7 Warning Signs Your Small Business Might Be Hacked
Updated: Sep 1

Updated August 2026: I originally published this article in April 2025, but the ways I look for signs of a possible business compromise continue to evolve. I have updated it to include current Microsoft 365 and Entra ID security signals, unexpected MFA activity, Risky Users and Risky Sign Ins, suspicious mailbox rules and forwarding, endpoint and RMM alerts, evidence preservation, and other indicators I now look at when something does not seem right in a client's environment.
When most business owners picture a cyberattack, they picture something obvious. Maybe a ransomware message appears on a computer, an employee suddenly cannot access an account, or files become unavailable. Those things certainly happen, but some of the compromises I am more concerned about are much quieter. Someone who gains access to a business email account may benefit from remaining unnoticed while they monitor conversations, manipulate email rules, look for financial information, or wait for an opportunity to insert themselves into a legitimate business transaction.
The first indication of a problem may not come from an employee at all. It may come from Microsoft Entra identifying a risky user or risky sign in, an endpoint security alert, an RMM platform showing that a device is no longer reporting properly, a firewall or other security platform showing unexpected activity, or a customer calling about a message nobody inside the business remembers sending. This is why I do not think the question is simply, “What does a hacked computer look like?” A better question for a business owner is,
“How would we know if something happening in our environment could be a sign of an account or system compromise?”
There is rarely one warning sign that proves a small business has been hacked. A legitimate employee can trigger a security alert.. A legitimate employee can trigger a security alert. A computer can run slowly for perfectly ordinary reasons. A user traveling for work can create sign in activity that looks different from their normal pattern. I want enough visibility into an environment to notice something unusual, investigate it, and make a determination based on the information available rather than either assuming everything is an attack or dismissing something important.
1. Unexpected Sign Ins, MFA Prompts, or Account Changes
Identity and authentication activity are some of the first things I look at when something does not seem right in a Microsoft 365 environment. An employee may receive a Microsoft Authenticator request they did not initiate, get locked out unexpectedly, notice an authentication method they do not recognize, or encounter another account change they cannot explain. Behind the scenes, Microsoft Entra can provide additional information about sign ins, users, devices, locations, applications, IP addresses, and identity risk that helps put those events into context.
One of the simplest things I tell users is not to approve an MFA request they did not initiate just because it appeared on their phone. An unexpected authentication request is worth reporting. It may turn out to have an innocent explanation, but I would rather know about it while I still have the opportunity to investigate the surrounding activity.
Why I Review Risky Users and Risky Sign Ins
For Microsoft 365 environments where the appropriate Microsoft Entra ID Protection capabilities are available, I like having visibility into Risky Users, Risky Sign Ins, and risk detections. Microsoft analyzes identity signals and can flag activity that may warrant further investigation. I can then look at details such as the application being accessed, device, location, IP address, user activity, and other available security information to determine whether the activity makes sense for that particular user.
I do not automatically treat every Microsoft risk detection as proof that an account has been compromised. Microsoft provides administrators with ways to classify risk after investigation, including confirming a user as compromised, confirming a user as safe when an alert is a false positive, or dismissing benign risk. I have seen activity that deserved investigation but ultimately had a legitimate explanation. I would still rather receive the signal, investigate it, and make that determination than never know the unusual activity occurred in the first place.
This is also an example of why I distinguish between owning Microsoft 365 security capabilities and actually configuring and managing them. Having a particular Microsoft license does not tell me whether the appropriate security controls have been configured for that business or whether anyone is reviewing the information those systems produce. That is one of the areas I look at as part of an SNL-Tech Services Microsoft 365 Audit.
Why I Customize My Clients' Microsoft Sign-In Experience
Another configuration choice I make for the Microsoft 365 environments I manage is customizing the Microsoft Entra sign-in experience with the client's branding. I like employees becoming familiar with what their normal authentication process looks like. If someone follows a link and suddenly arrives at a generic or unfamiliar looking sign-in experience, that difference can give them another reason to stop and question what they are seeing before entering credentials.
