Sourcepass MCOE Blog

What Happens After a Microsoft 365 Compromise | Sourcepass MCOE

Written by Nicole Walker | Apr 16, 2026 1:00:00 PM

Most Microsoft 365 compromises follow a familiar pattern. Access beings through phishing or token theft. Persistence is added quietly. Then attackers wait before taking any financial action. 

Where many incident responses break down is not in detection. It is the assumption that a password reset ends the attack. 

Our Demystifying Microsoft episode on account compromise walks through why remediation often fails in active environments. 

Identity-based attacks rarely depend on a single credential. Once access exists, the goal shifts to keeping it. That is why activity can continue days or even weeks after remediation appears complete. 

Fully removing access requires more than a password reset. Preventing a repeat incident means addressing identity gaps inside Microsoft 365 directly. 

 

Why Password Resets Fail to Stop Microsoft 365 Attacks 

 

Modern Microsoft 365 intrusions target identity, not endpoints. The motivation is typically financial. The approach is built around persistence. 

Attackers often avoid malware entirely. Instead, they rely on identity-based techniques that remain effective even after password changes and basic MFA cleanup. 

Common techniques include: 

  • Session token theft through adversary-in-the-middle (AiTM) phishing
  • OAuth consent abuse that grants ongoing mailbox or file access
  • MFA fatigue attacks that trigger accidental approval

These access paths are covered in detail in Why Microsoft 365 Accounts Get Compromised and How to Reduce Risk. 

These methods allow continued access without repeated authentication prompts or traditional endpoint alerts. 

 

What Attackers Do After a Microsoft 365 Compromise

 

Once access is established, the objective shifts from entry to persistence. 

 

Establishing Persistence in Microsoft 365

Persistence keeps access alive even after the original credential is revoked. 

Common methods include: 

  • Inbox rules that forward, hide, or delete messages
  • External auto-forwarding to infrastructure outside the tenant
  • Additional authentication methods added after the initial compromise
  • OAuth applications that retain delegated access after consent is granted
  • Entra joining attacker-controlled devices that maintain trusted access 

OAuth app abuse is one of the most reliable persistence mechanism because delegated access survives password resets and MFA changes. 

 

Reconnaissance Inside the Mailbox

After persistence is established, attackers go quiet. They monitor communication and wait. 

What they typically watch forr: 

  • Payment approvals

  • Vendor email threads
  • Payroll communications
  • Executive correspondence timing

This phase often lasts days or weeks. Action is delayed until the timing appears safe. 

 

Financial Exploitation

When attackers act, the window is brief. 

Common outcomes include: 

  • Invoice tampering or wire redirection

  • Payroll account diversion
  • Time-delayed fraud using legitimate email threads
  • Targeting other users in the tenant with higher-value access

The FBI continues to report Business Email Compromise (BEC) as one of the highest-loss cybercrime categories year over year. 

 

What Gets Addressed Immediately After a Microsoft 365 Compromise

 

After a compromise is identified, the focus shifts to containing identity access, not just restoring a single account. 

  • Active Sessions and Authentication Risk
    The first priority is cutting off live access. This means invalidating active sessions and reviewing authentication risk signals to confirm access is no longer being granted. Static MFA alone is often insufficient at this stage. 

  • Persistent Mechanisms
    Persistence is the most common reason incidents resurface after initial cleanup. Early investigation looks for:

    • Mailbox rules and forwarding configurations 
    • Added authentication methods
    • Newly joined devices
    • OAuth applications that may still provide access 
  • Broader Tenant Exposure
    A single compromised account is rarely the full picture. Indicators such as repeated MFA prompts, similar inbox rules across users, or recent enterprise application changes are examined to determine whether access extends further into the tenant. 

  • Financial Workflows
    If the compromised account is tied to billing, payroll, or vendor communications, those workflows become an immediate concern. Activity connected to financial processes is treated as high risk until legitimacy is confirmed through secondary channels.

    Accounting controls such as ACH change verification remain a critical layer of defense against BEC.

How to Reduce the Risk of Repeat Microsoft 365 Compromise

 

Recurring compromise is most often linked to weaknesses at the identity layer, not a single failed control. 

 

MFA Quality and Approval Patterns

Push-based and SMS MFA are most common targets in fatigue attacks. Phishing-resistant MFA and number matching reduce unintended approvals by requiring more deliberate user interaction. 

 

Conditional Access Risk Signals 

Risk-based policies separate routine sign-ins from anomalous behavior. User risk and sign-in risk serve different purpose. Clear separation between the two improves visibility into suspicious authentication events. 

 

OAuth Consent and Delegated Access 

OAuth consent abuse is a reliable source of persistent access that survives credential resets.
Unmanaged or broad consent policies introduce access paths that are difficult ultimately to surface through standard alerts. 

 

External Auto-Forwarding

Outbound forwarding is a common persistence mechanism in email-based attacks. Restricting or removing forwarding eliminates one of the most common paths for silent monitoring outside the tenant. 

 

Email Threat Signals in Defender for Office 365 

Defender for Office 365 provides additional email-related signals during incident analysis. These include impersonation attempts and suspicious link or attachment activity that can clarify both how initial access occurred and what follow-on behavior looks like.

 

 

How to Tell When a Microsoft 365 Incident is Actually Contained

 

Containment means more than closing the obvious door. Look for all of the following before declaring an incident resolved:

  • No active sessions remain
  • No unauthorized inbox rules or forwarding configuration exist
  • No unknown OAuth apps retain delegated permissions
  • No repeated MFA prompts appear in sign‑in logs

Ongoing monitoring, not one‑time remediation, is what determines whether access has been fully removed. 

What Enables Ongoing Access After a Microsoft 365 Compromise

 

Microsoft 365 compromise is rarely fully contained at the moment it is detected.

Once access exists, attackers focus on persistence mechanisms that are easy to miss and hard to invalidate through basic remediation. That is why repeated access, delayed fraud, and lingering exposure remain common even after initial cleanup appears complete. 

Understanding how persistence is established, where visibility gaps exist, and why identity-based attacks continue to succeed helps explain how these incidents unfold. 

Post-incident clarity depends less on a single control and more on recognizing the patterns that allow access to persist, stay hidden, and resurface over time.

 

 

 

Related resources on Microsoft 365 Account Compromise