An account may be compromised. What do I do first?

Reset the password, sign them out explicitly, then look for what was left behind. Do not assume an MFA reset signed them out.

Containment comes before investigation. Every minute spent working out what happened is a minute the intruder still has the account.

Ask for session revocation explicitly, every time, and read what the reply says about it. Other actions sometimes revoke sessions and sometimes do not, and the case where they do not is exactly the case you cannot afford to guess at.

Then look for what was left behind. An attacker who has been in a mailbox usually leaves a rule or a forwarding setting so they keep receiving mail after you have locked them out.

Before you begin

Have the person’s email address, and tell them what is about to happen. They are about to be signed out of everything mid-task.

Do not start by asking Avvi what happened. Investigation is the second step and it is much better done once the account is contained.

Stop the access first

  1. Ask Avvi to reset the person’s password. Avvi asks whether to sign them out everywhere, and in a compromise the answer is always yes.
  2. Ask Avvi to revoke their sessions explicitly, as a separate request.
  3. Ask Avvi to reset their multi-factor methods.
  4. Ask Avvi for the inbox rules on their mailbox, and for their forwarding status.
  5. Ask Avvi to run a security investigation on them.

Step two is not redundant. Read the reply and confirm it says the sessions were revoked.

Good to know

An MFA reset revokes sessions only when it actually removed a method. An account whose only registered method cannot be removed remotely, such as Windows Hello for Business, reports success and revokes nothing.

Revocation invalidates the tokens used to stay signed in. A session already open can survive for up to about an hour on services that do not re-check continuously, which is why the password reset matters as much as the revocation.

An attacker’s rule is usually designed not to be noticed: moving replies to a rarely opened folder, or deleting messages containing certain words.

Verify it worked

Confirm the reply for the revocation says sessions were revoked, rather than assuming it from a success message elsewhere.

Wait a few minutes, then confirm the person is actually signed out rather than checking immediately.

Confirm no unexpected rules or forwarding remain, and check whether anything was shared externally while the account was open.

If something doesn’t look right

If the reply says session revocation failed, or does not mention sessions at all, ask again explicitly. Existing tokens may still be working.

If the person still cannot sign in afterwards, check whether a method survived the reset. Windows Hello for Business has to be cleared on their own device.

If the same symptoms appear on another account, treat it as wider than one person and scan the client’s sign-ins rather than repeating this per account.

To escalate, open a support conversation from the Help drawer with the client, the person, and what the investigation could and could not check.

FAQ

Q: Does resetting multi-factor sign them out?

A: Only when it removed a method. Ask for revocation separately rather than relying on it.

Q: How fast does revocation take effect?

A: The instruction is immediate. An open session can persist for up to about an hour on some services.

Q: Should I disable the account instead?

A: Disabling also works and stops the person working. For an account somebody still needs, resetting and revoking is the usual answer.

We value your privacy

We use cookies to improve your experience, analyse traffic and measure our marketing. You can choose what to allow. Cookie Policy