Detecting and Responding to Credential Theft in Microsoft 365 Environments A single compromised Microsoft 365 account can quickly escalate into mailbox abuse, SharePoint or OneDrive data exfiltration, business email compromise, or even tenant-wide privilege escalation. In this video, we'll show you a practical, incident-driven approach to detecting and responding to credential theft using built-in Microsoft 365 and Microsoft Entra ID capabilities. Before we begin, be sure to subscribe to NinjaOne's IT video hub and our YouTube channel for more tech content like this. How to Detect and Respond to Credential Theft in Microsoft 365 Step One: Enable Audit Logging and Sign-In Visibility Audit logging must be enabled in the Microsoft 365 Compliance Center, so that user and admin activity is recorded in the Unified Audit Log. Azure AD sign-in logs are your primary detection source. These logs allow you to quickly surface: risky or flagged sign-ins, logins from unfamiliar or high-risk locations, legacy authentication attempts. Step Two: Detect Suspicious Activity. Key red flags to look out for include impossible travel scenarios, repeated failed sign-in attempts, use of legacy authentication protocols like IMAP or POP, and browser- based logins from suspicious IP addresses. For MSPs and administrators managing multiple tenants, PowerShell enables faster triage. As an example, here's a simple Microsoft Graph query to pull risky sign-ins: For more advanced filtering, automation, and cross-tenant queries, refer to the full scripts in the blog. Step Three: Investigate Mailbox Abuse Threat actors frequently create inbox rules or forwarding rules to silently exfiltrate data. These rules often persist even after a password reset if they are not explicitly removed. Using Exchange Online PowerShell, you can quickly identify suspicious rules. For example, you should also review mailbox audit logs for unusual access patterns, especially for executives, finance users, or shared mailboxes. Step Four: Isolate and Reset the Compromised Account. Your immediate goals are to revoke active sessions, reset credentials, and block further access while the investigation continues. A common response sequence includes revoking refresh tokens and forcing a password reset. For example, this script instantly invalidates existing sessions across devices and applications. From there, you can force a password reset and temporarily block sign-in if needed. Full remediation workflows are covered in detail in the blog. Step Five: Harden Access to Prevent Recurrence Your focus should now shift to preventing the next incident. Microsoft Entra ID Conditional Access should be doing most of the heavy lifting here. At a minimum, you should: require MFA for all users, block legacy authentication entirely, apply location-based or device-based access controls. On the endpoint side, Group Policy can still play a role by enforcing strong password policies and supporting smart card or MFA-based authentication. Step Six: Monitor Continuously and Automate Response Continuous monitoring is critical. Microsoft Defender for Identity and Defender for Cloud Apps provide native alerting for suspicious behavior, including unusual mailbox access and risky sign-ins. For local systems, basic PowerShell monitoring can help detect repeated authentication failures, for example: While this is not a replacement for SIEM or Defender tooling, it's useful for quick validation during an incident. Credential theft isn't going away, but with the right visibility, response playbooks, and preventive controls, Microsoft 365 can be defended effectively. For more information, check out our official blog post on detecting and responding to credential theft in Microsoft 365 environments, linked in the description below.