I do not treat company branding as proof that a login page is legitimate, and I would never teach an employee that seeing the company logo means a page is automatically safe. Logos, colors, backgrounds, and other visual elements can be copied onto a phishing page. For me, branding is an additional visual cue that helps establish what employees normally expect to see. It works alongside stronger identity controls, appropriate authentication methods, Conditional Access where applicable, employee awareness, and the ability to investigate suspicious activity.
2. Emails, Inbox Rules, or Forwarding You Did Not Create
A compromised mailbox does not always start sending hundreds of obvious spam messages. Someone who is trying to monitor an invoice, payment, contract, or other valuable conversation has a reason to stay quiet. They may create mailbox rules, forward selected messages, move messages somewhere the employee rarely looks, or otherwise manipulate the mailbox in a way that allows them to watch what is happening without immediately drawing attention to themselves.
This is why I look well beyond the Inbox when I investigate suspicious Microsoft 365 email activity. Microsoft's current compromised account guidance specifically identifies missing or deleted email, suspicious Inbox rules, rules moving messages into folders including RSS Subscriptions, suspicious Sent or Deleted Items, unexplained account lockouts, and recently added external forwarding as potential indicators of compromise. Microsoft also provides administrators with ways to inspect hidden Inbox rules and forwarding configurations.
Depending on what brought the issue to my attention, I may review:
Inbox rules, including hidden rules and rules the user does not recognize
External forwarding
RSS Subscriptions
Junk Email
Deleted Items
Sent Items
Other folders the employee rarely uses
Microsoft 365 sign in activity
Authentication methods and account changes
Relevant Microsoft 365 audit and security information
Why I Check the RSS Subscriptions Folder
The RSS Subscriptions folder is one of the places I specifically inspect when I am investigating a potentially compromised mailbox. Most of my clients do not normally use that folder, which means messages showing up there unexpectedly are something I want to understand. Microsoft specifically identifies suspicious rules that move messages into RSS Subscriptions as a possible symptom of a compromised Microsoft 365 mailbox.
Finding an email in RSS Subscriptions does not prove that someone compromised the account. I want to know how it got there, whether a rule moved it, whether the user recognizes that rule, what kinds of messages the rule affects, and what other account activity occurred around the same time. That larger investigation is much more useful than looking at one unusual folder and jumping immediately to a conclusion.
3. Security or Management Tools Start Reporting Something Unusual
One of the advantages of centrally managing a business environment is that the employee sitting in front of a computer does not have to be the first person to notice every problem. Depending on the environment, Microsoft Defender, another endpoint security platform, Microsoft Entra, an RMM system, email security, a firewall, or another monitoring platform may identify activity that deserves attention before the employee notices anything unusual.
For the businesses I manage, I want to know if a computer that should be checking into an RMM platform suddenly stops reporting, if endpoint security generates an alert, or if another management or security system shows something outside the expected pattern. There can be perfectly legitimate explanations for those events. A laptop may be turned off, an agent may have a problem, or a security product may generate a false positive. The value is having enough centralized visibility to know something changed so I can determine why.
This is also why I distinguish between owning security products and actively managing an environment. A business can pay for endpoint security, Microsoft 365, an RMM platform, a firewall, and several other security tools, but those tools are much more useful when they are properly configured, the devices that should be covered are actually in scope, alerts are being reviewed, and someone understands what normal activity looks like for that business.
4. New Accounts, Applications, Devices, or Administrative Access Appear
An unexpected change to the environment can also be a warning sign, particularly when nobody responsible for managing the technology can explain why the change occurred. That might be a new user account, an authentication method the employee did not add, an application nobody remembers approving, an unfamiliar device associated with an account, unexpected administrative access, or permissions that changed without an obvious business reason.
