 account affect Azure services?
Yes. If your compromised Microsoft 365 credentials have administrative access to Azure, attackers can potentially pivot into your Azure environment, compromise hosted resources, or escalate privileges.
How do I revoke all active sessions in Microsoft 365?
If you are an admin, log into the Microsoft 365 Admin Center, navigate to 'Active users', select the compromised user's profile, go to the 'Account' tab, and click 'Sign out of all sessions'.




