Microsoft 365 business email compromise is the incident that most UK businesses are least ready for and most likely to suffer. It does not announce itself. There is no ransom note, no encrypted file share, no screen full of skulls. There is just a finance manager, three weeks later, asking why the supplier is chasing an invoice that was definitely paid.
That quietness is the whole problem. A Microsoft 365 security audit will tell you how exposed you are before anything happens, but once an attacker is already inside a mailbox the questions change entirely: what do we do in the next hour, what must we not touch, who do we have to tell, and how do we know they are gone. Those questions need answering in advance, in writing, by somebody who is not panicking.
This guide is a working Microsoft 365 business email compromise response plan for organisations of roughly ten to three hundred staff running Business Premium, E3 or E5. It covers containment, evidence, investigation, the money, notification, recovery and prevention, in the order you will actually need them. It assumes a competent IT person or provider at the keyboard, not a forensics specialist on a retainer.
One warning before the detail. The instinct during a Microsoft 365 business email compromise is to clean up fast — delete the rules, reset the password, move on. That instinct destroys the evidence you need to answer the only question that matters, which is what the attacker read and what they sent. Contain first, investigate second, clean third. In that order, every time.
Table of contents
- Why Microsoft 365 business email compromise works so reliably
- The first sixty minutes of a Microsoft 365 business email compromise
- Microsoft 365 business email compromise evidence you must collect first
- How to investigate a Microsoft 365 business email compromise properly
- Money, invoices and the recall clock
- Notifying staff, customers, insurers and the regulator
- Recovering the tenant after a Microsoft 365 business email compromise
- Preventing the next Microsoft 365 business email compromise
- Writing the Microsoft 365 business email compromise response plan
- Frequently asked questions about Microsoft 365 business email compromise
Why Microsoft 365 business email compromise works so reliably
Understanding the mechanics of a Microsoft 365 business email compromise is not academic. Every step of the response plan below exists because of something in this section.
Attackers log in rather than break in
There is no exploit in a typical Microsoft 365 business email compromise. Somebody enters a real username and a real password on a convincing fake sign-in page, and the attacker replays them. Microsoft’s platform behaves exactly as designed, which is why nothing alerts, nothing crashes, and your antivirus stays silent for weeks.
Token theft has quietly weakened MFA
Modern phishing kits sit between the user and the real Microsoft login, relay the multi-factor prompt in real time, and steal the resulting session token. The user approves a prompt they genuinely triggered. The attacker inherits an authenticated session. This is why “we have MFA” is no longer a complete answer, and why a Microsoft 365 business email compromise response plan has to assume MFA can be defeated.
The mailbox is both the crime scene and the weapon
Once inside, the attacker does not need malware. They read months of correspondence, learn who authorises payments and how your invoices are phrased, then send mail as the account owner. The compromised mailbox becomes a trusted launchpad against your customers, and its reply-to history makes the fraud almost impossible to spot.
Finance and payroll are the destination
Most intrusions wander until they find money. Finance mailboxes, accounts inboxes and directors’ accounts are the prize, but a marketing account with visibility of supplier threads is a perfectly good stepping stone. Lateral movement inside a tenant is usually just an internal email that nobody questions.
What it actually costs a UK business
The direct loss from a Microsoft 365 business email compromise is the diverted payment, frequently between fifteen and eighty thousand pounds for a mid-sized firm. The indirect costs are larger: forensic time, legal advice, customer notification, insurance excess, and the awkward call to a client whose money went somewhere else. Serious cybersecurity planning treats the second list as the real number.
The first sixty minutes of a Microsoft 365 business email compromise
Speed matters here, but only in specific ways. Doing the wrong fast thing is worse than doing nothing for ten minutes.
Do not delete anything yet
Not the inbox rules. Not the suspicious messages. Not the sign-in log entries you are about to screenshot. In a Microsoft 365 business email compromise the rules an attacker creates are timestamped evidence of when they arrived and what they were hunting for. Deleting them at minute two costs you the entire timeline, and you will need that timeline for your insurer and possibly for the regulator.
Revoke sessions, not just the password
A password reset alone does nothing to a stolen session token. The attacker stays signed in and simply watches you change it. Reset the credential and then revoke all refresh tokens for that user, which invalidates every existing session across Outlook, the web, mobile and any connected application. If you only remember one technical instruction from this Microsoft 365 business email compromise response plan, make it this one.
