Skip to main content Skip to footer

Case Study: Compromised Identities Uncovered During Managed Services Onboarding

Person using a laptop

Overview

During a routine onboarding engagement for a new managed services client, a mid-sized professional services firm in the Mid-West region, our team discovered two actively compromised user identities within the client’s Microsoft 365 tenant. Investigation showed the accounts had been compromised for at least two months before onboarding began.

One of the compromised accounts had also been used to store a malicious file in OneDrive, positioned to support secondary and tertiary attacks. The compromise had gone undetected by the client and their previous in-house IT support the entire time.

This case shows why structured onboarding is a critical security checkpoint, and how easily a compromise can sit unnoticed in an unmonitored environment.

Client Background

The client engaged our team to assume management of their Microsoft 365 environment, endpoint fleet, and network infrastructure. The environment consisted of several dozen licensed M365 users, hybrid on-premises resources, and no existing security monitoring, conditional access policies, or MFA enforcement across the tenant. Prior IT support had been handled in-house and was reactive and break/fix in nature.

As with all new clients, onboarding included a full review of the M365 tenant during integration and configuration: identity hygiene, Exchange Online configuration, mailbox rules, sign-in activity, license posture, and data storage review.

Discovery

While performing M365 integrations and configurations, our engineers identified that two user identities had been disabled by Microsoft Exchange Online and flagged as Restricted Entities. Microsoft applies this restriction automatically when an account exhibits behavior consistent with compromise. In this case, both accounts had sent mass outbound email following the initial breach.

Key findings during investigation:

  • Two compromised identities, active for at least two months: Sign-in and activity logs showed evidence of unauthorized access dating back a minimum of two months before onboarding. Both accounts were eventually used to send high volumes of unsolicited outbound email, triggering Microsoft’s automated restriction. Neither the client nor their internal IT staff noticed the accounts were disabled or investigated why.

  • Malicious file stored in OneDrive: During data review, a malicious file was discovered in the OneDrive of one of the compromised accounts. The file’s placement was consistent with staging for secondary and tertiary attacks. Shared from a trusted internal account, it could extend the attacker’s reach to other employees and outside contacts.

  • No MFA, no conditional access: The tenant lacked baseline identity protection, which is consistent with how the initial compromise likely occurred (credential theft via phishing or password spray).

  • No alerting or visibility: Because no monitoring was in place, the only detection prior to our involvement was Microsoft’s own automated enforcement, which quietly disabled the accounts without anyone acting on it. The attacker had at least a two-month window of unrestricted access before that enforcement occurred.

Response and Remediation

Once the compromise was confirmed, our team executed a containment and remediation plan:

  1. Credential invalidation: Passwords were reset and all active sessions and refresh tokens were revoked for the affected identities.

  2. Malicious content removal: The file was isolated and removed from OneDrive, and sharing links and access logs were reviewed to determine whether it had been distributed. Any shares tied to the file were revoked.

  3. Mailbox forensics: Inbox rules, forwarding configurations, and delegate permissions were audited across the affected mailboxes to remove attacker persistence mechanisms.

  4. Tenant-wide sweep: Sign-in logs, OAuth application consents, and mailbox rules were reviewed for all users to confirm the compromise was limited to the two identified accounts. Given the two-month dwell time, this review extended across the full historical log window available in the tenant.

  5. Restricted Entity remediation: After confirming the accounts were secured, the restriction was lifted through the Microsoft 365 security portal and outbound mail flow was restored.

  6. Hardening: MFA was enforced tenant-wide, conditional access policies were deployed, legacy authentication was disabled, and security alerting was configured so that future anomalous activity generates immediate notification rather than silent enforcement.

From In-House IT to Managed Services: Why It Matters

This incident is not a story about a careless client. It is a story about the limits of in-house, break/fix IT in an environment where identity is the primary attack surface. Two things stand out: how managed services changes the security posture of user identities and the organization, and why incidents like this go unnoticed for months without foundational controls in place.

