Managing security settings and protections in Outlook on the web for business
Follow these steps immediately to regain control of the mailbox and stop the malicious behavior:
- Secure the account credentials
- Change the account password again from a trusted device and network.
- Ensure the new password is strong and unique and not reused on any other site.
- Turn on multi-factor authentication (MFA) for the account if not already enabled. MFA blocks most password-based attacks.
- Sign out attackers and remove their access
- From the Microsoft account security page, use the option to sign out of all active sessions so any attacker sessions are terminated.
- Review and remove any unknown or suspicious app permissions or connected apps that might be maintaining access.
- Clean up malicious mailbox rules and forwarding Compromised Microsoft 365 mailboxes often show exactly what is being described: missing or deleted mail, suspicious sent items, and rules that hide or move messages.
In Outlook on the web for business:
- Go to Settings → Mail → Rules and delete any rules that:
- Automatically forward email to unknown addresses.
- Move messages to Notes, Junk Email, RSS Subscriptions, or other unexpected folders.
- Go to Mail → Forwarding and remove any external forwarding addresses that were not configured.
- Check Automatic replies and signatures for any suspicious content that might be sending links or instructions to recipients.
- Check folders for evidence of compromise
- Review Sent Items and Deleted Items for suspicious messages (for example, messages asking others to click a link and enter a code, or “proposal” emails that were not sent).
- If messages are disappearing, verify that no rules are deleting or moving them as described above.
- Coordinate with the Microsoft 365 admin (master account / boss) Since the account was previously blocked and unblocked by the master account:
- Ask the admin to:
- Review sign-in logs and security alerts for the account.
- Check for any external forwarding configured at the tenant level.
- Use Microsoft Defender for Office 365 tools (if available) to detect and remediate malicious rules and forms in the mailbox.
- Inform contacts and limit damage
- Notify the people who received the fraudulent “proposal” emails that the account was compromised and that they should:
- Not click any links.
- Not enter codes or credentials.
- If they already clicked, advise them to change their passwords and enable MFA on their own accounts.
- Monitor for recurring compromise
- After cleanup, continue to monitor:
- For new suspicious rules or forwarding.
- For unusual sign-ins, password changes, or account lockouts.
- For new suspicious messages in Sent Items.
If the symptoms listed in the Microsoft guidance for compromised accounts (blocked sending, suspicious rules, missing mail, external forwarding, etc.) continue after these steps, follow the full remediation guidance for compromised cloud email accounts and, if necessary, escalate through the organization’s security or IT team.
References:
- Respond to a compromised cloud email account
- Common symptoms of a compromised Microsoft 365 email account
- Help protect your Outlook.com email account
- Phishing and suspicious behavior in Outlook
- How to recover a hacked or compromised Microsoft account
- What to do if your email address is leaked
- My account got hacked. - Microsoft Q&A
- My account got hacked - Microsoft Q&A
- My personal hotmail account hacked by hacker with authentication app enabled. - Microsoft Q&A
- How do I send an email to Microsoft about my account being hacked and taken over by <removed> ? - Microsoft Q&A
- Hacker set up continuous draft ransomware email - Microsoft Q&A