Microsoft 365 offices
Businesses using Exchange Online, Teams, OneDrive, SharePoint, and cloud sign-ins as the center of daily work.
A plain-English guide to the account takeover paths that matter most in Microsoft 365 environments: phishing, MFA fatigue, password spraying, token theft, BEC, OAuth consent abuse, shared mailbox misuse, and admin compromise.
An identity attack targets the account, session, or permission that proves someone is allowed to access business systems. Instead of breaking into a server first, the attacker tries to sign in as a real person, trick them into approving access, steal their session, or abuse an app permission the user granted.
That is why these attacks feel normal at first. The sign-in may be for a real user. The email may come from a real mailbox. The SharePoint access may use a real token. The defence has to look beyond “was the password correct?” and ask whether the behaviour makes sense for that user, device, location, and business process.
Businesses using Exchange Online, Teams, OneDrive, SharePoint, and cloud sign-ins as the center of daily work.
Law, accounting, consulting, engineering, and advisory firms where email threads often drive approvals and client work.
Teams with sensitive scheduling, intake, and client or patient communication that cannot afford messy account recovery.
A bookkeeper receives a Microsoft 365 sign-in prompt after clicking what appears to be a shared document from a client. The password and MFA prompt are completed on a phishing proxy. The attacker captures the active session, searches the mailbox for invoice and payment terms, then creates an inbox rule that hides replies from the firm owner.
Nothing looks like a Hollywood breach. Email still works. The bookkeeper can still sign in. Two days later, a vendor receives updated payment instructions from the compromised mailbox. This is why identity security needs MFA, Conditional Access, mailbox auditing, payment verification, and endpoint monitoring working together.
Bookkeeper clicks a fake "shared document" link from a client email.
Password and MFA prompt entered on a convincing phishing proxy site.
Attacker authenticates from a separate location using the stolen session.
Hidden rule forwards replies and deletes alerts. Owner cannot see replies.
Most incidents we see are a chain of ordinary-looking events, not one dramatic event.
Phishing email, password spray, MFA prompt fatigue, stolen password, or malicious OAuth consent request.
The attacker signs in, steals a token, adds an app permission, or enters through a legacy protocol.
Mailbox searches, forwarding rules, MFA method changes, app grants, or hidden inbox rules help maintain access.
Invoice redirection, internal phishing, data download, password resets, or administrator takeover attempts follow.
These attacks overlap. A single incident may start with phishing, continue through token theft, and end as business email compromise.
Fake Microsoft, DocuSign, courier, bank, or file-sharing login page.
MFA, phishing-resistant training, Safe Links, sign-in review.
Repeated approval prompts until a user taps approve to make them stop.
Number matching, Conditional Access, user reporting process.
Common passwords tried slowly across many staff accounts.
MFA, smart lockout, legacy auth block, sign-in log monitoring.
User appears already authenticated from an unusual browser or device.
Conditional Access, session controls, compliant devices, EDR.
Inbox rules, strange sent mail, invoice changes, hidden replies.
Mailbox auditing, forwarding alerts, payment verification.
A user grants a third-party app permission to read mail or files.
Admin consent workflow, app governance, permission reviews.
Too many users have access, or a shared workflow masks who acted.
Delegate review, audit logs, no shared passwords.
Old mail protocols keep accepting basic authentication paths.
Block legacy auth and review sign-in logs.
Admin account sign-in from odd location or new MFA method added.
Separate admin accounts, phishing-resistant MFA, alerts.
Each guide covers one attack path in depth — how it works, what it costs a small business, and where to start.
How password spray attacks work, why MFA and Conditional Access matter, and what small businesses should monitor.
Read guideHow attackers steal session tokens, why users may appear legitimately signed in, and how Conditional Access helps reduce risk.
Read guideWhy old authentication protocols create account takeover risk in Microsoft 365 environments.
Read guideHow mailbox compromise leads to invoice fraud, forwarding rules, and client impersonation.
Read guideA user appears in Toronto and another country within minutes, or signs in from networks never used by the business.
Rules that hide replies, move messages, or forward mail externally are common in BEC cases.
New phone numbers, authenticator devices, or security info changes need immediate review.
A user authorizes an app that requests broad mailbox, files, or offline access.
A tenant-wide pattern is more important than one account having a few failed attempts.
Banking changes should be verified through a known out-of-band method, not the same email thread.
Start with admins, owners, finance, and high-risk users, then cover every human account.
Require stronger checks for risky sign-ins, unmanaged devices, admins, and external locations.
Remove POP, IMAP, and basic SMTP paths that can weaken MFA enforcement.
Look for external forwarding, hidden rules, and broad OAuth grants.
Token theft and browser credential theft often start on a compromised device.
Make staff comfortable pausing and verifying payment changes before money moves.
Revoke sessions, reset the password, reset MFA methods, and temporarily block sign-in if ownership is uncertain.
Export sign-in logs, mailbox audit records, inbox rules, forwarding settings, and suspicious messages before cleanup.
Check OAuth app grants, new MFA devices, hidden mailbox rules, delegated access, external forwarding, and admin role changes.
Warn finance and client-facing staff, verify any payment changes out-of-band, and review recent invoice or banking requests.
Rotate exposed credentials, review device health, remove risky app consent, and notify impacted contacts when needed.
Document the entry path, tighten Conditional Access or mailbox controls, and add monitoring so the same path is visible next time.
What you can enforce depends on what Microsoft 365 plan your business uses.
Useful for very small tenants that need MFA on quickly.
Best practical target for most 5-50 person professional offices.
Owners, finance, admins, partners, and users handling sensitive client records.
CtrlShift IT Services can review your Microsoft 365 sign-in policies, MFA coverage, mailbox rules, admin accounts, endpoint protection, and identity logs so you know where the real gaps are.
FAQ
Microsoft 365 is a common target because email, files, Teams, and identity all meet there. The same principles apply to Google Workspace, accounting portals, CRM systems, and remote access tools.
MFA greatly reduces risk, but active session theft, phishing proxies, OAuth consent abuse, and compromised devices can still create access. That is why Conditional Access, endpoint protection, and logging matter.
Revoke sessions, reset the password and MFA methods, review inbox and forwarding rules, check sign-in logs, inspect sent mail, and preserve audit logs before cleanup.
Yes. Admin accounts should be separate from daily email accounts, protected with strong MFA, and used only for administration.