Business Email Compromise Response: The First 24 Hours After a Microsoft 365 Account Takeover

By Ron Samson

A Microsoft 365 takeover is a financial incident, not just an identity incident

A business email compromise (BEC) event moves quickly because the attacker is already operating from a trusted identity. Once they control a Microsoft 365 mailbox, they can read invoice threads, impersonate executives, alter payment instructions, create forwarding rules, and use the account to target suppliers or payroll teams. The first 24 hours determine whether the event remains a contained account compromise or becomes a material fraud, privacy, and operational crisis.

The response objective is not simply “reset the password.” Security, IT, finance, legal, and communications teams need to stop attacker access, preserve evidence, identify affected conversations, protect payment workflows, and make defensible decisions under pressure. That requires a sequence of actions, clear ownership, and visibility beyond a single user account.

Microsoft reported that more than 600 million identity attacks occur daily across its services, while the FBI Internet Crime Complaint Center continues to identify BEC as one of the costliest cybercrime categories. The practical implication is straightforward: organizations should treat Microsoft 365 account takeover as a rehearsed incident type, not an unusual help-desk ticket.

💡 Critical distinction: A compromised mailbox can be used to create fraudulent instructions without sending a large volume of obvious phishing emails. Investigators must examine what the attacker read, changed, forwarded, and impersonated—not merely what they sent.

The first hour: contain access without destroying the investigation

The incident commander should open a tracked case immediately and assign one person to coordinate technical containment, business impact, and executive updates. Avoid parallel, uncoordinated changes. A rushed administrator can erase useful evidence, alert the adversary prematurely, or overlook persistence in a second account.

Start by validating the report. Capture the affected user, their department, reporting time, suspicious messages, known payment conversations, devices, IP addresses, and any Microsoft Defender, Entra ID, SIEM, or endpoint alerts. Record everything in a case timeline with timestamps and the analyst responsible. This becomes essential if a bank recall, cyber-insurance notification, customer notification, or legal review follows.

Business Email Compromise Response: The First 24 Hours After a Microsoft 365 Account Takeover
Fast containment must protect both evidence and business operations.

Next, revoke active sessions and block the attacker’s current access path. In Microsoft 365 and Entra ID, this typically includes disabling the account temporarily or blocking sign-in, revoking refresh tokens and sessions, resetting the password to a strong unique value, and requiring fresh multifactor authentication registration where appropriate. If risk warrants it, disable mailbox access protocols that are not required, especially legacy authentication paths.

Do not assume multifactor authentication makes the incident harmless. Adversaries may have stolen session tokens, enrolled their own authentication method, approved a malicious device, exploited consented applications, or used a compromised endpoint. Review sign-in logs for unfamiliar locations, impossible travel, user agents, devices, IP addresses, authentication methods, and successful sign-ins after the user says they changed credentials.

Immediate action Why it matters Common failure
Revoke sessions and reset credentials Stops continued use of stolen credentials or tokens Resetting only the password
Preserve audit evidence Supports scoping, recovery, and reporting Deleting suspicious messages immediately
Alert finance and leadership Interrupts fraudulent payment activity Treating security as the only stakeholder

Hours one through four: remove persistence and establish scope

Containment is incomplete until the team identifies what the attacker changed. Mailbox rules are central to BEC investigations. Threat actors frequently create hidden or inconspicuous inbox rules that forward messages externally, move replies to RSS feeds or deleted items, mark communications as read, or suppress messages from a supplier, bank, or security team. Review inbox rules, transport rules, delegates, mailbox permissions, shared mailbox access, forwarding SMTP addresses, and automatic replies.

Inspect OAuth application consent and enterprise applications as carefully as mailbox rules. A malicious application with broad Mail.Read, Mail.Send, Files.Read, offline_access, or directory permissions can survive a password reset. Revoke suspicious consent, disable the application, rotate affected credentials, and document the tenant-wide impact. Review recent changes to Conditional Access policies, privileged roles, authentication methods, and break-glass accounts as well.

Then determine whether the compromised identity is the initial account or one node in a wider intrusion. Search Entra sign-in logs, Microsoft 365 unified audit logs, Defender telemetry, VPN records, firewall logs, EDR data, and identity-provider events for shared IP addresses, devices, browser fingerprints, domains, and application identifiers. Check nearby users who received the same lure, especially finance staff, executives, assistants, HR, procurement, and users with privileged access.

This is where a mature monitoring function pays for itself. Effective Managed SOC Services correlate identity, endpoint, email, and network evidence rather than asking one administrator to manually inspect disconnected consoles. The outcome is faster confidence about blast radius: one mailbox, multiple accounts, an infected endpoint, or active tenant-level persistence.

Evidence worth preserving before routine cleanup

  • Suspicious email headers, original messages, attachments, URLs, and message trace results.
  • Entra ID sign-in, audit, authentication-method, and risky-user events covering the suspected dwell period.
  • Mailbox audit events for rule creation, forwarding, message access, deletion, delegation, and send activity.
  • Endpoint telemetry for the affected user’s devices, including browser activity, malware detections, and remote-access tools.
  • Payment records, vendor master-data changes, bank recall references, and internal approval evidence.

Hours four through eight: stop fraud and protect affected relationships

BEC response fails when the technical team contains an account but finance continues processing an attacker-manipulated transaction. Notify the CFO, controller, accounts payable lead, treasury, procurement, and payroll owner through a trusted channel. Tell them precisely which mailbox, suppliers, bank details, invoices, payment threads, and dates require extra verification. Do not rely on email to communicate this instruction.

Place a temporary hold on pending payments connected to the compromised mailbox or suspicious change requests. Require out-of-band confirmation using an independently validated telephone number—not a number included in the email chain. Review recently changed vendor banking information, payment approvals, payroll direct-deposit updates, wire templates, and purchase orders. If funds have moved, contact the sending bank immediately and request a recall, freeze, or fraud escalation. Speed matters more than complete technical certainty.

Customer and supplier communications require judgment. A broad announcement can create confusion and invite follow-on scams, but silence can leave partners vulnerable. Contact parties who received fraudulent messages, had sensitive threads accessed, or may act on changed instructions. State what happened, identify the affected address and timeframe, advise recipients to disregard specified messages, and provide a verified callback route for payment confirmation.

The CISA guidance on business email compromise reinforces this business-led approach: verify payment changes independently and report suspected fraud quickly. Security teams should provide accurate facts, but finance leadership owns the operational decision to hold, release, reverse, or revalidate payments.

Hours eight through 16: investigate the initial access path

Eradication depends on knowing how the attacker entered. Common paths include phishing, adversary-in-the-middle credential theft, MFA fatigue, stolen browser cookies, reused passwords, malicious OAuth consent, exposed credentials from another breach, and endpoint malware. The investigation should test each plausible path against evidence rather than choosing the most familiar explanation.

Interview the affected employee without blame. Ask when they noticed unusual activity, whether they entered credentials into a link, approved unexpected prompts, installed software, used a personal device, traveled, or received unusual calls from “IT.” Compare the interview with sign-in telemetry and browser history. A respectful interview often supplies the timeline that logs alone cannot.

If endpoint compromise is possible, isolate the device from the network while preserving it for investigation. Run EDR triage, inspect persistence, check browser extensions and saved credentials, identify remote-management software, and hunt for matching indicators across the fleet. A clean Microsoft 365 tenant does not help if malware on the employee’s laptop steals the newly reset password five minutes later.

This is an appropriate decision point for Managed Detection and Response. MDR is most valuable when it combines skilled investigation with active containment across endpoint and identity telemetry. Buyers should ask whether their provider can investigate cloud identity abuse, not only classify endpoint alerts, and whether analysts can work within agreed authority during an active fraud event.

Hours 16 through 24: recover safely and turn findings into controls

Recovery should restore business access in a controlled order. Re-enable the user only after investigators have removed malicious rules, unauthorized delegates, risky OAuth grants, suspicious authentication methods, and known persistence. Require strong phishing-resistant MFA where feasible, confirm that recovery methods belong to the employee, and review device compliance before allowing access from unmanaged endpoints.

Before closing the urgent phase, produce a concise executive brief. It should identify the compromised identities, confirmed attacker actions, suspected initial access method, affected data and relationships, financial exposure, payment status, containment completed, open investigative questions, and next decisions. This document is not a technical log dump. Leaders need clear statements of what is known, unknown, and being done next.

Use the incident to tune controls that reduce recurrence. Priorities commonly include disabling legacy authentication, enforcing Conditional Access, restricting external forwarding, alerting on mailbox-rule creation, tightening OAuth consent, implementing DMARC, improving vendor payment verification, protecting privileged accounts, and retaining adequate logs. Map each improvement to a named owner, target date, budget requirement, and measurable outcome.

Microsoft’s guidance for responding to compromised email accounts is a useful technical reference, while the NIST Cybersecurity Framework helps leadership organize longer-term improvements across governance, protection, detection, response, and recovery. Neither replaces a response plan tailored to your payment processes and Microsoft 365 configuration.

Build a response capability before the next mailbox takeover

Clearnetwork helps organizations monitor, tune, investigate, and respond across Microsoft 365, identity, endpoint, and security operations—so incident teams can act decisively when fraud risk is highest.

Request a cybersecurity assessment

Questions leaders should ask after a BEC incident

Should we force a tenant-wide password reset?

A tenant-wide reset may be necessary when evidence indicates broad credential theft, compromised privileged accounts, or an identity attack affecting multiple users. It is disruptive, however, and can create support overload. Base the decision on verified scope, authentication evidence, endpoint findings, and the attacker’s ability to maintain persistence—not fear alone.

How long should we monitor after recovery?

Heightened monitoring should continue long enough to detect re-entry attempts, delayed fraud, and follow-on phishing. Many organizations use at least 30 days, with more intensive review during the first week. Monitor sign-ins, rule changes, OAuth activity, payment changes, external forwarding, and communications from impacted partners.

What is the most important nontechnical control?

Independent payment verification is the most reliable business control against BEC loss. A defined callback process, trusted vendor contacts, dual approval for banking changes, and clear authority to pause payments can prevent a compromised mailbox from becoming an irreversible wire transfer.

The first 24 hours are about disciplined execution: contain access, preserve evidence, stop financial loss, establish scope, eradicate persistence, and recover with stronger controls. Organizations that combine tested business workflows with experienced security operations reduce confusion, shorten attacker dwell time, and protect the trust that BEC attacks are designed to exploit.


About

Ron Samson