Cloud environments have made this broader than simply asking whether somebody knows an employee's password. Microsoft 365 can include identities, authentication methods, devices, sessions, administrative roles, applications, permissions, SharePoint and OneDrive data, and connections to third party services. Microsoft's current Entra investigation guidance recommends looking beyond an individual sign in to consider resources that may have been affected, including potential data downloads or administrative modifications.
Some of the questions I may need to answer include:
Do we recognize every administrative account?
Does the employee recognize the authentication methods associated with the account?
Are there applications or integrations nobody recognizes?
Do the devices associated with the account make sense?
Were administrative roles or permissions intentionally changed?
Are former employees completely removed from systems they should no longer access?
What company resources did the account access around the suspicious activity?
This is one of the reasons I have written separately about Microsoft 365 management for small businesses. Having Microsoft 365 does not tell a business owner whether the environment is being actively reviewed, documented, secured, and managed as the company and Microsoft's platform change.
5. A Computer Starts Behaving in Ways You Cannot Explain
I have deliberately changed this warning sign from the original version of this article because I do not think telling business owners that a slow computer means malware is particularly useful. Computers become slow for all kinds of ordinary reasons. Hardware ages, storage fills up, applications become more demanding, updates run in the background, and software problems happen. A five year old computer taking longer to open an application is not enough information for me to conclude that the business has a cybersecurity incident.
What concerns me more is behavior that does not fit the normal operation of the computer. Security software becoming disabled unexpectedly, applications appearing that nobody intentionally installed, unexplained remote access, files suddenly becoming inaccessible, unusual browser behavior, unexpected settings changes, ransomware messages, or several abnormal behaviors occurring together deserve a closer look. I want employees to report those changes rather than deciding on their own that they are either definitely being hacked or that the problem is probably nothing.
This is another place where centralized endpoint management helps. If I can compare what the employee is seeing with information from endpoint security, RMM, device management, event information, or other available management tools, I have much more context than I would get from simply asking whether the computer “feels slow.”
6. Your Network or Security Systems Show Activity You Cannot Explain
Not every sign of a possible compromise appears inside a mailbox or on an employee's screen. A firewall, wireless system, identity platform, endpoint security system, or other monitoring tool may identify a device, connection, authentication pattern, or other activity that does not fit what I expect to see in that environment. Being able to recognize that difference starts with knowing what the environment is supposed to look like in the first place.
If nobody knows which devices should be connected to the network, identifying an unfamiliar device becomes harder. If nobody knows which systems normally communicate with one another, unusual network traffic is harder to put into context. Network segmentation can help provide structure by separating systems such as employee computers, servers, guest WiFi, cameras, printers, phones, or IoT equipment where that architecture makes sense for the business. A VLAN alone does not create meaningful security if the firewall and access rules between networks still allow everything to communicate, so the design and controls matter just as much as the VLAN itself.
This connects directly to the Small Business IT Checklist: How Well Do You Know Your Technology?. A cyber incident is a terrible time to discover that nobody knows which devices belong on the network, who manages the firewall, which computers are under centralized management, where the backups are, or where the current documentation is stored.
7. Customers, Vendors, or Employees Report Activity You Did Not Initiate
Sometimes the person who notices something unusual is outside the IT environment entirely. A customer may receive an invoice nobody inside the company sent. A vendor may get an unexpected request to change payment information. An employee may receive a message that appears to come from the owner asking for something unusual, or someone may call because they received an attachment or link from one of your employees that the employee does not remember sending.
I take those reports seriously, but I do not automatically assume they prove the mailbox was hacked. There is an important difference between email spoofing and an attacker actually gaining access to a legitimate mailbox. Someone can make an email appear to come from a business without necessarily logging into that business's Microsoft 365 environment. If an attacker actually has access to the account, however, the account may provide access to the associated mailbox and potentially SharePoint folders, OneDrive files, and other resources available to that identity.
If a client tells me someone received a suspicious message that appears to have come from inside the business, I want to determine what actually happened rather than guess. That may mean looking at the message itself, authentication activity, mailbox rules, forwarding, sign in information, and other available evidence. I discuss that distinction and the broader email security controls in Microsoft 365 Email Security for Law Firms and Business Email Compromise.
