OUTLOOK · MICROSOFT 365 · EXCHANGE
How to check a hacked Outlook account: a Microsoft 365 assessment guide
A compromised Outlook mailbox can expose confidential conversations, invoices and connected access. In Microsoft 365, impact depends on account permissions and authorised apps. A stolen session may allow access without another MFA prompt.
This guide explains how to perform an Outlook account assessment and organise a response, distinguishing personal Microsoft accounts, work identities in Entra and Exchange servers managed by your organisation.
1. Warning signs of an Outlook intrusion
Unfamiliar inbox rules
Invoices or alerts are automatically moved, archived or deleted. A forgotten rule may be legitimate; an unauthorised rule needs investigation.
Unusual sign-ins
Check an alert by opening Microsoft’s official portal directly. Distinguish a failed attempt from a successful sign-in. Location can reflect a VPN or carrier and does not alone prove an intrusion.
Messages sent without your knowledge
Look for unrecognised sent messages and take reports from contacts seriously. A displayed sender address can also be spoofed without mailbox access; IT should correlate the evidence.
Changed security methods
A phone, recovery email or MFA method added without your approval is an important warning. Do not approve authentication prompts you did not initiate.
2. Assess Outlook security without exposing access
Use a trusted device and official interfaces for these checks. Never share a password, MFA code or session token with a third-party tool.
Identify the account type
For a work or school account, use My Account and My Sign-ins (myaccount.microsoft.com and mysignins.microsoft.com). For personal Outlook.com or Hotmail, check security and activity at account.microsoft.com. Sign-in history is not a complete list of currently active sessions.
Review rules and forwarding
In Outlook on the web, review mail settings, particularly Rules and Forwarding. Record suspicious destinations and rules, then have them removed without delaying protection. At work, administrators must supplement these checks: some hidden rules, delegation or Exchange settings are not visible in this interface.
Review OAuth consent
Review apps you granted permissions to and report unfamiliar authorisations. Administrators should also examine organisation-wide consent and permissions. Microsoft Graph access depends on granted rights; a password change is not a substitute for revoking those permissions.
3. Immediate steps to regain control
Alert IT immediately
At work, promptly report times, observed actions and affected items to your administrator or security team. They can temporarily block sign-in and coordinate containment. Do not wait to finish an assessment when unauthorised activity is visible.
Change the password and revoke access
From a trusted device, choose a long, unique password stored in a password manager. For a work account, have the Entra administrator revoke sessions. For a personal Microsoft account, use “Sign out everywhere” in advanced security options: Microsoft states this may take up to 24 hours, with an exception for Xbox.
Correct recovery and MFA methods
Remove unauthorised methods and review recovery details and registered devices. Coordinate changes with IT on a managed account to preserve a safe recovery path.
Investigate and monitor after containment
Have available Entra and email logs, consent, delegation and rules reviewed. Account permissions determine potentially exposed resources, including OneDrive or SharePoint. Alert affected contacts and finance staff if fraudulent messages or payment requests were sent.
Revocation is not always immediate
In Entra, the effect depends on tokens, applications and support for continuous access evaluation. Some access tokens or application-owned sessions can remain usable until expiry or application-side revocation. Administrators must verify access has ended and address app permissions separately; a password change alone does not replace this work.
4. Prevent recurrence and understand session theft
Prefer phishing-resistant authentication where your organisation offers it, secure devices and limit unnecessary consent. Security keys and passkeys strengthen authentication without making theft of an existing session impossible. Learning to check a suspicious Outlook account complements these protections and prompt reporting.
Read also: has my account been hacked?Deploy SecurCheck Business to support your teams