{"id":392,"date":"2019-10-10T13:57:22","date_gmt":"2019-10-10T13:57:22","guid":{"rendered":"http:\/\/www.torontohelpdesk.ca\/blog\/?p=392"},"modified":"2019-11-06T15:50:49","modified_gmt":"2019-11-06T15:50:49","slug":"office-365-tenancy-hacked","status":"publish","type":"post","link":"https:\/\/www.torontohelpdesk.ca\/blog\/office-365-tenancy-hacked\/","title":{"rendered":"Office 365 Tenancy Hacked"},"content":{"rendered":"\n<p><strong>Problem:<\/strong><\/p>\n\n\n\n<p>You find that your Office 365 tenancy is hacked.<\/p>\n\n\n\n<p><strong>Solution:<\/strong><\/p>\n\n\n\n<p><em>(h\/t AC)<\/em><\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>We changed the password.<\/li><li>Checked for the Outbound connector from EAC ( Exchange Admin Center )&#8211;> Mail Flow&#8211;> Connector.<\/li><li>Check for the Inbox rules and we found the suspicious inbox rules.<\/li><li>We disable the MAPI and Active sync protocol before deleting the Inbox rules ( Active sync will take precedence if not disabled and the rules will reflect again after deleting ).<\/li><li>Then we deleted the Inbox rules .<\/li><li>We check for the email forwarding if any applied on the impacted email address.<\/li><li>We check the Message trace so that we can find weather the bulk email was send from the impacted user Mailbox.<\/li><li>We ran the command Get-inboxrule -Mailbox <a href=\"mailto:abc@domain.com\">abc@domain.com<\/a> to check the inbox rules with out login to the user from OWA ( Outlook Web Application )<\/li><li>We enable MFA for Admin Login.<\/li><li>We downloaded the Poweshell from EAC &#8211;> Hybrid &#8211;> click on second Configure to download the PowerShell for MFA. With this you can check RULEs user by user by this command<ol><li>  Get-InboxRule -Mailbox <a href=\"mailto:alexm@plantbest.com\">abc@domain.com<\/a> <\/li><li> If it came empty \u2013 no any rules are set <\/li><\/ol><\/li><li>Sign into the Office 365 Security and Compliance Center and in the list on the left, expand\u00a0<strong>Threat Management<\/strong>, choose\u00a0<strong>Review<\/strong>, and then choose\u00a0<strong>Restricted Users<\/strong>.<\/li><\/ol>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Problem: You find that your Office 365 tenancy is hacked. Solution: (h\/t AC) We changed the password. Checked for the Outbound connector from EAC ( Exchange Admin Center )&#8211;> Mail Flow&#8211;> Connector. Check for the Inbox rules and we found <a class=\"more-link\" href=\"https:\/\/www.torontohelpdesk.ca\/blog\/office-365-tenancy-hacked\/\">Continue reading <span class=\"screen-reader-text\">  Office 365 Tenancy Hacked<\/span><span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-392","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/www.torontohelpdesk.ca\/blog\/wp-json\/wp\/v2\/posts\/392","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.torontohelpdesk.ca\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.torontohelpdesk.ca\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.torontohelpdesk.ca\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.torontohelpdesk.ca\/blog\/wp-json\/wp\/v2\/comments?post=392"}],"version-history":[{"count":2,"href":"https:\/\/www.torontohelpdesk.ca\/blog\/wp-json\/wp\/v2\/posts\/392\/revisions"}],"predecessor-version":[{"id":399,"href":"https:\/\/www.torontohelpdesk.ca\/blog\/wp-json\/wp\/v2\/posts\/392\/revisions\/399"}],"wp:attachment":[{"href":"https:\/\/www.torontohelpdesk.ca\/blog\/wp-json\/wp\/v2\/media?parent=392"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.torontohelpdesk.ca\/blog\/wp-json\/wp\/v2\/categories?post=392"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.torontohelpdesk.ca\/blog\/wp-json\/wp\/v2\/tags?post=392"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}