Can a Hacker Still Get Into an Account That Has MFA?
MFA remains an important security control, but enabling MFA does not mean there is nothing else to monitor. Identity attacks have continued to evolve, and Microsoft Entra ID Protection looks at a range of signals associated with users and sign ins. During an investigation, details such as the application, device, location, IP address, user agent, authentication activity, and the user's normal behavior can help determine whether an event is legitimate or potentially suspicious.
For a small business owner, the important point is not that MFA has somehow stopped working. MFA should be part of a broader identity security strategy. I still want to know about an unexpected authentication request. I still want visibility into risky users and risky sign ins where those capabilities are available. I want appropriate administrative protections and Conditional Access policies, and I want someone reviewing what is happening in the environment instead of assuming that turning on MFA finished the job.
What Should I Do If I Think My Business Has Been Hacked?
The right response depends heavily on what actually happened. A suspicious Microsoft 365 sign in is not the same incident as ransomware on a workstation, and a spoofed email is not the same as an attacker having access to a legitimate mailbox. An employee clicking a phishing link without entering any information presents a different situation from an employee entering credentials and approving an MFA request, and both are different from discovering that money was transferred to a fraudulent account.
Before making a large number of changes, I want to establish enough information to understand the situation, preserve what may be important, and determine the appropriate response.
Question | Why It Matters |
What happened? | Establishes what first triggered the concern. |
Which user, device, mailbox, or system is involved? | Helps begin defining the potential scope. |
When was it first noticed? | Provides a starting point for building the incident timeline. |
What evidence should be preserved? | Logs, screenshots, timestamps, alerts, system information, and physical media may be important for determining what occurred. |
What actions have already been taken? | Changes made after discovery can affect both the environment and available evidence, so they should become part of the incident record. |
Is suspicious activity still occurring? | Active malicious activity can change how quickly containment needs to occur. |
Was money or sensitive information involved? | This may affect which outside professionals or organizations need to become involved. |
Do we have cyber insurance and an incident response plan? | The policy and plan may contain contacts, procedures, and notification requirements that need to be followed. |
Preserve the Evidence Before You Start Making Changes
When I am dealing with a potentially compromised account or computer, I do not want the first response to be making a long list of changes to the environment. Before remediation begins, I want to gather enough information to understand what happened, establish a timeline, determine what may have been affected, and preserve the information that could be important later. Actions taken on a potentially compromised system can change information that may help with the investigation, which is why I document what I find before I begin making unnecessary changes.
Documentation is a major part of that process for me. Depending on the incident and the systems involved, I may capture screenshots, timestamps, IP addresses, sign in records, Risky User and Risky Sign In information, Microsoft 365 audit information, endpoint security alerts, mailbox rules, forwarding settings, message traces, RMM information, firewall logs, and other information that helps establish what happened. Whenever the underlying information can be exported or preserved, I want that as well rather than relying solely on screenshots. I also document the actions I take and when I take them so there is a chronological record of both the discovery and the response.
I have had a client situation where preserving the physical drive was part of this process. I removed the drive from the affected computer and provided it to the client with documentation showing the date and time it was removed. Along with the drive, I provided screenshots, timestamps, supporting documentation, and a runbook showing what I had done during the response. That gave the client a documented record of the technical work and preserved the drive rather than continuing to make changes to the original storage device.
That kind of documentation can become especially important if the business later decides it needs to involve its cyber insurance carrier, legal counsel, a digital forensics specialist, law enforcement, or another outside party. My role in a situation like this is to document the technical environment, preserve the information and physical media within my scope, and provide a clear record of the actions I performed. I would not describe that as performing a formal digital forensic examination. If formal forensic acquisition, analysis, expert testimony, or legally defensible evidence handling is required, the business may need a qualified digital forensics specialist.
I also would not turn this into generic advice telling a business owner to immediately shut down a computer or remove a hard drive themselves. The appropriate response depends on what is happening, what evidence may exist, whether malicious activity is ongoing, and whether specialized forensic assistance is required. Some potentially valuable information can also be volatile, which means an uninformed shutdown or other change may eliminate information an investigator would have wanted to collect. The important point for a business owner is that actions taken during those first minutes and hours matter, which is why having an incident response process and someone who understands the environment is so valuable.
A Microsoft 365 Compromise Needs the Same Documentation Mindset
A Microsoft 365 incident does not give me a physical hard drive containing all of the evidence, but I approach the documentation with the same mindset. If an account may have been compromised, I want to capture the information that helps establish what occurred. Depending on the circumstances and available licensing, that can include sign in activity, IP addresses, locations, Risky Users and Risky Sign Ins, authentication changes, Inbox and hidden rules, forwarding, message traces, audit events, applications, administrative changes, and other Microsoft 365 resources the identity may have accessed.
There is still a point where containment and remediation have to happen, particularly when the available evidence indicates that an attacker still has access. Evidence preservation should not become an excuse to knowingly leave malicious access active. What matters is coordinating discovery, documentation, evidence preservation, containment, remediation, and recovery rather than treating the response as nothing more than changing a password and moving on.
What If an Employee Clicked a Phishing Link?
If an employee thinks they clicked a phishing link, I want them to tell me or whoever manages the company's IT and security as soon as possible. I would much rather investigate something that turns out to be harmless than have an employee hide what happened because they are embarrassed or worried they will get in trouble. Fast reporting gives us a much better opportunity to determine what happened while the details are still fresh.
The next questions depend on what occurred after the click. Did the employee enter their password? Did they approve an MFA request? Did a file download? Did they open an attachment or grant an application permission? Did the page simply open and nothing else happen? Those details can materially change what needs to be investigated, which is why “I clicked something suspicious” is useful information rather than an admission that the employee definitely compromised the business.
What Should Be Checked If a Microsoft 365 Email Account May Be Compromised?
There is no single Microsoft 365 screen that answers every question about a suspected compromise. The areas that need to be reviewed depend on the incident, the licensing in the tenant, the services being used, and what evidence is available. A broader investigation may include several parts of the environment.
Area | Examples of What May Need Review |
Identity | Risky Users, Risky Sign Ins, sign in logs, and risk detections |
Authentication | MFA methods, unexpected authentication changes, and active sessions |
Mailbox | Inbox rules, hidden rules, forwarding, RSS Subscriptions, Sent Items, and Deleted Items |
Applications | Connected applications and unexpected permissions |
Administrative access | Roles, privileged accounts, and recent changes |
Microsoft 365 data | OneDrive, SharePoint, and other resources available to the identity |
Devices | Whether activity corresponds with a known or managed device |
Audit and security information | Relevant changes, alerts, and activity around the suspected incident |
This is also why I am careful about Microsoft 365 licensing when discussing security. Not every Microsoft 365 subscription provides the same identity protection, security telemetry, audit capabilities, retention, Defender features, or Conditional Access functionality. I want to understand what the business actually owns, what has been configured, and what information is available before assuming a particular investigation capability exists.
Why an Incident Response Plan Matters Before Something Happens
One of the worst times to figure out who should be called, where the backups are, who controls Microsoft 365, who manages the firewall, what the cyber insurance policy requires, or who has authority to make business decisions is while a cyber incident is already unfolding. An incident response plan gives the business a structure for handling those questions before the pressure of a real event is added to the situation.
For a small business, that plan should establish practical information such as:
Who employees should contact first when they suspect a security problem
Who is responsible for the technical response
Who has authority to make business decisions during an incident
Who manages Microsoft 365, endpoints, and the network
Where current IT documentation is stored
Who can access and restore backups
Who the cyber insurance contacts are
Which legal, regulatory, contractual, insurance, or compliance professionals may need to become involved
How the business will communicate if normal email or other systems cannot be trusted
This is an area where good IT documentation becomes much more than administrative paperwork. Current inventories, network information, screenshots, configuration records, runbooks, backup documentation, and a record of who controls important systems can all help during an incident because the technical team does not have to reconstruct the entire environment while also trying to determine what happened.
