InboxGuards Start monitoring

How to spot Microsoft 365 account takeover

A taken-over mailbox rarely looks broken. The owner still gets most of their mail. The tell is usually a small settings change they didn't make.

The signs worth checking

SignWhy attackers do itAudit operation to search
New inbox rule that moves, deletes or marks mail as readHide replies from the real owner while a fake invoice thread runsNew-InboxRule, Set-InboxRule
Forwarding to an outside addressKeep a copy of everything, even after a password changeSet-Mailbox (forwarding fields), forwarding rules
Sign-in from a new country, ISP or deviceShows the account is in use by someone elseUserLoggedIn, Entra sign-in logs
Many failed sign-ins, then a successPassword spraying that finally landedEntra sign-in logs
Mailbox permission granted to another accountRead the mailbox from a different loginAdd-MailboxPermission
New MFA method or admin roleStay in after the reset, or take the whole tenantMFA registration and role-change events
OAuth app consent the user doesn't recognizeApp access that skips the password entirelyConsent to application

Where to look

Microsoft Purview's audit search and the Entra ID sign-in logs hold these records. The trouble for a small business isn't access, it's attention. A log nobody reads on a schedule isn't monitoring. More detail on reading them: Microsoft 365 audit logs explained.

Your options for watching

ApproachEffortCost
Check Purview and sign-in logs by handHigh. Needs a named person and a schedule.Included with your plan
Microsoft's built-in alert policiesMedium. Alerts often go to an admin inbox nobody reads.Included, with more in higher tiers
MSP with a managed SOC or MDRLow for youVaries by provider
InboxGuardsLow. Read-only connect, then alerts land on a dashboard, and critical ones are emailed to you.$2/user/mo or $20/user/yr

InboxGuards reads these supported audit events read-only. It doesn't change your tenant and it doesn't respond for you. You get the alert and decide what to do.

Already seeing one of these?

Go to what to do in the first hour.

Common questions

What is the most common sign of Microsoft 365 account takeover?

A new inbox rule that moves, deletes or marks messages read, especially rules matching words like invoice, payment or wire, or messages from one particular contact. Attackers use these rules to hide replies from the real owner.

Does resetting the password fix a compromised account?

Not by itself. Also sign out all sessions, check MFA methods, delete unknown inbox rules, remove external forwarding, and review OAuth app consents and mailbox permissions. Those survive a password reset.

Where do I see these events?

In the Microsoft Purview audit log, plus the Entra ID sign-in logs. The records are there, but someone has to look at them.

About InboxGuards