How to safely revoke access and sign out all devices from your Microsoft 365 account after a suspected compromise
Summary
This guide helps you troubleshoot and resolve: How to safely revoke access and sign out all devices from your Microsoft 365 account after a suspected compromise. Follow the steps below to fix the issue.
Common Causes
If you suspect that your Microsoft 365 account has been compromised, acting quickly is essential to prevent unauthorised access to your emails, files, and sensitive business data. This guide walks you through the steps to force every device and application to sign out, revoke suspicious app permissions, and lock your account down so attackers can no longer use it.
The steps below assume you still have access to your account. If you have already been locked out, open a ticket with our support team immediately so we can help you recover the account through Microsoft's secure reset process.
Quick Fix Steps
- Change your Microsoft 365 password from a trusted device.
- Enable multi-factor authentication (MFA) if it is not already on.
- Revoke all active sessions from your account security settings.
- Remove any suspicious or unfamiliar third-party app permissions.
- Review recent sign-in activity for anything you do not recognise.
Detailed Instructions
Step 1: Change your password immediately
- Sign in to https://myaccount.microsoft.com/ from a device you trust.
- Select Security from the left-hand menu.
- Choose Password security, then click Change my password.
- Follow the prompts to create a strong, unique password that you have not used anywhere else. Aim for at least 14 characters, including a mix of upper and lower case letters, numbers, and symbols.
- Save the new password in a reputable password manager rather than writing it down.
Step 2: Enable or confirm multi-factor authentication
- In the same Security area, select Advanced security options.
- Look for Multi-factor authentication and confirm a second factor is registered. If your organisation allows self-service setup, follow the prompts to add the Microsoft Authenticator app.
- Register at least two verification methods where possible, ideally the Microsoft Authenticator app and an SMS number you control.
- Save your changes and complete a test sign-in to confirm everything works.
Step 3: Revoke all active sessions and sign out everywhere
- Changing your password in Step 1 automatically invalidates existing sign-in sessions, but you can also revoke sessions explicitly.
- Go to https://mysignins.microsoft.com/ to review and remove trusted devices and sessions.
- Under Devices, remove any devices you do not recognise.
- After a few minutes, sign back in on the devices you personally use and re-authenticate with your new password and MFA.
Step 4: Review and remove suspicious app permissions
- Visit https://myaccount.microsoft.com/permissions.
- Scroll through the list of apps and services that have access to your account.
- For anything you do not recognise, no longer use, or did not intentionally install, click Remove.
- Pay particular attention to apps requesting permissions to read email, send mail as you, or access files.
Step 5: Check recent sign-in activity
- Go to https://mysignins.microsoft.com/.
- Review the list of recent sign-ins, paying close attention to the location, IP address, device, and timestamp of each entry.
- If you see anything unfamiliar, click the entry and select This wasn't me to flag it to Microsoft.
- Make a note of any suspicious entries to share with our support team if needed.
Step 6: Audit mailbox rules and forwarding
Attackers often create hidden inbox rules to silently forward mail or hide security notifications.
- Sign in to Outlook on the web at https://outlook.office.com/.
- Click the Settings gear icon, then choose Mail > Rules.
- Delete any rules you did not create, especially those that move messages to obscure folders or forward mail to external addresses.
- Under Mail > Forwarding, confirm that no unknown forwarding addresses are listed.
Troubleshooting
I cannot sign in to change my password
If the attacker has already changed your password or removed your MFA method, use the Forgot my password link on the Microsoft sign-in page to begin the recovery process. If recovery fails, contact us straight away via our support portal so we can escalate to Microsoft on your behalf.
I am still seeing sign-in attempts after revoking sessions
This is normal for a short period while cached tokens expire across Microsoft's global infrastructure. If attempts continue for more than a few hours, change your password again and confirm MFA is still enabled. Persistent attempts may indicate your credentials are leaked elsewhere — change any reused passwords immediately.
An admin account has been compromised
Tenant administrator compromises require urgent action. Open a priority ticket through our support portal and we will engage Microsoft's security team, review audit logs, and lock down the tenant.
Still Having Issues?
💻 Open a Ticket