Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If an Exchange or Microsoft 365 mailbox may have been accessed without permission, treat it as a suspected identity incident: contain access, check for unauthorized changes, establish what happened, then restore the account only after cleanup. An unusual rule, missing message, or suspicious sign-in is a reason to investigate—not proof on its own.

This guide focuses on Microsoft 365 cloud mailboxes, including Exchange Online and the associated Microsoft Entra identity. For on-premises Exchange or a hybrid identity, apply the corresponding local Exchange and authoritative identity controls as well; a cloud password change may not be authoritative for a synchronized or federated account. Microsoft’s compromised Microsoft 365 email account guidance is the primary reference for the cloud response.

What signs should you investigate?

Record what prompted concern, the affected account, the approximate first-seen time, and any relevant user action—for example, clicking a link or entering credentials. Look for changes and activity that do not fit the user’s normal pattern:

  • Messages missing from the mailbox, or unexpected items in Deleted Items or Sent Items.
  • Messages the user did not send, especially suspicious or high-volume email.
  • New forwarding to an external address, or inbox rules that redirect mail or move it into less-visible folders.
  • Unexplained account lockouts or repeated password changes.
  • Unexpected changes to the user’s signature or contact directory.

These indicators warrant investigation, but none confirms unauthorized access by itself. Check the timing and combination of signs against sign-in, mailbox, and message activity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How do you contain access?

  1. Disable the cloud account during the investigation if feasible. Microsoft says, “Disabling the compromised account is preferred and highly recommended until you complete the investigation.” If disabling is not possible, reset the password through the identity system that is authoritative for the account. For a synchronized or federated identity, follow the organization’s on-premises identity process. Do not send a replacement password to the mailbox that may be exposed. See Microsoft’s account response guidance.
  2. Revoke active sign-in sessions and refresh tokens. Treat this as a separate action from changing the password; one does not replace the other. Use administrator-approved Microsoft Graph permissions and procedures. Follow Microsoft’s session-revocation instructions.
  3. Review app passwords. A password reset does not automatically revoke app passwords. Identify any still in use and replace or remove them as appropriate.

What mailbox and account changes should you check?

Inspect forwarding and visible or hidden inbox rules

Check mailbox-level forwarding as well as inbox rules. In Exchange Online PowerShell, these read-only examples show the relevant forwarding properties and enumerate hidden rules:

Get-Mailbox -Identity user@contoso.com | Format-List ForwardingAddress,ForwardingSmtpAddress,DeliverToMailboxAndForward
Get-InboxRule -Mailbox user@contoso.com -IncludeHidden

Replace the example address with the affected mailbox. A nonblank forwarding address deserves review; DeliverToMailboxAndForward indicates whether forwarded messages are also kept in the mailbox. A redirect rule can send messages elsewhere without retaining them in the mailbox. Confirm whether a rule and its destination are expected before removing or changing them. Microsoft documents these checks in its compromised-account guidance.

Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Review identity methods, application consent, and roles

  • Review the user’s registered MFA methods and devices; remove anything the user or administrator cannot recognize.
  • Check applications the user consented to and revoke unauthorized consent.
  • Review assigned administrative roles for unexpected or unauthorized changes.

These checks matter because unauthorized access may persist or extend beyond a mailbox rule. Microsoft’s response guidance covers these account-level review areas.

Use audit records before removing suspicious changes

Purview audit records can help identify who configured forwarding or created inbox rules. They can also help investigate deleted-message actions. Whether deleted items can be recovered depends on the mailbox’s applicable deleted-item retention period or hold. See Microsoft’s Purview audit troubleshooting guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

How do you establish the timeline and scope?

Use complementary evidence sources rather than relying on one log or one mailbox symptom. Start the audit review immediately before the suspected activity and continue through remediation; Microsoft advises against narrowing the initial search too aggressively. Correlate the results by time with message trace and the account’s Sent Items.

Evidence source Question it helps answer
Microsoft Entra sign-in logs What sign-ins occurred, and what IP address, location, time, and result were recorded?
Purview audit records Who changed forwarding or inbox rules, and what deleted-message actions were recorded?
Mailbox rules and forwarding settings Was mail redirected, moved, or otherwise handled by a rule or mailbox setting?
Message trace and Sent Items What mail activity aligns with the suspected period, including messages sent from the account?

Log availability depends on licensing: Microsoft’s phishing playbook says Entra sign-in and audit log retention is limited to 30 or 90 days depending on licensing, and recommends exporting logs for longer analysis. Check the applicable retention for your tenant and preserve relevant records before they age out. See the Microsoft security operations playbook for phishing.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Look beyond the mailbox when evidence points further

Check for password-spray or brute-force activity, suspicious sign-ins, OAuth consent grants, token abuse, unusual mailbox or collaboration activity, possible data exfiltration, related accounts and services, and other persistence such as delegation or forwarding. If a phishing attachment was opened, determine whether malware ran on the endpoint. Escalate to the organization’s incident-response lead if the evidence suggests broader access, sensitive data exposure, or involvement of an administrative account. Microsoft’s phishing response playbook and password-spray response playbook describe related investigation areas.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When should you restore the account?

Restore service after investigation and remediation, not simply because the password has changed. If you disabled the account, reset credentials before re-enabling it. Recheck that unauthorized forwarding, rules, identity methods, application consent, or role assignments have been addressed. If the account was restricted after sending spam or high-volume email, Microsoft directs administrators to remove the user from Restricted entities after investigating and resolving the cause; follow its account recovery guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How can you reduce the chance of a repeat?

Enforce MFA and consider whether a phishing-resistant method is appropriate for the account’s risk and organizational policy. Microsoft’s administrator guidance explains phishing-resistant MFA. The right method depends on policy and compatibility; introducing a new authentication method does not contain an incident that is already underway.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.