Avatar of Pau Lo
Pau Lo
 asked on

office365 email compromise

If someone has compromised as in gained unauthorised access) to an Office365 email account, for the purposes of data access, is there anyway they could lead emails out to an external address without it leaving a trace in the tracking logs? With such an attack how is it likely the attacker would make use of the access they have achieved through whatever compromise, to read/use the data? It seems a bit simplistic to me to just start forwarding them outwards, but I am not sure how these attacks happen and what exactly it is they would do with their access once achieved (and how to determine what if anything they did do once access was achieved).
ExchangeMicrosoft 365OutlookSecurity

Avatar of undefined
Last Comment
btan

8/22/2022 - Mon
Jackie Man

There is no need to forward the emails to get the data out of Office 365.

Just setup the Office 365 account as an Exchange account in MS Outlook and drag and drop (and press the Ctrl key at the same time) to copy the emails in a local .PST file in MS Outlook. If do not press the Ctrl key, the emails are moved to the local .PST file and will be gone forever.

There are no traces or logs.
Jackie Man

So, prevention is better than tracing after being compromised.

Turn on two factor authentication to prevent the compromise of the Office 365 account.
Pau Lo

ASKER
its not quite that simple though if there is suggestion of compromise you had to legally determine to what extent in certain cases. from what I understand if there are certain protocols enabled for accessing a office365 mailbox then 2FA can sometimes be bypassed.
All of life is about relationships, and EE has made a viirtual community a real community. It lifts everyone's boat
William Peck
ASKER CERTIFIED SOLUTION
masnrock

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
SOLUTION
Log in to continue reading
Log In
Sign up - Free for 7 days
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.