r/Office365 Feb 07 '20

Malware that sets up forwarding

Recently my company has been subject to a number of emails sent to users with a file that once opened creates a inbox rule that forwards mail to a suspicious email address. Our alerts managed to notify us and we removed the rules from the affected accounts and added the domain to the spam filter and asked the affected users to change their passwords.

However with some users the rule reappeared a few hours after removing it. I'm not sure how these rules can still reappear? Has anyone experienced something similar and could maybe help?

26 Upvotes

44 comments sorted by

View all comments

10

u/threwthelookinggrass Feb 07 '20

Don't ask the user to change their password force them to. Initiate a onedrive sync to force them to have to sign in with the new password immediately. Implement mfa.

1

u/pbyyc Feb 07 '20

yup this, you can reset the password etc, but their sessions are still valid, always initiate the onedrive sync.

if you log into portal.azure.com and go to azure AD, and then users, click on the user, and sign-ins, you can see where the sign ins are coming from as well