Block sign-in for the account
Blocking sign-in is heavier than a reset and appropriate while you work. It stops the attacker returning through any path you have not yet closed, including an app password or a device you have not found. Warn the user’s manager that the account is going dark for a few hours and route their calls elsewhere.
Freeze payment changes across the business
Any bank detail change, any new supplier, any unusual payment request is now suspended pending a voice call to a known number. Say this to the whole finance team immediately, not just to the compromised user, because the fraudulent instruction may already be sitting in somebody else’s inbox awaiting action.
Put one named person in charge
A Microsoft 365 business email compromise fails or succeeds on coordination, not on technical skill. One person owns the decisions, keeps the log, and is the only voice communicating status. Everybody else does tasks. This is standard incident response practice and it matters more at hour one than any tooling you own.
Microsoft 365 business email compromise evidence you must collect first
This section is what separates a response from a guess. Collect all of it, export it, and store it outside the tenant.
Sign-in logs are the arrival record
Pull the sign-in logs for the affected user covering at least ninety days, because a Microsoft 365 business email compromise is usually older than the day you found it. You are looking for successful sign-ins from unexpected countries, hosting providers and autonomous systems, and for the specific pattern of a legitimate sign-in immediately followed by one from somewhere else. Note the timestamps, because everything else anchors to them.
The unified audit log is the activity record
The unified audit log records mailbox access, rule creation, file access and consent grants. Search it for the compromised account across the same period. Be aware that retention depends on licence — ninety days on many plans, longer on E5 — which is a genuine argument for the higher tier that nobody makes until the week they need it.
Inbox rules and their creation timestamps
Export every rule on the mailbox before touching it. Attacker rules are recognisable: they move messages containing “invoice”, “payment”, “bank” or “remittance” into Archive, RSS Feeds, Conversation History or a folder named with a single character, and they often mark them read. The creation timestamp tells you when the attacker arrived, which is usually earlier than anyone expects.
Forwarding exists at three separate levels
Check mailbox forwarding, transport rules and inbox-rule forwarding. They are configured in different places and a Microsoft 365 business email compromise commonly uses more than one so that removing the obvious one restores nothing. Tenant-wide external forwarding should be off; if it is on, that is a finding in its own right.
OAuth grants and consented applications
Look at the applications the user has consented to and the service principals in the tenant. A malicious OAuth grant survives password resets, MFA re-enrolment and session revocation, because it is a separate authorisation path entirely. This is the single most common reason a Microsoft 365 business email compromise appears to recur a fortnight later.
Message trace tells you what left
Run a message trace for the whole exposure window and export it. You need to know how many messages were sent from the account, to whom, and with what subject lines. That export becomes the basis of your customer notification list and, if it comes to it, your evidence that a given customer was never contacted.
How to investigate a Microsoft 365 business email compromise properly
You now have the raw material of the Microsoft 365 business email compromise. Investigation is the process of turning it into two answers: what did they read, and what did they send.
Read the rules as statements of intent
In a Microsoft 365 business email compromise an attacker’s rules describe their objective. A rule hiding anything containing “invoice” means they were running payment diversion. A rule hiding messages from your IT provider means they expected to be reported and wanted the user not to see the warning. A rule hiding a specific customer’s domain means that customer is already being targeted.
Reconstruct the payment conversations
Search the mailbox for the threads the rules were hiding. Look for altered bank details, changed remittance addresses and any message where the reply came from a lookalike domain rather than the genuine one. Lookalike domains are the tell — one character different, registered days before the fraud.
Establish whether the attacker moved sideways
Check whether the compromised account sent internal mail during the window, and whether any recipient then showed unusual sign-ins. A single successful internal phish turns one incident into three, and a Microsoft 365 business email compromise that has spread needs the whole containment sequence run again per account.
Do not stop at email
A Microsoft 365 business email compromise is never confined to the mailbox, because Entra ID accounts reach SharePoint, OneDrive and Teams. Review file access and download activity for the same window, particularly bulk downloads and newly created anonymous sharing links. Attackers take contract documents and client lists because those enable the next fraud, not because they intend to publish them.
Decide honestly whether personal data left
This is a judgement call with legal consequences, and it should be made from the message trace and file access logs rather than from optimism. If a mailbox containing personal data was accessible for six weeks, the defensible position is that its contents were accessible, not that the attacker probably was not interested. Sound data protection practice starts from what was possible.
