We've had several near-breaches involving a phishing technique where a compromised account emails everyone in the victim's address book. The message links to a legitimate SharePoint site, but the site leads to a spoofed Microsoft sign-in and MFA prompt. If the recipient completes the prompt, the attacker can take over the account and repeat the process using the new victim's contacts. How are you preventing and responding to this?
5 Answers
For a compromised account, immediately revoke active sessions, reset the password, remove unfamiliar authentication methods, review OAuth app consent, forwarding rules, inbox rules, recent SharePoint activity, and outbound messages. A short help-desk playbook makes containment much faster.
Use Conditional Access to block device code authentication if your organization doesn’t have a legitimate need for it. If the attack depends on that flow, removing it is more reliable than expecting users to recognize the phishing page.
Training is still useful, especially because these messages may come from trusted partners or internal departments and can point to genuine Microsoft pages. Simulated phishing exercises and clear guidance to verify unexpected file-share invitations help, but users shouldn’t be the only control.
I’d also review whether users really need permission to create SharePoint sites or similar collaboration resources. Restricting unnecessary creation and access paths can reduce the attacker’s ability to build convincing lures, while phishing-resistant MFA such as FIDO2 security keys or passkeys adds another strong layer.
Conditional Access can also require a corporate-managed or compliant device. That prevents sign-ins from unknown personal devices and makes it much harder for an attacker to use stolen credentials or an intercepted code.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures