What to Do After a Suspicious Login Alert in Microsoft 365
Step-by-step response to a suspicious login alert in Microsoft 365 including securing the account, reviewing sign-in activity, checking forwarding rules, and preventing recurrence.
Immediate steps when you get an alert
- Change the password immediately for the flagged account.
- Sign out of all sessions. Microsoft 365 admin center lets you sign out a user from all devices.
- Enable or reset MFA if it was not already enabled.
- Check recent sign-in activity for unusual locations, devices, and IP addresses.
Check for signs of compromise
- Review email forwarding rules. Attackers often create hidden rules to monitor email.
- Check sent items for emails the user did not send.
- Look for new inbox rules that delete or redirect incoming messages.
- Check for unauthorized application registrations or OAuth consent grants.
Prevent recurrence
- Enable MFA for all users. The single most effective protection against account compromise.
- Enable security defaults or Conditional Access policies to block sign-ins from unexpected locations.
- Configure alerts for risky sign-ins, impossible travel, and unfamiliar locations.
- Train staff to recognize and report phishing attempts.
Frequently Asked Questions
How do I know if a suspicious login alert is real?
Log into the Microsoft Entra admin center and review the sign-in logs directly. Look at the IP address, location, device, and application used. If the details do not match your expected sign-in patterns, treat it as real and take immediate action.
How quickly do I need to respond to a suspicious login alert?
Immediately. Attackers can send phishing emails, access sensitive data, or change account settings within minutes of gaining access. The faster you respond, the less damage is likely.
Need help?
Maine CyberTech helps Maine businesses respond to security incidents, review Microsoft 365 security settings, and implement MFA and Conditional Access. Contact us for incident response assistance.
Contact Us