Money, invoices and the recall clock
If a payment has already gone, the next few hours decide whether any of it comes back.
Call the bank within the hour
The financial half of a Microsoft 365 business email compromise moves faster than the technical half. Ask specifically for the fraud team and use the words “authorised push payment fraud”. Same-day recall has a genuine chance of success; the odds fall sharply after the funds are moved on, which is typically within hours. Do this before you finish the technical investigation — the bank call is not something to schedule for the afternoon.
Report to Action Fraud and your insurer
Report the crime to Action Fraud, the UK’s national reporting centre for fraud and cybercrime, and get the reference number. Notify your insurer the same day, because most cyber policies impose a notification deadline measured in hours and will decline a late claim on that basis alone.
Warn everybody in that mailbox
Every supplier and customer who corresponded with the account during the exposure window needs a warning that mail from it may have been fraudulent, sent from a different address and ideally followed by a phone call. This is uncomfortable and it is also the step that stops the incident spreading down your supply chain.
Rebuild the payment change process
The control that actually prevents recurrence is procedural, not technical: bank detail changes are verified by voice call to a number already on file, never to a number supplied in the email requesting the change. Write it down, make it mandatory, and make it apply to the finance director as well.
Notifying staff, customers, insurers and the regulator
Notification is where a technically competent Microsoft 365 business email compromise response often falls apart, because the deadlines are legal rather than operational.
The 72-hour clock and when it starts
Under UK GDPR the clock starts when you become aware of a personal data breach, not when you finish investigating it. Seventy-two hours to notify the ICO where the breach is likely to result in a risk to individuals. Regulators are markedly more forgiving of an incomplete notification submitted on time than a complete one submitted late.
What to tell customers, and how
Tell them what happened, over what dates, what to do about it, and how to verify future communications from you. Do not speculate about attribution, and do not promise it cannot happen again. Customers respond well to a plain account and badly to corporate reassurance that later turns out to have been premature.
Keep a decision log throughout
Record every decision in the Microsoft 365 business email compromise, the time it was made, who made it and why. This is tedious in the moment and invaluable afterwards, when your insurer, your customers and possibly the ICO each ask a version of “when did you know”. Without a log you are reconstructing it from memory weeks later.
The insurer conditions you may already be breaching
Many cyber policies require MFA on all accounts, notification within a set window, and preservation of evidence. Read your policy before an incident, because discovering an exclusion during a claim is an expensive way to learn what it said.
Recovering the tenant after a Microsoft 365 business email compromise
Recovering from a Microsoft 365 business email compromise is not “reset the password and hope”. It is the systematic removal of every path back in.
Reset credentials in the right order
Reset the compromised account, then any account it emailed internally that shows unusual activity, then privileged accounts as a precaution. Revoke sessions after each reset rather than at the end, and confirm that any app passwords are removed — legacy app passwords bypass MFA entirely.
Remove persistence, all of it
Delete the inbox rules once you have exported them. Remove forwarding at all three levels. Revoke malicious OAuth grants and, where appropriate, remove the service principal. Check for newly registered MFA methods and enrolled devices, and remove anything the user does not recognise. Persistence is why an incomplete recovery from a Microsoft 365 business email compromise reappears within weeks.
Re-enrol MFA rather than trusting it
If an attacker registered their own authenticator, changing the password achieves nothing. Delete the registered methods and have the user re-enrol in person or on a verified video call. Treat any method registered during the exposure window as attacker-controlled until proven otherwise.
Decide what happens to the mailbox
For a badly contaminated mailbox with months of attacker access, some organisations create a new address and retire the old one. That is disruptive and occasionally correct. More often, thorough cleaning plus enhanced monitoring for a month is proportionate — but make it a decision, not a default.
Watch the account for a fortnight
Set alerts for sign-ins to the recovered account from unexpected locations, for new inbox rules, and for new consent grants. Two weeks of deliberate attention catches the return visit. Ongoing IT security monitoring is what turns that fortnight of vigilance into a permanent capability.
Preventing the next Microsoft 365 business email compromise
Every control below is cheaper than the incident you just worked through, and most are included in licences you already own.
Conditional Access is the control that matters most
Most Microsoft 365 business email compromise activity arrives from somewhere your staff have never worked. Block sign-ins from countries you do not operate in, require compliant or hybrid-joined devices for mail access, and require reauthentication for risky sign-ins. Conditional Access stops the replay of stolen credentials from unexpected places better than any awareness training will, and it is the highest-value hour of configuration available to you.
