Cyber security

A practical Microsoft 365 business email compromise response plan

What an Australian small or medium-sized business should contain, preserve, check and recover after a Microsoft 365 account compromise.

First response

Treat suspected business email compromise as both an identity incident and a business-process incident. Containing the account is necessary, but payment instructions, mailbox rules, sessions, delegated access, application consent and affected contacts also need investigation. Preserve evidence before routine clean-up makes the sequence harder to understand.

Work through it in this order

  1. 01

    Activate the decision path

    Name the incident lead, finance contact and technical responder. Record the time, reporter and suspected accounts.

  2. 02

    Contain identity access

    Disable or restrict affected access, revoke sessions, reset credentials safely, review multi-factor authentication (MFA) methods and protect privileged accounts.

  3. 03

    Preserve and inspect

    Retain relevant audit, sign-in and message information; review forwarding, inbox rules, delegates, application consent and unusual administrative changes.

  4. 04

    Protect money and relationships

    Call the bank promptly when payment may be affected. Verify recent supplier and payroll changes using trusted details and notify affected parties carefully.

  5. 05

    Recover and learn

    Remove persistence, re-enable access in a controlled way, monitor for recurrence and repair approval, verification and administrative processes.

From day-to-day administration

Details worth settling early

Investigate the identity and the mailbox

For a smaller Microsoft 365 tenant, a useful order is sign-in activity and active sessions, registered multi-factor authentication methods, forwarding and inbox rules, delegates, application consent, then payment and supplier processes. A password reset on its own does not answer how access was obtained or what changed afterwards.

Finance needs a separate workstream

Technical containment does not cancel a fraudulent transfer. Recent bank-detail changes, supplier payments and payroll instructions need verification through contact details that did not come from the affected mailbox.

Keep these points in view

  • The Australian Signals Directorate lists email compromise and financially damaging business email compromise among the leading reported cybercrime types for business.
  • Use a known-safe channel to verify payment changes; avoid the compromised email thread.
  • Recovery is incomplete until the entry path and business-process weakness are addressed.
  • Finance, identity and communication decisions need one coordinated incident timeline.

Before closing the issue

  • Incident lead named
  • Sessions revoked
  • MFA and app consent reviewed
  • Mailbox rules checked
  • Payment risk escalated
  • Evidence retained
  • Root cause and control changes documented

Easy mistakes under pressure

  • Replying inside a potentially compromised thread
  • Resetting only the password while leaving sessions or malicious rules active
  • Sending broad claims before facts, legal duties and affected parties are understood

Official guidance to keep nearby

  1. Australian Signals Directorate, Australian Cyber Security Centre — Annual Cyber Threat Report 2024–25
  2. Australian Signals Directorate, Australian Cyber Security Centre — Business email compromise
  3. Australian Signals Directorate, Australian Cyber Security Centre — Implementing multi-factor authentication
  4. Microsoft Learn — Microsoft 365 security solutions

Links and technical details checked 2 September 2026. Corrections can be sent to info@turnstoneai.com.

A practical next step

Apply the guidance to the real environment.

Share what is not working, what is changing or what decision needs to be made. Technical answers can come after the business context is clear.