Securing user identities and the organization

In-house IT teams at small and mid-sized organizations are typically staffed and budgeted to keep systems running, not to defend them. Identity security requires dedicated tooling, configuration discipline, and continuous attention that generalist internal support rarely has room for. Moving to a managed services model closed that gap for this client in several concrete ways:

  • MFA enforcement is a standard, not an option: Multi-factor authentication was enforced across the entire tenant as part of the managed security baseline. Under in-house management it had never been rolled out, leaving every account one stolen password away from compromise.

  • Identity threat detection and response (ITDR): Identity-focused monitoring now watches for the signals this attacker generated freely: impossible travel sign-ins, anomalous authentication patterns, suspicious inbox rule creation, and mass mail behavior. These signals now produce alerts that a security team investigates, rather than sitting unread in logs.

  • Email filtering and threat protection: Advanced email filtering was deployed to reduce the phishing exposure that most likely enabled the initial credential theft, and to catch malicious attachments and links before they reach users.

  • Conditional access and legacy authentication cleanup: Access policies now evaluate every sign-in based on risk, location, and device, and legacy protocols that bypass modern authentication were disabled entirely.

  • Defense of the organization, not just the account: Because a compromised identity is a launch point for attacks on coworkers, clients, and vendors, identity protections also protect the organization’s reputation and its business relationships. The staged OneDrive file in this case was aimed at exactly that next ring of victims.

Why incidents go unnoticed without foundational controls

The most striking fact in this case is not the compromise itself. It is the dwell time: at least two months of attacker access inside the environment with no one aware. That outcome is predictable when foundational security controls are absent.

  • No monitoring means no detection: Without ITDR or centralized alerting, the evidence of compromise existed only in logs no one was reading. The attacker did not need to be stealthy. There was simply nothing watching.

  • Automated platform protections fail silently: Microsoft eventually restricted the accounts for mass mailing, but that enforcement quietly disabled mail flow and stopped there. Without a team responsible for investigating anomalies, even a vendor-triggered containment event went unexamined.

  • Break/fix IT only sees what users report: Reactive support models respond to tickets. An attacker reading email, creating inbox rules, and staging files generates no tickets. The compromise only became visible when it disrupted something a user noticed, and even then, it was misread as a mail problem rather than a security incident.

  • Small gaps compound: No MFA made the initial breach easy. No email filtering made the phishing lure deliverable. No monitoring made persistence safe. Each missing control extended the attacker’s window, and together they turned what should have been a blocked login attempt into a two-month intrusion.

Outcome

The client’s environment was fully remediated with no evidence of lateral movement beyond the two identities, and the malicious file was removed before it could be used in follow-on attacks. Despite a dwell time of at least two months, the damage was contained. The client transitioned onto our managed security baseline, gaining the monitoring and identity protections that would have detected or prevented the original compromise.

Key Takeaways

  • Onboarding is a security event: A thorough tenant review during MSP onboarding routinely surfaces pre-existing compromise that clients don’t know about. In this case, the attacker had been inside the environment for at least two months before anyone looked.

  • Automated protections are a backstop, not a strategy: Exchange Online’s Restricted Entity enforcement stopped the mass mailing, but without monitoring, no one investigated the root cause. The attacker’s stored file and persistence mechanisms remained in place.

  • Compromised accounts are rarely the end goal: The malicious file in OneDrive shows the attacker using an initial foothold to prepare secondary and tertiary attacks against the organization and its contacts.

  • Foundational identity security matters: MFA enforcement, conditional access, email filtering, and ITDR would have dramatically reduced the likelihood of this compromise occurring at all, and monitoring would have cut the two-month dwell time to hours.

Talk to Us About Your Identity Security Posture

If your environment has no MFA enforcement, no conditional access, and no one watching sign-in activity, the controls that caught this compromise are the same ones missing from your tenant. Learn more about our managed IT services, or set up an appointment for a review of your Microsoft 365 environment.

Details in this case study have been anonymized to protect client and vendor confidentiality.