Responding to a Microsoft 365 Business Email Compromise Attack

Explore Our Microsoft Cloud Security Training →

Business Email Compromise (BEC) attacks pose a significant threat to organizations using Microsoft 365. In this post, we’ll walk you through the process of responding to such an attack.

How Business Email Compromise Attacks Work in M365

BEC attacks often involve unauthorized access to a mailbox to impersonate its owner and manipulate email conversations for financial gain.

Detecting BEC Using Defender for Office 365 and Sentinel Alerts

Defender for Office 365 and Microsoft Sentinel can help identify potential BEC attacks by monitoring email activity and generating alerts.

Investigating Compromised Mailboxes and Forwarding Rules

Once an alert is triggered, investigate the compromised mailbox for any forwarding rules or unusual activity that may indicate ongoing compromise.

Identify Compromised Account via MDO365 Alerts

Review alerts from Microsoft Defender for Office 365 to identify accounts potentially compromised by BEC attacks.

Review Mailbox Audit Logs for Forwarding Rules

Investigate mailbox audit logs for any rules that forward emails to external addresses, which may indicate a BEC attack.

Evicting Attackers from M365 Tenant

Upon confirmation of a compromise, take action to evict the attacker from your M365 tenant.

Disable Compromised Account

Disable the compromised account to prevent further damage.

Revoke Sessions and Remove Attacker Rules

Revoke any active sessions associated with the compromised account and remove any rules set up by the attacker.

Reset Credentials and Enable MFA

Reset the password for the compromised account and enable Multi-Factor Authentication (MFA) to enhance security moving forward.

Post-Incident Hardening to Prevent BEC Recurrence

After addressing the immediate threat, take steps to harden your M365 tenant to prevent future BEC attacks.

Hardening Measures

  • Enforce strong password policies
  • Implement regular security training for users
  • Review and update email protection settings

Join ITP Training‘s Microsoft Cloud Security Course

To learn more about securing your M365 environment, consider enrolling in our Microsoft Cloud Security Training.

Explore Our Microsoft Cloud Security Training →

Written by Mohammed Akhter

Founder of ITP Training. 50,000+ students trained across 30+ countries in Microsoft endpoint and cloud security. Learn more →