Skip to content
Back to Blog
7 min readmicrosoft-365incident-responsetokens

Microsoft 365 Token Theft: An Incident Responder's Playbook

Session token theft has become one of the most effective techniques for maintaining persistent access to Microsoft 365 environments. Here's our response playbook.

The shift from passwords to tokens

As organizations deploy MFA, attackers have shifted their focus from stealing passwords to stealing session tokens. A valid session token lets an attacker access Microsoft 365 services as the authenticated user, completely bypassing MFA. Tokens can be stolen through AiTM phishing, infostealer malware, or by compromising the device where tokens are cached.

Once an attacker has a valid session token, they can access Outlook, SharePoint, Teams, and any other M365 service the user has permissions for, all without triggering any additional authentication challenges.

Detection indicators

Look for these signs of token theft in your M365 environment: sign-in events from unusual IP addresses or locations shortly after a legitimate sign-in, especially if no MFA challenge was triggered. Token usage from a different device or operating system than the original authentication. Impossible travel: logins from geographically distant locations within a short time frame. New inbox rules, mail forwarding, or OAuth app consents shortly after an unusual sign-in. Access to resources the user doesn't normally use.

Immediate response steps

When token theft is confirmed, work in this order. Revoke all refresh tokens for the affected user (Revoke-MgUserSignInSession via Microsoft Graph PowerShell, or the Entra admin action) and force sign-out from all sessions before touching the password: a password reset alone leaves refresh tokens and stolen session cookies valid. Reset the password after sessions are revoked. Remove attacker-added MFA methods and review every MFA registration event in the audit log. Review and revoke suspicious OAuth app consents at user and tenant level, and remove any service-principal credentials added during the compromise window. Remove mailbox rules (especially auto-forward, auto-delete, and move-to-RSS-Feeds), Exchange transport rules, and Power Automate flows the attacker created. Pull Entra ID sign-in logs, the Unified Audit Log, and mailbox audit logs to determine the full scope of unauthorised access and any pivot to SharePoint, OneDrive, or Teams. Check for attacker-added conditional access exclusions. Enable Continuous Access Evaluation (CAE) so tokens can be revoked within minutes going forward.

Talk to a senior responder about Microsoft 365 Token Theft: An Incident Responder's Playbook.

Schedule a response call
Incident response

Need incident response?

088 SECDESK (7323375)

Call us. A senior responder picks up.

  • Two-hour SLA
  • Dutch senior responders

Emergency form

Two-hour response.

Is this urgent? Call us.

088 SECDESK (7323375)

Cannot wait? Call 088 SECDESK (7323375) now

Emergency line088 SECDESK
Call now