If cyber insurance is part of the picture, I also recommend understanding the policy and response requirements before an incident occurs. My Cyber Insurance Requirements for Small Businesses article explains some of the technical questions businesses may need to answer and why accurate documentation matters before an application, renewal, or incident.
Frequently Asked Questions About a Possible Business Hack
How do I know if my small business has been hacked?
There usually is not one universal sign that proves a small business has been compromised. Unexpected sign ins, unfamiliar MFA prompts, suspicious mailbox rules, unexplained forwarding, unknown applications, security alerts, unusual device or network activity, and reports from customers or vendors can all be reasons to investigate. The useful question is whether the activity fits what is normal for that particular user and business and whether the available evidence points to legitimate activity or a potential compromise.
Why am I getting Microsoft Authenticator prompts I did not request?
An unexpected Microsoft Authenticator prompt can indicate that someone else is attempting to authenticate to the account, although the circumstances still need to be investigated. Do not approve an authentication request you did not initiate simply to clear the notification. Report it so the associated sign in and account activity can be reviewed.
What is a Risky User in Microsoft 365?
Microsoft Entra ID Protection uses identity risk signals to identify users whose accounts may be at risk. The Risky Users report gives administrators information they can use to investigate why the user was flagged and determine the appropriate response. A Risky User does not automatically mean the account has been compromised. Microsoft's tools allow administrators to confirm a user as compromised, confirm the user as safe when the risk is a false positive, or dismiss benign risk after investigation.
What Is the Difference Between a Risky User and a Risky Sign In?
They answer related but different questions. User risk relates to whether an identity may be compromised, while sign in risk evaluates a particular authentication event. Looking at both can provide useful context during a Microsoft 365 identity investigation, particularly when combined with the device, location, application, IP address, user agent, and the user's normal activity.
Where Should I Look for Hidden Emails if I Think My Microsoft 365 Account Was Hacked?
Do not limit the investigation to the Inbox. Depending on what happened, Inbox rules including hidden rules, external forwarding, RSS Subscriptions, Junk Email, Sent Items, Deleted Items, and other unusual folders may need to be reviewed. Sign in and authentication activity should also be considered because mailbox manipulation may be only one part of a larger account compromise.
Does an Email From My Address Mean My Mailbox Was Hacked?
No. A message that appears to come from your company could involve email spoofing without the attacker actually accessing the mailbox, or it could originate from a legitimate account that has been compromised. Determining which occurred requires looking at the message and the surrounding email and authentication information rather than assuming the sender address tells the entire story.
Can a Hacker Get Into an Account That Has MFA?
MFA significantly improves account security, but no individual security control prevents every possible identity attack. Phishing, social engineering, stolen sessions or tokens, malicious applications, and other techniques can still create risk. I treat MFA as an important part of a larger identity security strategy that can also include Conditional Access, appropriate authentication methods, endpoint security, monitoring, user awareness, and investigation of suspicious activity.
Should I Immediately Change a Password if I Think a Business Email Account Was Hacked?
Securing the account can be an important part of containment and remediation, but I do not want a suspected compromise reduced to nothing more than changing the password. Before and during the response, we may need to capture information that helps establish what occurred while also determining whether malicious access is still active. Microsoft 365 sessions, authentication methods, mailbox rules, hidden rules, forwarding, applications, administrative access, sign in activity, and other resources may all need to be considered. The appropriate sequence depends on the incident.
Should I Shut Down a Computer if I Think It Has Been Hacked?
There is not one answer that applies to every incident. Shutting down, disconnecting, or continuing to use a potentially compromised computer can each affect the environment and the evidence available for investigation. If possible, contact the person responsible for the technical incident response and avoid making unnecessary changes until the situation has been evaluated. An actively spreading or destructive incident may require faster containment, which is why the response has to be based on what is actually happening.
