SecurCheckCyber Centre

OUTLOOK · MICROSOFT 365 · EXCHANGE

How to check a hacked Outlook account: a Microsoft 365 assessment guide

Secur Cloud ·

A compromised Outlook mailbox can expose confidential conversations, invoices and connected access. In Microsoft 365, impact depends on account permissions and authorised apps. A stolen session may allow access without another MFA prompt.

This guide explains how to perform an Outlook account assessment and organise a response, distinguishing personal Microsoft accounts, work identities in Entra and Exchange servers managed by your organisation.

1. Warning signs of an Outlook intrusion

  1. Unfamiliar inbox rules

    Invoices or alerts are automatically moved, archived or deleted. A forgotten rule may be legitimate; an unauthorised rule needs investigation.

  2. Unusual sign-ins

    Check an alert by opening Microsoft’s official portal directly. Distinguish a failed attempt from a successful sign-in. Location can reflect a VPN or carrier and does not alone prove an intrusion.

  3. Messages sent without your knowledge

    Look for unrecognised sent messages and take reports from contacts seriously. A displayed sender address can also be spoofed without mailbox access; IT should correlate the evidence.

  4. Changed security methods

    A phone, recovery email or MFA method added without your approval is an important warning. Do not approve authentication prompts you did not initiate.

2. Assess Outlook security without exposing access

Use a trusted device and official interfaces for these checks. Never share a password, MFA code or session token with a third-party tool.

  1. Identify the account type

    For a work or school account, use My Account and My Sign-ins (myaccount.microsoft.com and mysignins.microsoft.com). For personal Outlook.com or Hotmail, check security and activity at account.microsoft.com. Sign-in history is not a complete list of currently active sessions.

  2. Review rules and forwarding

    In Outlook on the web, review mail settings, particularly Rules and Forwarding. Record suspicious destinations and rules, then have them removed without delaying protection. At work, administrators must supplement these checks: some hidden rules, delegation or Exchange settings are not visible in this interface.

  3. Review OAuth consent

    Review apps you granted permissions to and report unfamiliar authorisations. Administrators should also examine organisation-wide consent and permissions. Microsoft Graph access depends on granted rights; a password change is not a substitute for revoking those permissions.

3. Immediate steps to regain control

  1. Alert IT immediately

    At work, promptly report times, observed actions and affected items to your administrator or security team. They can temporarily block sign-in and coordinate containment. Do not wait to finish an assessment when unauthorised activity is visible.

  2. Change the password and revoke access

    From a trusted device, choose a long, unique password stored in a password manager. For a work account, have the Entra administrator revoke sessions. For a personal Microsoft account, use “Sign out everywhere” in advanced security options: Microsoft states this may take up to 24 hours, with an exception for Xbox.

  3. Correct recovery and MFA methods

    Remove unauthorised methods and review recovery details and registered devices. Coordinate changes with IT on a managed account to preserve a safe recovery path.

  4. Investigate and monitor after containment

    Have available Entra and email logs, consent, delegation and rules reviewed. Account permissions determine potentially exposed resources, including OneDrive or SharePoint. Alert affected contacts and finance staff if fraudulent messages or payment requests were sent.

Revocation is not always immediate

In Entra, the effect depends on tokens, applications and support for continuous access evaluation. Some access tokens or application-owned sessions can remain usable until expiry or application-side revocation. Administrators must verify access has ended and address app permissions separately; a password change alone does not replace this work.

4. Prevent recurrence and understand session theft

Prefer phishing-resistant authentication where your organisation offers it, secure devices and limit unnecessary consent. Security keys and passkeys strengthen authentication without making theft of an existing session impossible. Learning to check a suspicious Outlook account complements these protections and prompt reporting.

Read the Storm-2755 alert: Microsoft 365 and payroll fraud

Read also: has my account been hacked?

Deploy SecurCheck Business to support your teams

Official Microsoft references