Skip to main content
Skip to main content

Compromised Mail Users in Microsoft 365

Audience: Security Operations and Email Administrators.

Purpose: Investigate and remediate potentially compromised Microsoft 365 mail accounts.


Overview

When Microsoft detects potentially compromised mail user behavior, automated investigations are created in the Security Portal. This guide covers the investigation and resolution process.


Investigation Process

Step 1: Access Investigations

  1. Navigate to the Security Portal Investigations
  2. Use the blue link to open the investigation in a new window

Step 2: Examine Evidence

Review the investigation details and evidence to determine if this is:

  • False Positive — Normal user behavior incorrectly flagged
  • True Positive — Actual compromise requiring remediation

Step 3: Resolve False Positives

If determined to be a false positive:

  1. Resolve the alert and mark as False Positive
  2. Go to the Pending Actions tab
  3. Reject the recommended action of resetting the password
Action Note

Rejecting the password reset appears to do nothing, but should be completed for audit completeness.

Step 4: Remove Restrictions

  1. Visit the Restricted Users page
  2. Locate the affected user
  3. Remove the restrictions

Step 5: Resolve Alerts

Navigate to the Alerts page and resolve:

  • Suspicious email activity alerts
  • User restricted from sending email alerts

Unblocking Users

If a user was erroneously blocked from sending mail:

  1. Navigate to Restricted Users
  2. Select the user
  3. Click Unblock
  4. Confirm the action

Quick Reference

TaskLocation
View Investigationssecurity.microsoft.com/airinvestigation
View Restricted Userssecurity.microsoft.com/restrictedusers
View Alertsprotection.office.com/viewalerts