Why Are Screenshots and Timestamps Important During a Cyber Incident?
Screenshots and timestamps can help establish what was observed, when it was observed, and how the environment changed as the incident progressed. I also want the underlying logs and exports when they are available because a screenshot should not be the only evidence we preserve. Combined with a runbook or incident record showing the actions taken and when they were performed, this information helps create a clearer technical timeline and may be useful if the business later involves its cyber insurance carrier or another specialist.
When Should I Contact My Cyber Insurance Company?
That depends on the policy and the incident. Cyber insurance policies can contain notification requirements and may identify approved legal, forensic, incident response, or other resources. Businesses should review their actual policy and involve their insurance professional rather than relying on a generic timeline from an article.
Recognizing the Warning Signs Is Only the Beginning
A cyber incident does not have to announce itself with a ransomware screen or a completely disabled network. The first indication may be an unexpected Authenticator request, a Risky User alert in Microsoft Entra, an Inbox rule moving messages into RSS Subscriptions, a device disappearing from centralized management, a security alert from an endpoint, or a call from a customer about a strange email. None of those events automatically proves the business has been hacked, but each can provide a reason to investigate further.
This is why the security work I do with clients extends beyond installing antivirus or enabling MFA. I want visibility into the identities, computers, Microsoft 365 environment, network, backups, security systems, and documentation the business depends on because understanding what should normally be happening makes it much easier to recognize and investigate something that does not belong. When something does happen, that same documentation becomes part of the response. Screenshots, timestamps, logs, system information, runbooks, inventories, and a clear record of what was done can help us reconstruct the incident rather than trying to remember everything after the fact.
If you are not sure whether your business has that visibility today, the Small Business IT Checklist: How Well Do You Know Your Technology? is a practical place to start. It is designed to help business owners identify what they know about their environment, what they do not know, and which areas may need a closer technical review before a security incident forces them to find out.
ADDITIONAL RESOURCES
Microsoft Learn: Respond to a Compromised Email Account in Microsoft 365
Microsoft's current guidance for identifying, investigating, securing, and restoring a compromised Microsoft 365 email account, including suspicious Inbox rules, hidden rules, forwarding, authentication activity, and other areas that may need investigation.Respond to a Compromised Email Account in Microsoft 365
Microsoft Learn: Investigate Risk with Microsoft Entra ID Protection
Microsoft's guidance for investigating Risky Users, Risky Sign Ins, risk detections, sign in characteristics, and potentially affected resources.Investigate Risk with Microsoft Entra ID Protection
Microsoft Learn: Microsoft Entra ID Protection Risk Detections
Microsoft documents the identity risk signals and detections available through Entra ID Protection and explains how those detections can help identify activity that deserves investigation.Microsoft Entra ID Protection Risk Detections
Microsoft Learn: Microsoft Entra Risky User Report
Microsoft explains how administrators can investigate Risky Users and determine whether detected activity represents compromise, a false positive, or benign activity.Microsoft Entra Risky User Report
Microsoft Learn: Configure Microsoft Entra Company Branding
Microsoft explains how organizations can customize the Microsoft Entra authentication experience with their own organizational branding.Configure Microsoft Entra Company Branding
Microsoft Learn: Conditional Access and Risk Based Policies
Microsoft explains how identity risk can be incorporated into Conditional Access policies when the appropriate Microsoft Entra capabilities and licensing are available.Microsoft Entra Risk Based Conditional Access
NIST: Digital Evidence Preservation, Considerations for Evidence Handlers
NIST provides guidance on preserving digital evidence, including considerations involving physical storage media and other digital evidence that may need to be retained during an investigation.NIST Digital Evidence Preservation Guidance
NIST: Cybersecurity Resources for Small Businesses
NIST provides cybersecurity guidance and resources specifically intended to help small businesses understand, manage, and respond to cybersecurity risks.NIST Small Business Cybersecurity Corner





Comments