If you believe your Microsoft 365 account has been compromised and you are unable to send emails, follow these steps to secure your account:
- Reset Your Password: Immediately reset your password to prevent further unauthorized access.
- Revoke User Access: Use PowerShell to revoke any active sessions. You can run the following command in an elevated PowerShell window:
ReplaceRevoke-MgUserSignInSession -UserId <YourEmailAddress><YourEmailAddress>with your actual email address. - Check for Suspicious Activity: Look for unusual activity in your mailbox, such as missing emails or unexpected changes in your contacts. If you notice any suspicious inbox rules (like forwarding emails to unknown addresses), remove them.
- Review MFA Devices: Check the Multi-Factor Authentication (MFA) settings and remove any unrecognized devices or methods.
- Scan for Malware: Ensure that your devices are free from malware by running a comprehensive scan.
- Notify Your Administrator: If you are part of an organization, inform your IT administrator about the compromise so they can assist you further.
- Enable MFA: If you haven't already, enable Multi-Factor Authentication to enhance your account security moving forward.
Following these steps can help you regain control of your account and secure it against future compromises.
References: