
If a company mailbox has been compromised, changing the password is important, but it may not remove everything the attacker changed.
An attacker can create an inbox rule or automatic forwarding setting that quietly sends copies of incoming email somewhere else. That could include invoices, password-reset messages, customer conversations, or internal information.
Microsoft specifically lists suspicious inbox rules and newly added external forwarding as signs of a compromised Microsoft 365 account.
If you suspect a mailbox has been accessed, check the account itself, the forwarding settings, active sessions, and connected applications.
Can someone keep receiving email after the password is changed?
Yes.
Imagine an attacker gets access to an employee's Microsoft 365 account and creates a rule that forwards certain messages to an outside address.
The employee changes their password. The attacker may lose direct access to the account, but the forwarding rule can remain.
Microsoft warns that suspicious inbox rules may automatically forward email to unknown addresses or move messages into folders such as Junk Email, Notes, or RSS Subscriptions to make them harder for the user to notice.
That is why a password reset should be part of the response, not the entire response.
The problem is often discovered because something feels wrong rather than because Microsoft 365 stops working completely.
Watch for:
Messages unexpectedly disappearing
Customers receiving replies the employee did not send
Vendors questioning unusual payment instructions
Password-reset emails going missing
Messages appearing in unusual folders
New forwarding addresses nobody recognizes
Unexpected rules inside the mailbox
Sign-ins from unfamiliar devices or locations
Microsoft identifies missing or deleted email, suspicious sent messages, unexplained account changes, and newly added external forwarding as common signs of mailbox compromise.
A mailbox can appear completely normal while selected messages are quietly being copied elsewhere.
Because the attacker may have already established another way to maintain access.
After a suspected compromise, administrators should look beyond the password and review:
Active sign-in sessions
Inbox and forwarding rules
MFA methods
Recently connected applications
Account permissions
Recent sign-in activity
Microsoft recommends revoking active sessions when responding to a compromised Microsoft 365 mailbox. This helps invalidate existing access rather than waiting for sessions to expire naturally.
The goal is to remove the attacker's access and anything they changed while they had it.
Microsoft 365 accounts can give third-party applications permission to access company information.
An employee may legitimately connect a scheduling tool, CRM, document application, or other service. But if an attacker tricks someone into approving a malicious application, changing the user's password may not address that application permission.
Microsoft recommends reviewing applications that have user consent after an account compromise and removing anything that should not be there.
Administrators should ask a simple question:
Do we recognize every application that currently has access to this user's account?
If the answer is no, investigate before assuming the account is secure.
Start with the affected mailbox.
In the Exchange admin center, administrators can open the user's mailbox and review its Email forwarding settings. Microsoft allows forwarding to another internal mailbox or an external email address, so any destination should be confirmed as legitimate.
Then review the mailbox's inbox rules. Look for rules that:
Forward or redirect messages
Delete messages automatically
Move messages into unusual folders
Apply only to invoices, payments, executives, or specific vendors
Send information to an unfamiliar address
Some malicious rules may also be hidden from the normal user view. Microsoft documents additional administrator checks that can identify hidden inbox rules when investigating a compromised mailbox.
Microsoft 365 administrators can also use the Auto-forwarded messages report in Exchange Online to see which users are automatically forwarding messages, where the messages are going, and which external domains are receiving them. Microsoft specifically describes this report as a way to look for potential data leaks.

If a suspicious rule or forwarding address is found, treat it as a sign that the mailbox may have been compromised.
A practical response is:
Remove or disable the suspicious forwarding rule.
Reset the affected user's password.
Revoke active sessions.
Review MFA methods and remove anything unfamiliar.
Review connected applications and permissions.
Check recent sign-ins and mailbox activity.
Determine what information may have been forwarded.
Look for suspicious messages sent from the account.
Microsoft recommends disabling malicious inbox rules, resetting credentials, and investigating additional activity when suspicious forwarding is confirmed.
Businesses should also consider restricting automatic external forwarding unless there is a legitimate business reason for it. Microsoft warns that external automatic forwarding can increase exposure to account-takeover attacks and provides Microsoft 365 controls for limiting it.






