How to spot Microsoft 365 account takeover
A taken-over mailbox rarely looks broken. The owner still gets most of their mail. The tell is usually a small settings change they didn't make.
The signs worth checking
| Sign | Why attackers do it | Audit operation to search |
|---|---|---|
| New inbox rule that moves, deletes or marks mail as read | Hide replies from the real owner while a fake invoice thread runs | New-InboxRule, Set-InboxRule |
| Forwarding to an outside address | Keep a copy of everything, even after a password change | Set-Mailbox (forwarding fields), forwarding rules |
| Sign-in from a new country, ISP or device | Shows the account is in use by someone else | UserLoggedIn, Entra sign-in logs |
| Many failed sign-ins, then a success | Password spraying that finally landed | Entra sign-in logs |
| Mailbox permission granted to another account | Read the mailbox from a different login | Add-MailboxPermission |
| New MFA method or admin role | Stay in after the reset, or take the whole tenant | MFA registration and role-change events |
| OAuth app consent the user doesn't recognize | App access that skips the password entirely | Consent to application |
Where to look
Microsoft Purview's audit search and the Entra ID sign-in logs hold these records. The trouble for a small business isn't access, it's attention. A log nobody reads on a schedule isn't monitoring. More detail on reading them: Microsoft 365 audit logs explained.
Your options for watching
| Approach | Effort | Cost |
|---|---|---|
| Check Purview and sign-in logs by hand | High. Needs a named person and a schedule. | Included with your plan |
| Microsoft's built-in alert policies | Medium. Alerts often go to an admin inbox nobody reads. | Included, with more in higher tiers |
| MSP with a managed SOC or MDR | Low for you | Varies by provider |
| InboxGuards | Low. Read-only connect, then alerts land on a dashboard, and critical ones are emailed to you. | $2/user/mo or $20/user/yr |
InboxGuards reads these supported audit events read-only. It doesn't change your tenant and it doesn't respond for you. You get the alert and decide what to do.
Already seeing one of these?
Go to what to do in the first hour.
Common questions
What is the most common sign of Microsoft 365 account takeover?
A new inbox rule that moves, deletes or marks messages read, especially rules matching words like invoice, payment or wire, or messages from one particular contact. Attackers use these rules to hide replies from the real owner.
Does resetting the password fix a compromised account?
Not by itself. Also sign out all sessions, check MFA methods, delete unknown inbox rules, remove external forwarding, and review OAuth app consents and mailbox permissions. Those survive a password reset.
Where do I see these events?
In the Microsoft Purview audit log, plus the Entra ID sign-in logs. The records are there, but someone has to look at them.
About InboxGuards
- Price: $2 per active user per month, or $20 per user per year. No minimum, no setup fee.
- 30-day money-back guarantee. No free trial.
- Read-only access to supported Microsoft 365 and Google Workspace audit records. It does not read message content and cannot change tenant settings.
- It is an alarm. It is not a staffed SOC and not an email gateway.
- Owned and operated by Orion CMD LLC, Omaha, Nebraska. hello@inboxguards.com, 402-650-8407.