logo
search
Account Security Problems

What to Do About a Suspected Microsoft 365 Account Compromise

Steve KSteve K Oct 1, 2026 868 views

Question details

The user needs to know the correct protocol and immediate actions to take when a Microsoft 365 or Azure account is suspected of being compromised.

How to Secure a Suspected Compromised Microsoft 365 Account
Product
Microsoft 365
Device & OS
not provided
Scenario
Experiencing multiple unexpected issues across Microsoft 365, Azure, devices, or networks that indicate a broader security incident.
Observed behavior
Unauthorized access and abnormal network or device activities that require immediate security containment rather than standard software troubleshooting.
Before you start

Immediately isolate any affected devices by disconnecting them from your network to prevent the potential compromise from spreading. Ensure you have access to a known, completely clean device before attempting to log in and secure your accounts.

Solution 1Recommended

Contain the Compromise and Secure Your Account

Take immediate action to lock out unauthorized users by isolating devices and resetting your credentials from a secure environment.

When dealing with a suspected account compromise, immediate containment is critical. Do not continue normal troubleshooting on an infected device, as this can give attackers more time to access sensitive data or spread laterally across your network.

1
Disconnect affected devices

Unplug ethernet cables and disable Wi-Fi on any computer, tablet, or smartphone showing suspicious behavior to cut off the attacker's access.

2
Use a known-clean device

Obtain a secondary, secure device that is not connected to the compromised network to perform your recovery steps.

3
Change your password

Log into your Microsoft 365 account from the clean device and immediately change your password to a strong, unique passphrase.

4
Revoke active sessions

Access the Microsoft 365 Admin Center or your account security settings to force a sign-out of all current active web and app sessions.

5
Review authentication methods

Check your Multi-Factor Authentication (MFA) settings to ensure no unauthorized phone numbers, email addresses, or authenticator apps have been added by the attacker.

6
Consult professionals

Contact your tenant administrator immediately. If you suspect a widespread compromise across your organization, consult a qualified incident-response professional.

Contain the Compromise and Secure Your Account
Azure Support: For Azure-specific issues related to a security incident, the Microsoft Community may not be sufficient. Post Azure-related questions on the Azure App Service Microsoft Q&A forum.
Free Microsoft Office alternative

Switch to a Secure, Offline-Capable Office Alternative

If you are locked out of Microsoft 365 during a security incident, WPS Office provides a highly reliable, offline-capable alternative to keep your work moving. It offers full compatibility with Microsoft formats without relying on constant cloud connectivity.

  1. 1. Download the software: Visit the official WPS website from your clean device and download the free installation package.
  2. 2. Install locally: Run the installer and set up WPS Office on your secure machine. You can use it entirely offline.
  3. 3. Access your files securely: Open your existing Microsoft Word, Excel, and PowerPoint files directly in WPS Office to continue working without interruptions.
Work offline securely without relying on cloud accounts during a network compromise.Fully compatible with Microsoft Office formats, including DOCX, XLSX, and PPTX.Familiar user interface allows for a seamless and immediate transition.Lightweight design ensures fast installation on any backup or clean device.
microsoft office alternative - wps office

Frequently Asked Questions

What are the common signs of a Microsoft 365 account compromise?

Common signs include unexpected password reset emails, unfamiliar messages sent from your account, missing or deleted files, unrecognized devices appearing in your active sessions, and unusual inbox forwarding rules.

Can a compromised Microsoft 365 account affect Azure services?

Yes. If your compromised Microsoft 365 credentials have administrative access to Azure, attackers can potentially pivot into your Azure environment, compromise hosted resources, or escalate privileges.

How do I revoke all active sessions in Microsoft 365?

If you are an admin, log into the Microsoft 365 Admin Center, navigate to 'Active users', select the compromised user's profile, go to the 'Account' tab, and click 'Sign out of all sessions'.