Move to phishing-resistant MFA
Number matching and push notifications are a meaningful improvement over SMS, but only FIDO2 security keys, passkeys and Windows Hello for Business are genuinely resistant to real-time relay attacks. Start with finance, directors and IT administrators — the accounts a Microsoft 365 business email compromise is actually aiming at.
Turn off legacy authentication
Legacy protocols such as IMAP, POP and basic SMTP authentication bypass Conditional Access and MFA entirely. Block them tenant-wide. Find the two ancient devices that will break, fix them properly, and close the door for good.
Restrict user consent to applications
Users should not be able to grant applications access to their mailbox without review. Switch to admin consent with a request workflow. This single setting removes the most durable persistence mechanism attackers have in Microsoft 365, and almost nobody notices the change day to day.
Impersonation protection, DMARC and external tagging
Configure anti-phishing impersonation protection for your directors and finance staff, publish DMARC with an enforcing policy, and make sure external senders are visibly tagged in Outlook. Lookalike domain fraud relies on the recipient not looking closely; tagging makes looking closely automatic.
Alerting that reaches an actual human
Configure alerts for new inbox rules, new forwarding, impossible-travel sign-ins and consent grants — then confirm somebody reads them. Alerts routed to an unmonitored shared mailbox are a comfort blanket, and this is exactly the gap a Microsoft 365 security audit is designed to surface before an incident does.
Train the workflow, not just the people
Awareness training helps, but people click links; that is not a character flaw. The durable fix is a payment process that cannot be completed on the strength of an email alone. Design the workflow so that a successful phish is not sufficient to move money, and the fraud stops paying.
Writing the Microsoft 365 business email compromise response plan
A plan that lives in somebody’s head is not a plan. This is the artefact you should have before you need it.
One page, not thirty
Nobody reads a thirty-page runbook at 4pm on a Friday. One page: first actions, who to call, what not to delete, and where the detail lives. Every serious Microsoft 365 business email compromise response plan I have seen work in practice fits on a single side of paper.
Name roles, not individuals
Incident lead, technical lead, communications lead, finance lead. Named people leave, go on holiday and are occasionally the compromised user. Roles survive the org chart, and the plan should list a deputy for each.
List the numbers you will need under stress
Bank fraud line, insurer’s notification line, IT provider’s out-of-hours number, Action Fraud, and the ICO reporting page. Nobody should be searching for a phone number during an incident, and the list should exist on paper as well as online.
Rehearse it once a year
Ninety minutes around a table, one realistic scenario, no laptops. You are not testing whether people know the answers; you are finding the two steps that do not work — the alert that goes nowhere, the person on leave, the log that was never enabled. A managed IT services partner should run this with you, not for you.
Store it where the incident cannot reach it
A response plan stored only in the tenant you have lost access to is not available when it matters. Keep a copy offline and a copy with your provider. The same logic applies to your contact list and your evidence exports.
Frequently asked questions about Microsoft 365 business email compromise
Does MFA prevent it?
It prevents the majority of credential stuffing and simple phishing, and no Microsoft 365 business email compromise defence works without it. It does not prevent real-time relay attacks that steal session tokens, which is why Conditional Access and phishing-resistant methods matter for high-value accounts. Treat MFA as necessary, not sufficient.
How long do attackers usually stay?
Frequently weeks. They are waiting for a payment conversation worth hijacking, and the audit log timestamps on the inbox rules usually reveal an arrival date well before anyone noticed. Assume a longer window than feels intuitive until the evidence narrows it.
Do we have to tell the ICO?
If personal data was likely accessed and there is a risk to individuals, yes, within seventy-two hours of becoming aware. A compromised mailbox at a business handling customer data usually meets that test. Take the decision deliberately, record the reasoning, and notify when in doubt.
Is the built-in retention enough for an investigation?
Often only just. Standard audit retention of ninety days is workable for an incident discovered quickly and insufficient for one discovered late. If your business is exposed to payment fraud, longer retention is a defensible cost. Wider business email compromise research consistently shows detection lagging intrusion by weeks.
Who should own this in a small business?
The finance director and the IT provider jointly, because the controls are half technical and half procedural. A Microsoft 365 business email compromise is a fraud problem delivered by an email system, and a plan owned only by IT will miss the payment process that actually stops the loss.