CtrlShiftIT
Security Guides
Identity Security Guide

Stop account takeovers before they become incidents

A plain-English guide to the account takeover paths that matter most in Microsoft 365 environments: phishing, MFA fatigue, password spraying, token theft, BEC, OAuth consent abuse, shared mailbox misuse, and admin compromise.

Who this guide is for

What identity attacks mean in plain English

An identity attack targets the account, session, or permission that proves someone is allowed to access business systems. Instead of breaking into a server first, the attacker tries to sign in as a real person, trick them into approving access, steal their session, or abuse an app permission the user granted.

That is why these attacks feel normal at first. The sign-in may be for a real user. The email may come from a real mailbox. The SharePoint access may use a real token. The defence has to look beyond “was the password correct?” and ask whether the behaviour makes sense for that user, device, location, and business process.

Microsoft 365 offices

Businesses using Exchange Online, Teams, OneDrive, SharePoint, and cloud sign-ins as the center of daily work.

Professional service firms

Law, accounting, consulting, engineering, and advisory firms where email threads often drive approvals and client work.

Clinics and regulated offices

Teams with sensitive scheduling, intake, and client or patient communication that cannot afford messy account recovery.

Estimated reading time14 minutes
Primary systemsMicrosoft 365, Entra ID, email, Teams, SharePoint, OneDrive, finance workflows
Who this guide is forOwners, office managers, clinic administrators, law firms, accountants, consultants, and Microsoft 365 decision-makers at 5-50 employee businesses.
Last reviewedApril 2026
Real-world scenario

Real-world scenario: a small accounting firm during tax season

A bookkeeper receives a Microsoft 365 sign-in prompt after clicking what appears to be a shared document from a client. The password and MFA prompt are completed on a phishing proxy. The attacker captures the active session, searches the mailbox for invoice and payment terms, then creates an inbox rule that hides replies from the firm owner.

Nothing looks like a Hollywood breach. Email still works. The bookkeeper can still sign in. Two days later, a vendor receives updated payment instructions from the compromised mailbox. This is why identity security needs MFA, Conditional Access, mailbox auditing, payment verification, and endpoint monitoring working together.

Phishing link opened

Bookkeeper clicks a fake "shared document" link from a client email.

Credentials submitted

Password and MFA prompt entered on a convincing phishing proxy site.

Session token captured

Attacker authenticates from a separate location using the stolen session.

Inbox rule created

Hidden rule forwards replies and deletes alerts. Owner cannot see replies.

Attack progression

How identity compromise usually unfolds

Most incidents we see are a chain of ordinary-looking events, not one dramatic event.

1. Lure or credential attempt

Phishing email, password spray, MFA prompt fatigue, stolen password, or malicious OAuth consent request.

2. Session or mailbox access

The attacker signs in, steals a token, adds an app permission, or enters through a legacy protocol.

3. Discovery and persistence

Mailbox searches, forwarding rules, MFA method changes, app grants, or hidden inbox rules help maintain access.

4. Business action

Invoice redirection, internal phishing, data download, password resets, or administrator takeover attempts follow.

Identity attack paths

Identity attack paths small businesses should recognize

These attacks overlap. A single incident may start with phishing, continue through token theft, and end as business email compromise.

Initial access

Credential phishing

Fake Microsoft, DocuSign, courier, bank, or file-sharing login page.

MFA, phishing-resistant training, Safe Links, sign-in review.

MFA fatigue

Repeated approval prompts until a user taps approve to make them stop.

Number matching, Conditional Access, user reporting process.

Password spraying

Common passwords tried slowly across many staff accounts.

MFA, smart lockout, legacy auth block, sign-in log monitoring.

Session abuse

Session/token theft

User appears already authenticated from an unusual browser or device.

Conditional Access, session controls, compliant devices, EDR.

Business impact

Business email compromise

Inbox rules, strange sent mail, invoice changes, hidden replies.

Mailbox auditing, forwarding alerts, payment verification.

Persistence

OAuth consent abuse

A user grants a third-party app permission to read mail or files.

Admin consent workflow, app governance, permission reviews.

Operational blind spots

Shared mailbox abuse

Too many users have access, or a shared workflow masks who acted.

Delegate review, audit logs, no shared passwords.

