Skip to content
Severity: HighSecurity Advisory

Responding to Suspicious Microsoft 365 Sign-In Activity

A structured response to suspicious sign-in signals in a Microsoft 365 tenant — session revocation, mailbox rule review, and access audit.

Affected
Microsoft 365 tenants
Updated
June 22, 2026

Risk summary

Suspicious sign-ins frequently indicate stolen credentials or session tokens. Attackers commonly follow with mailbox rules, data exfiltration, or lateral movement.

Recommended actions

  1. Revoke active sessions for the affected account and require re-authentication.
  2. Force a password reset and verify MFA method.
  3. Review mailbox forwarding and inbox rules for attacker-created persistence.
  4. Check recent OAuth application consents for the account.
  5. Review sign-in logs for related activity across other accounts and IPs.
  6. Preserve relevant logs for post-incident review.

North Shield security advisories provide general educational and operational guidance. Organizations should evaluate recommendations against their own systems, risk profile and applicable vendor instructions.

Related resources

Related services

  • Microsoft 365

    Design, harden, and operate the Microsoft 365 platform your business runs on.

  • Cybersecurity

    Managed detection & response, EDR, SIEM, and continuous compliance monitoring.

Stay informed about important IT and security developments.

Receive practical technology guidance, educational security updates and new North Shield resources by email.

Frontend preview — subscription delivery is not yet connected.

By subscribing you agree to receive occasional updates from North Shield. See our privacy notice (placeholder). You can unsubscribe at any time.

Need help operationalizing this?

Turn advisory guidance into standing controls.

North Shield can help translate this guidance into runbooks, monitoring, and automation.