Responding to Suspicious Microsoft 365 Sign-In Activity
A structured response to suspicious sign-in signals in a Microsoft 365 tenant — session revocation, mailbox rule review, and access audit.
- Affected
- Microsoft 365 tenants
- Updated
- June 22, 2026
Risk summary
Suspicious sign-ins frequently indicate stolen credentials or session tokens. Attackers commonly follow with mailbox rules, data exfiltration, or lateral movement.
Recommended actions
- Revoke active sessions for the affected account and require re-authentication.
- Force a password reset and verify MFA method.
- Review mailbox forwarding and inbox rules for attacker-created persistence.
- Check recent OAuth application consents for the account.
- Review sign-in logs for related activity across other accounts and IPs.
- Preserve relevant logs for post-incident review.
North Shield security advisories provide general educational and operational guidance. Organizations should evaluate recommendations against their own systems, risk profile and applicable vendor instructions.
Related resources
- Microsoft 365 Security Review Checklist
A tenant-level review covering identity, mail flow, sharing, device policies, and audit logging.
Related services
- Microsoft 365
Design, harden, and operate the Microsoft 365 platform your business runs on.
- Cybersecurity
Managed detection & response, EDR, SIEM, and continuous compliance monitoring.
Stay informed about important IT and security developments.
Receive practical technology guidance, educational security updates and new North Shield resources by email.
Frontend preview — subscription delivery is not yet connected.
Turn advisory guidance into standing controls.
North Shield can help translate this guidance into runbooks, monitoring, and automation.