Try this first
- 1Disable the account immediately (Microsoft 365: Active Users > user > Block sign-in). Investigate after.
- 2Force logout of all sessions (Microsoft Entra: user > Authentication > "Sign out all sessions").
- 3Check the mailbox for forwarding rules. Attackers usually create a rule that auto-forwards and deletes mail.
- 4Reset the password, enable MFA, then re-enable the account.
- 5Reach the colleague on another channel (not mail from the suspect account) to explain what happened.
When to bring us in
No experience with session revoke or mailbox rules? Do not do it alone; one missed forwarding rule and the attacker stays in. We can join within an hour.
See also
- I think I clicked a phishing linkNo shame, happens to everyone. The next fifteen minutes matter.
- Lost the MFA app: new phone, no backup codesClassic problem after a phone upgrade. You are not the first to be locked out.
- My phone is flooded with MFA pushes I did not requestSomeone has your password and is hoping you tap approve to make the spam stop. Do not.
None of the above fits?
Describe your situation below. We pass your input plus the steps you already saw to our AI and return tailored next-step advice. If it's too risky to DIY, we'll say so.
Or skip the DIY entirely
Our Managed IT clients do not look these things up. One point of contact, a fixed monthly price, resolved within working hours.