MICROSOFT · ONEDRIVE · SSO · SUBSCRIPTIONS
Microsoft account hacked: what to do? A complete assessment guide
Microsoft access can involve more than Outlook messages: OneDrive files, purchases, subscriptions or business applications. The impact of an intrusion depends on the account type, its permissions and connected services.
Here is how to perform a Microsoft account assessment and organise your response. If unauthorised activity is visible, secure the account without waiting to finish a checklist and alert IT for any work access.
1. Personal account or work identity: define the scope
A personal Microsoft account and a Microsoft Entra work or school account are separate identities, even when a similar address appears at sign-in. Personal OneDrive, Xbox and family subscriptions do not automatically grant access to company servers or its tenant.
A personal account can nevertheless be invited into an organisation. SSO app access depends on actual permissions; Azure consoles also require assigned rights. Have an administrator inventory that access. Consumer Skype was retired on 5 May 2025: review remaining connected Microsoft services, including Teams Free if you use it.
2. Signs of a compromised Microsoft account
Unusual activity
An unrecognised successful sign-in warrants a prompt response. Open the official portal directly to verify the alert. A failed attempt or approximate location does not alone prove the account is hacked.
Changed files and sharing
Review unexpected changes, deletions or sharing in OneDrive and, at work, SharePoint. Downloads are not necessarily visible to users; logs available to administrators depend on the environment.
OAuth requests and unfamiliar methods
An app requests permissions unrelated to your activity, or a recovery method appears without your approval. A consent request is not yet an authorisation: do not approve it before checking.
Unexplained sign-outs or spending
Repeated sign-in requests can result from IT policy, an update or an incident; they do not prove intrusion. Correlate them with security events and review unrecognised purchases or subscriptions.
3. Review access without exposing secrets
Perform these checks in official interfaces from a trusted device. Never enter a password, MFA code or recovery code into a third-party assessment tool.
Recent activity
For a personal account, review security and activity at account.microsoft.com. For a work or school account, use myaccount.microsoft.com and mysignins.microsoft.com. Compare times, apps and sign-in outcomes. History is not a complete inventory of active sessions.
Recovery and authentication
Review recovery details, passkeys, authenticator apps and registered devices. Have unauthorised additions removed while retaining a safe recovery method. In a managed environment, involve the administrator.
Permissions and resources
Review connected apps and their permissions. IT should investigate organisation-wide consent and administrative roles if a work identity is involved. Check file sharing and resources the identity could actually access, without assuming every service is compromised.
4. Immediate steps to contain an intrusion
Report immediately and use a trusted device
Alert IT immediately for a work or guest account. Describe actions, times and affected services. If credential-stealing malware is suspected, use another trusted device and have the endpoint examined; do not enter your new password on it.
Change the password and revoke access
Choose a long, unique password stored in a password manager; change it wherever reused. For a personal account, request “Sign out everywhere” in advanced security options. It can take up to 24 hours and Xbox is excluded. For an Entra identity, have the administrator coordinate blocking and revocation: some tokens or application sessions require additional action.
Regain control of recovery methods
Correct altered methods and remove unfamiliar additions. On a personal Microsoft account, the 25-character recovery code is distinct from a temporary MFA code. If it may be exposed and you can access the account, generate a new one: the previous code becomes unusable. Keep it out of reach of a compromised device. This is not the procedure for managed Entra accounts.
Review consequences and monitor
Review affected files, sharing, purchases and subscriptions. Revoking a share does not retrieve downloaded copies. At work, have available logs, consent and privilege changes investigated. Report unrecognised financial activity to the relevant service and your bank where necessary.
Lost personal account access: follow official Microsoft recovery help
Strengthen sign-in methods for the long term
Use unique passwords and stronger authentication, preferably phishing-resistant where available. Passkeys and security keys do not make a compromised device or an already stolen session harmless. Checking a suspicious Microsoft account complements endpoint security, permission reviews and post-incident monitoring.
General guide: has my account been hacked?Deploy SecurCheck Business to support administrators and staff