Protocol risk

Legacy authentication

Old mail protocols keep accepting basic authentication paths.

Block legacy auth and review sign-in logs.

Tenant control

Admin takeover

Admin account sign-in from odd location or new MFA method added.

Separate admin accounts, phishing-resistant MFA, alerts.

Warning signs

Signals that point to identity exposure

Impossible travel or unfamiliar sign-ins

A user appears in Toronto and another country within minutes, or signs in from networks never used by the business.

New inbox rules or forwarding

Rules that hide replies, move messages, or forward mail externally are common in BEC cases.

Unexpected MFA changes

New phone numbers, authenticator devices, or security info changes need immediate review.

Suspicious app consent

A user authorizes an app that requests broad mailbox, files, or offline access.

Failed logins across many users

A tenant-wide pattern is more important than one account having a few failed attempts.

Payment or vendor changes by email only

Banking changes should be verified through a known out-of-band method, not the same email thread.

First steps

Where to start with identity security

Enforce MFA everywhere

Start with admins, owners, finance, and high-risk users, then cover every human account.

Turn on Conditional Access where licensed

Require stronger checks for risky sign-ins, unmanaged devices, admins, and external locations.

Disable legacy authentication

Remove POP, IMAP, and basic SMTP paths that can weaken MFA enforcement.

Review mailbox rules and app permissions

Look for external forwarding, hidden rules, and broad OAuth grants.

Protect endpoints

Token theft and browser credential theft often start on a compromised device.

Document payment verification

Make staff comfortable pausing and verifying payment changes before money moves.

Incident response

What to do when an account is suspected compromised

1. Contain the account

Revoke sessions, reset the password, reset MFA methods, and temporarily block sign-in if ownership is uncertain.

2. Preserve evidence

Export sign-in logs, mailbox audit records, inbox rules, forwarding settings, and suspicious messages before cleanup.

3. Hunt for persistence

Check OAuth app grants, new MFA devices, hidden mailbox rules, delegated access, external forwarding, and admin role changes.

4. Protect money movement

Warn finance and client-facing staff, verify any payment changes out-of-band, and review recent invoice or banking requests.

5. Reset affected trust

Rotate exposed credentials, review device health, remove risky app consent, and notify impacted contacts when needed.

6. Close the control gap

Document the entry path, tighten Conditional Access or mailbox controls, and add monitoring so the same path is visible next time.

Licensing path

Controls available at each licence level

What you can enforce depends on what Microsoft 365 plan your business uses.

Security Defaults / basics

Useful for very small tenants that need MFA on quickly.

  • Enable MFA baseline coverage
  • Block obvious legacy sign-in paths
  • Review admin accounts manually

Microsoft 365 Business Premium

Best practical target for most 5-50 person professional offices.

  • Conditional Access policies
  • Intune device compliance
  • Defender for Business and stronger identity controls

Higher-risk roles

Owners, finance, admins, partners, and users handling sensitive client records.

  • Phishing-resistant MFA where practical
  • Separate admin accounts
  • Tighter alerts and session review
ops@ctrlshiftit: ~/identity-security

Want a practical identity risk review?

CtrlShift IT Services can review your Microsoft 365 sign-in policies, MFA coverage, mailbox rules, admin accounts, endpoint protection, and identity logs so you know where the real gaps are.

Microsoft 365 identity baselineEndpoint and browser protectionEmail and mailbox controlsOperational response
FAQ

Identity security questions answered

FAQ

Common questions

4 results
SecurityAre identity attacks mostly a Microsoft 365 problem?

Microsoft 365 is a common target because email, files, Teams, and identity all meet there. The same principles apply to Google Workspace, accounting portals, CRM systems, and remote access tools.

SecurityCan MFA be bypassed?

MFA greatly reduces risk, but active session theft, phishing proxies, OAuth consent abuse, and compromised devices can still create access. That is why Conditional Access, endpoint protection, and logging matter.

SecurityWhat should we check first after a suspected mailbox compromise?

Revoke sessions, reset the password and MFA methods, review inbox and forwarding rules, check sign-in logs, inspect sent mail, and preserve audit logs before cleanup.

SecurityDo small businesses need separate admin accounts?

Yes. Admin accounts should be separate from daily email accounts, protected with strong MFA, and used only for administration.