Stopping M365 Tenant Compromise After a County Phishing Incident

Stopping M365 Tenant Compromise After a County Phishing Incident

Summary

A county government office stops Microsoft 365 (M365) tenant compromise after a phishing incident by closing multifactor authentication (MFA) gaps immediately, then verifying detection and backup coverage before declaring the incident closed. For a small county government agency recovering from a recent phishing-driven breach, the main risk right now is repeat targeting during the reconnaissance stage, when attackers probe mailboxes, forwarding rules, and partially enrolled MFA accounts for a second way in. The single first action is a tenant-wide credential reset paired with full MFA enforcement, since incomplete multifactor coverage is the most common reentry point attackers exploit after an initial foothold. Bring in expert help immediately if you notice unfamiliar mailbox rules, sign-ins from new locations, or signs that internal operational data has been accessed, because confirming the scope correctly the first time avoids a second, costlier cleanup. This is general guidance, not legal advice; retain qualified counsel and your cyber insurer's breach counsel before making public statements or notifications.

Who this is for

This guide is written for a founder-CEO leading a small county government office, where IT is handled through a partial managed service provider (MSP) arrangement and a single generalist staff member covers security tasks alongside other duties. Your organization is roughly 30 days past a phishing-driven incident and is still working through containment and lessons learned, which places you in a post-incident window where decisions carry more weight than usual. Your environment is cloud-first, uses a unified extended detection and response (XDR) platform, meaning a tool that correlates signals across endpoints, identity, and cloud apps, and keeps immutable backups, meaning backup copies that cannot be altered or deleted even by an attacker with administrative access. That is a solid foundation, but partial MFA enrollment remains the gap most likely to be targeted next.

Why this matters

For a county agency, an M365 compromise is not just an IT inconvenience, it is a disruption to services residents rely on, from permitting systems to emergency coordination logs. Even when the exposed material is internal operational data rather than resident-facing records, repeat incidents raise questions from other public-sector partners (a business-to-government, or b2g, relationship) before contract renewal. Documented policies only matter if they are enforced day to day, particularly around identity and access controls, which is where most real-world gaps actually live.

There is also a financial angle tied to your cyber insurance renewal. Underwriters increasingly ask specific questions about MFA coverage, privileged account controls, and whether incident response procedures have been tested, not just written down. A recent incident paired with a visible authentication gap can affect pricing or terms at renewal. Treating this as a governance moment, not only a technical cleanup, protects both your renewal position and your standing with the board, which you update quarterly.

What the risk means

M365 tenant compromise refers to unauthorized access to your Microsoft 365 environment, typically starting with one compromised account and expanding outward from there. Phishing remains the most common entry path because it targets people rather than infrastructure, tricking a staff member into entering credentials on a fake login page or approving a fraudulent MFA push notification.

Based on available signals, the activity in your environment sits at the reconnaissance stage. Attackers who gained initial access are likely exploring mailbox rules, shared files, and directory listings without yet taking disruptive action. This stage maps to the "Identify" function described in the NIST Cybersecurity Framework, where the priority is cataloging exposed accounts, assets, and data before an intruder escalates. Reviewing shadow IT, meaning apps or cloud services staff connected to the tenant without IT approval, is part of this identification work, since unmanaged connections are a recurring blind spot documented in CISA's phishing guidance.

What can go wrong

If reconnaissance goes uninterrupted, a few realistic outcomes follow. Attackers could set up hidden mailbox forwarding rules to quietly collect internal operational records, such as system logs, asset inventories, or network diagrams that help plan further intrusions. They could also impersonate staff in messages to vendors or partner agencies, damaging trust with other government entities that rely on your office for accurate, timely communication.

Financially, the exposure is less about a single regulatory fine and more about operational cost: extended investigation time, friction at insurance renewal, and staff hours spent rebuilding confidence in the environment. Trust with partner agencies in your service chain depends on showing the issue was contained quickly and the response was documented clearly, which is also what cyber insurers and procurement reviewers ask to see.

What to do first to contain M365 tenant compromise

Start today with these sequenced steps:

  1. Reset credentials for any account involved in the original phishing incident and any account showing unusual sign-in activity, prioritizing accounts that lack full MFA.
  2. Review mailbox rules across the tenant for forwarding or auto-delete rules the account owner did not create.
  3. Confirm your XDR platform is actively ingesting M365 sign-in and audit logs, not just endpoint telemetry, since cloud identity signals require separate configuration in most deployments.
  4. Verify immutable backup integrity for systems tied to the compromised accounts, including mailbox content and tenant configuration, to confirm recovery options remain intact.
  5. Loop in your MSP partner and, if the review surfaces further suspicious activity, escalate to a qualified incident response provider or legal counsel before any external communication.

