Microsoft 365 Compromised? — UK Tenant / Admin / Entra ID Breach Response
When Microsoft 365 admin is compromised, the whole tenant is at risk — global admin accounts breached, malicious OAuth apps granted tenant-wide access, attacker mailbox rules + conditional access tampering. Beyond a single mailbox, tenant-wide compromise requires deep response: tenant-wide audit log analysis, OAuth grant revocation, admin account reset, conditional access rebuild. UK 24/7 incident response.
We respond to incident triage requests within 60 minutes during UK business hours, and on-call within 4 hours overnight and weekends.
YOU MAY HAVE SEARCHED
Do these 4 things in the next 10 minutes
- 1
Identify the compromised admin (Entra ID → Users → Audit logs → Directory activity → look for role assignments, user creations, OAuth app consents that you dont recognise). Document the attacker admin list.
- 2
Reset the compromised admin password + MFA immediately. Reset ALL Global Admin passwords (typically max 5 in a small tenant). Use break-glass admin reset + a password you control, then re-secure.
- 3
Revoke all sessions for ALL admins (Entra ID → Users → Sign-in sessions → Revoke all). Then for ALL users (Entra ID bulk revoke).
- 4
Block the malicious OAuth apps. Entra ID → Enterprise applications → audit each app for admin consent / high-privilege (Mail.ReadWrite, Directory.ReadWrite.All, Files.ReadWrite.All). Block + delete suspicious app registrations. Document consents given by attackers as evidence.
What we do — the Gridisys incident timeline
From the moment you engage, within fixed-price limits.
Triage + scoping (Hour 0-3)
- ▸Free 15-min triage — confirm tenant-wide vs single-mailbox, admin vs user-only, suspected entry vector
- ▸Pull unified audit log (UAL) for ALL admin users — 90 days. Identify: admin logins, role assignments, app registrations, conditional access policy changes, MFA registration resets
- ▸Inventory all OAuth grants in the tenant — flag high-privilege (Microsoft Graph Mail.ReadWrite, Directory.ReadWrite.All, AppRoleAssignment.ReadWrite.All)
- ▸Identify persistence vectors: app passwords, legacy auth (IMAP / SMTP basic auth), delegated mailboxes, mail-flow connectors, transport rules added by attacker
Containment (Hour 2-6)
- ▸Reset MFA + password all Global Admins (typically 5 or fewer accounts)
- ▸Revoke all sessions for admins (and all users if tenant-wide)
- ▸Block + remove malicious app registrations / OAuth grants
- ▸Remove attacker-added user accounts (often the attacker creates a new help_desk_support_365.onmicrosoft.com style user) — block first, then delete after evidence preservation
- ▸Disable all legacy auth (basic auth for IMAP, POP, SMTP, EWS) at tenant level
- ▸Re-enable conditional access — particularly MFA-required-everywhere
Tenant-wide forensics (Hour 6-72)
- ▸Full unified audit log analysis (90 days of M365 + Entra logs) — list of every mailbox accessed, file accessed, app consent, role change
- ▸Identify what attacker accessed in each mailbox (sent mail, downloads, forwarding rules) — quantify data exposure for ICO + customer notification
- ▸Investigate conditional access manipulation — were policies weakened or admin-exempted? audit conditional access log (Azure Activity log)
- ▸Identify all app passwords created by any account in attacker window — these bypass MFA
- ▸Identify all mailboxes that had access granted to the malicious OAuth app — list of mailboxes with data exposure scope
Re-secure + rebuild tenant posture (Day 2-14)
- ▸Conditional access redesign — MFA-required-everywhere, geo-block, no legacy auth, device compliance for admins, break-glass accounts with strong credentials stored in a vault
- ▸Defender for Office 365 hardening — anti-phishing, safe links, safe attachments, ZAP
- ▸Mailbox audit logging enable (by default off in M365) — 90-day retention for all user mailboxes
- ▸Microsoft Entra ID Protection (if E5 licensed) configured + tuned — risky sign-in auto policies, password spray detection
- ▸Implementation of ~120-line M365 secure config baseline aligned to NCSC M365 Secure Configuration
- ▸Periodic admin review workflow (admins monthly, OAuth grants quarterly, cond-access drift monthly)
Notifications (Day 1-7) — ICO + FCA + customer + supplier
- ▸ICO notification assessment — tenant-wide admin compromise with mailbox access almost certainly triggers UK GDPR personal data breach threshold
- ▸ICO submission draft (within 72 hours of becoming aware): breach description, scope of personal data accessed, mitigation actions, recovery actions, residual risk
- ▸FCA notification (if FCA-regulated) — PS21/3 operational resilience notification for operationally significant impact
- ▸Customer notification (if customer personal data accessed) — sector-tailored notification (e.g., finance firms: regulated firm communications)
- ▸Supplier / partner notification (if supplier confidentiality compromised)
- ▸Cyber insurance notification — within 24 hours of confirmed incident
- ▸Action Fraud UK notification — for crime reference (insurance requires)
What it costs
Triage + first 4 hours: free. Tenant-wide compromise response (multi-account, conditional access rebuild, OAuth revocation) is fixed-price. Includes unified audit log forensics, tenant re-secure, ICO + customer notification pack, incident report. Optional ongoing M365 managed SOC available after the incident. Contact us for a tailored quote.
Full pricing breakdownWhat we cover
RELATED INCIDENT RESPONSE GUIDES
Frequently asked questions
Talk to us now
The first 15-minute triage call is free. We'll tell you whether it's a real incident, what's at risk, and what to do next — no obligation, no commitment.