Forum Discussion

Seena_Poopathi's avatar
Seena_Poopathi
Copper Contributor
Oct 07, 2026

Staff Email hacked how to reset from admin

One of my staff members' email accounts has been hacked. We are using an MSFT 365 online subscription.  How do I reset it as an admin? I tried resetting the password, removing restrictions, and blocking/unblocking the user, but none of these steps worked. Please assist.

3 Replies

  • LauraBennett's avatar
    LauraBennett
    Brass Contributor

    A password reset alone may not be enough—the attacker could still have an active session, an added authentication method, or a forwarding rule. Since you’ve already tried resetting it, keep the account blocked while you check those.

    1. Block sign-in and revoke sessions. In the Microsoft 365 admin center, go to Users > Active users, select the employee, and block sign-in. In the Entra admin center > Users > affected user, use Revoke sessions. Revocation may not take effect instantly in every app.
    2. Reset the password and secure MFA. Set a new, unique password. Under Authentication methods, remove any methods the employee doesn’t recognise and require MFA re-registration. Verify the employee’s identity through a trusted channel before giving them new access details.
    3. Check the mailbox for persistence. In Exchange admin center, review forwarding and mailbox delegation. Also inspect inbox rules for anything that forwards, deletes, or hides messages. Review the user’s recent Entra sign-in logs and unfamiliar application permissions.
    4. Restore access only after cleanup. Have the employee use a trusted, updated device and register their own MFA method. Then unblock sign-in. If Microsoft separately blocked outbound mail, remove the user from Restricted entities in Microsoft Defender only after securing the account.

    If it still fails, the exact symptom matters: can’t sign in, can’t send mail, or suspicious activity continuing require different fixes. Open a support request through Microsoft 365 admin center > Help & support with the error message and the time of the failed attempt. If your users sync from on-premises Active Directory, also check whether the password must be reset there.

  • You're dealing with a compromised Microsoft 365 mailbox where resetting the password and toggling block status did not restore safe access. That is expected if stolen sessions, added authentication methods, forwarding rules, or malicious app consent remain active. First block sign-in while you investigate. In Microsoft Entra, reset the password, require the user to register multifactor authentication again, remove unknown authentication methods, and revoke all sign-in sessions. In Exchange Online, inspect inbox rules, forwarding addresses, delegates, and outbound spam restrictions; remove anything unauthorized. Review Entra sign-in and audit logs to identify the source and scope, then scan the user’s devices before unblocking sign-in. If the account is listed under Restricted entities, remove it only after remediation. Also check sent items and notify affected contacts. If administrative access or recovery methods were changed, open a Microsoft 365 support case immediately rather than repeatedly resetting the password.