30-day action plan to reduce county government cyber risk

Owner Action Outcome
Founder-CEO Approve mandatory MFA enrollment for all remaining accounts Closes the authentication gap attackers are most likely to target next
MSP partner Audit all mailbox rules and third-party app connections (shadow IT) Surfaces hidden persistence or unauthorized access paths
Generalist IT staff Validate XDR coverage extends to M365 sign-in and audit logs Confirms detection visibility beyond endpoints alone
Founder-CEO Document findings against your current control set and review applicable state data breach notification rules with counsel Keeps compliance posture current for insurance renewal
MSP partner Test backup restoration for one critical mailbox and one configuration set Confirms whether the target recovery time is realistic in practice

90-day improvement plan

Prevention: Move from partial to full MFA enrollment, and add conditional access policies that restrict sign-ins from unexpected locations or unmanaged devices, reducing the openings phishing can exploit.

Detection: Tune your XDR platform's alerting specifically for M365 behaviors, such as newly created mailbox rules, improbable travel between sign-ins, and unusual access patterns tied to internal records. Document the specific log sources and alert thresholds your MSP configures, since generic "we have XDR" claims do not hold up during an insurance or audit review.

Response: Build a short, tested incident response runbook specific to M365 compromise, naming who approves credential resets and who contacts counsel or insurers, so the next event does not start from a blank page. The CISA Incident Response Playbook resources offer a template structure worth adapting rather than copying wholesale.

Recovery: Confirm your immutable backup strategy covers mailbox content and tenant configuration, not only file servers, and run an actual restoration test rather than relying on vendor claims about recovery time objective (RTO), the target duration for restoring a system after disruption. An untested RTO is an assumption, not a fact.

Governance: Bring a summary of the incident and remediation steps to your next quarterly board update, framing it as a maturity milestone rather than a failure, and consider a continuous exposure discovery process to catch shadow IT before it becomes a foothold again.

Vendor and tool considerations for outsourced county IT

Given your outsourced service model and partial MSP arrangement, the priority is less about buying new tools and more about confirming your current stack, XDR, immutable backups, and MFA, is configured and monitored correctly for M365 specifically. An IT asset management tool can help close the shadow IT gap by giving continuous visibility into what apps and devices connect to your tenant, which matters given a legacy-heavy technology footprint moving toward cloud-first operations.

Because you operate with a single decision maker and one generalist security staff member, look for a partner that functions as an extension of your team rather than one requiring heavy internal management. A Virtual CISO engagement can provide the governance oversight your board updates need without a full-time hire, while GRC, meaning governance, risk, and compliance tooling, can keep documentation current as controls evolve. For structured Support during contract renewal or incident follow-up, use the marketplace link below rather than choosing a vendor on name recognition alone, and compare options based on public-sector experience and documented incident response track record.

Common mistakes

A common mistake among small county offices is treating MFA rollout as optional for certain accounts, such as shared mailboxes or legacy service accounts, which is exactly where intruders look next. The better approach is enforcing MFA everywhere, including service accounts, using methods like certificate-based authentication where password prompts are impractical.

Another frequent error is assuming XDR coverage automatically includes cloud identity signals, when many deployments start endpoint-first and need explicit configuration to ingest M365 logs. A third mistake is delaying board or governance communication until an incident is fully closed; sharing interim updates, even with limited detail, builds trust and keeps funding conversations grounded in fact rather than surprise.

FAQ

What kind of data was exposed in this incident?

Based on current findings, the material at risk is internal operational data, such as system logs and configuration details, rather than resident-facing records protected under specific health or financial privacy rules. Confirm this conclusion with legal counsel and document the scope assessment, since the applicable state breach notification obligation depends on exactly what was accessed.

Will this incident affect our cyber insurance renewal?

It can, particularly if authentication gaps and the incident are both visible to the underwriter during renewal. Closing the MFA gap and documenting remediation steps before renewal conversations typically improves your position, and some insurers will request evidence of a tested backup restoration as well.

Do we need a full-time security hire to fix this?

Not necessarily. A generalist staff member supported by a Virtual CISO engagement and your existing MSP partner can cover governance, monitoring, and response without the cost of a full-time specialist, especially at your current office size.

How do we know if intruders are still active in our tenant?

Signs include unexplained mailbox rules, sign-ins from new locations or devices, and unusual file access tied to internal records. If your XDR platform is properly configured for M365 telemetry, these indicators should surface automatically; if you are not certain it is configured that way, an expert review is warranted before you assume the tenant is clean.

Next step

Closing the MFA gap and confirming detection and backup coverage are the fastest ways to reduce risk from repeat targeting, but verifying configuration and finding the right outsourced Support can take time your team does not have. If you want a faster path to vetted partners who understand county government environments, start here.

See vetted IT asset management vendors for state and local government

You can also start with a free cybersecurity assessment from Value Aligners to benchmark your current M365 and identity controls, or review the Value Aligners blog for more guidance on public-sector cloud security.

Sources