ACTIVE INCIDENT RIGHT NOW? Gridisys 24/7 emergency triage — £0 first 15 minutes.
24/7 EMERGENCY INCIDENT RESPONSE · UK

Microsoft 365 Compromised? — UK Tenant / Admin / Entra ID Breach Response

When Microsoft 365 admin is compromised, the whole tenant is at risk — global admin accounts breached, malicious OAuth apps granted tenant-wide access, attacker mailbox rules + conditional access tampering. Beyond a single mailbox, tenant-wide compromise requires deep response: tenant-wide audit log analysis, OAuth grant revocation, admin account reset, conditional access rebuild. UK 24/7 incident response.

We respond to incident triage requests within 60 minutes during UK business hours, and on-call within 4 hours overnight and weekends.

YOU MAY HAVE SEARCHED

"microsoft 365 tenant compromised""m365 admin account hacked""azure ad compromised UK""microsoft 365 suspicious oauth app""microsoft 365 security incident""entra id admin compromised""m365 elevated privilege alert""m365 admin mailbox breach impact""office 365 tenant taken over""conditional access disabled microsoft 365"

Do these 4 things in the next 10 minutes

  1. 1

    Identify the compromised admin (Entra ID → Users → Audit logs → Directory activity → look for role assignments, user creations, OAuth app consents that you dont recognise). Document the attacker admin list.

  2. 2

    Reset the compromised admin password + MFA immediately. Reset ALL Global Admin passwords (typically max 5 in a small tenant). Use break-glass admin reset + a password you control, then re-secure.

  3. 3

    Revoke all sessions for ALL admins (Entra ID → Users → Sign-in sessions → Revoke all). Then for ALL users (Entra ID bulk revoke).

  4. 4

    Block the malicious OAuth apps. Entra ID → Enterprise applications → audit each app for admin consent / high-privilege (Mail.ReadWrite, Directory.ReadWrite.All, Files.ReadWrite.All). Block + delete suspicious app registrations. Document consents given by attackers as evidence.

M365 tenant compromise is increasingly common because attackers know UK SMEs often have global admin accounts with weak self-service passwords, MFA on by default but conditional access open, and no review of OAuth consent. M365 admin compromise escalates to ICO, customer, FCA, and supply-chain notifications in parallel. We've handled 100+ tenant-level compromise incidents for UK SMEs and FCA-regulated firms.

What we do — the Gridisys incident timeline

From the moment you engage, within fixed-price limits.

First 60-180 minutes

Triage + scoping (Hour 0-3)

  • Free 15-min triage — confirm tenant-wide vs single-mailbox, admin vs user-only, suspected entry vector
  • Pull unified audit log (UAL) for ALL admin users — 90 days. Identify: admin logins, role assignments, app registrations, conditional access policy changes, MFA registration resets
  • Inventory all OAuth grants in the tenant — flag high-privilege (Microsoft Graph Mail.ReadWrite, Directory.ReadWrite.All, AppRoleAssignment.ReadWrite.All)
  • Identify persistence vectors: app passwords, legacy auth (IMAP / SMTP basic auth), delegated mailboxes, mail-flow connectors, transport rules added by attacker
Within 6 hours of engagement

Containment (Hour 2-6)

  • Reset MFA + password all Global Admins (typically 5 or fewer accounts)
  • Revoke all sessions for admins (and all users if tenant-wide)
  • Block + remove malicious app registrations / OAuth grants
  • Remove attacker-added user accounts (often the attacker creates a new help_desk_support_365.onmicrosoft.com style user) — block first, then delete after evidence preservation
  • Disable all legacy auth (basic auth for IMAP, POP, SMTP, EWS) at tenant level
  • Re-enable conditional access — particularly MFA-required-everywhere
Days 1-3

Tenant-wide forensics (Hour 6-72)

  • Full unified audit log analysis (90 days of M365 + Entra logs) — list of every mailbox accessed, file accessed, app consent, role change
  • Identify what attacker accessed in each mailbox (sent mail, downloads, forwarding rules) — quantify data exposure for ICO + customer notification
  • Investigate conditional access manipulation — were policies weakened or admin-exempted? audit conditional access log (Azure Activity log)
  • Identify all app passwords created by any account in attacker window — these bypass MFA
  • Identify all mailboxes that had access granted to the malicious OAuth app — list of mailboxes with data exposure scope
Within 2 weeks

Re-secure + rebuild tenant posture (Day 2-14)

  • Conditional access redesign — MFA-required-everywhere, geo-block, no legacy auth, device compliance for admins, break-glass accounts with strong credentials stored in a vault
  • Defender for Office 365 hardening — anti-phishing, safe links, safe attachments, ZAP
  • Mailbox audit logging enable (by default off in M365) — 90-day retention for all user mailboxes
  • Microsoft Entra ID Protection (if E5 licensed) configured + tuned — risky sign-in auto policies, password spray detection
  • Implementation of ~120-line M365 secure config baseline aligned to NCSC M365 Secure Configuration
  • Periodic admin review workflow (admins monthly, OAuth grants quarterly, cond-access drift monthly)
72-hour ICO clock

Notifications (Day 1-7) — ICO + FCA + customer + supplier

  • ICO notification assessment — tenant-wide admin compromise with mailbox access almost certainly triggers UK GDPR personal data breach threshold
  • ICO submission draft (within 72 hours of becoming aware): breach description, scope of personal data accessed, mitigation actions, recovery actions, residual risk
  • FCA notification (if FCA-regulated) — PS21/3 operational resilience notification for operationally significant impact
  • Customer notification (if customer personal data accessed) — sector-tailored notification (e.g., finance firms: regulated firm communications)
  • Supplier / partner notification (if supplier confidentiality compromised)
  • Cyber insurance notification — within 24 hours of confirmed incident
  • Action Fraud UK notification — for crime reference (insurance requires)

What it costs

Triage + first 4 hours: free. Tenant-wide compromise response (multi-account, conditional access rebuild, OAuth revocation) is fixed-price. Includes unified audit log forensics, tenant re-secure, ICO + customer notification pack, incident report. Optional ongoing M365 managed SOC available after the incident. Contact us for a tailored quote.

Full pricing breakdown

What we cover

Tenant-wide unified audit log forensics (90 days of M365 + Entra logs)
Admin account compromise containment — passwords reset, sessions revoked
OAuth grant abuse investigation + revocation (high-privilege consent approvals)
Attacker-created user accounts + app registrations blocked + removed
Conditional access rebuild — MFA, geo-block, device compliance, break-glass vaulting
Defender for Office 365 hardening — anti-phishing, safe links, safe attachments, ZAP
Microsoft Entra ID Protection tuning (if E5 licensed) — risky sign-in policies
Mailbox audit logging enable (+ preserve future evidence pack)
ICO 72-hour notification assessment + submission pack
FCA PS21/3 operational resilience notification (if FCA-regulated)
Customer / supplier notification packs — sector-tailored wording
Incident timeline + board pack — fitted for audit + insurance evidence

Frequently asked questions

Talk to us now

The first 15-minute triage call is free. We'll tell you whether it's a real incident, what's at risk, and what to do next — no obligation, no commitment.

Gridisys

AI-powered cybersecurity and app development. Protecting and building for businesses worldwide.

© 2026 Gridisys. All rights reserved.Gridisys Ltd — Company No. 15780405 — Registered in England & WalesRegistered Office: 128 City Road, London, United Kingdom, EC1V 2NX

We use cookies to improve your experience and analyse site traffic. By clicking "Accept", you consent to our use of cookies. Learn more.