A client's Microsoft 365 tenant appears to have been taken over by an attacker who obtained Global Administrator access, despite MFA and OTP being enabled. The attacker also removed the break-glass account, so the legitimate administrators and service provider are locked out. A case has been opened with Microsoft's data governance team, and the CSP has requested an escalation, but there has been little progress after roughly a day and a half. We can provide business records, domain ownership evidence, tenant details, and DNS changes to prove control of the organisation. What escalation routes or emergency steps have worked to recover the tenant or remove the attacker quickly in Australia?
4 Answers
Report the incident to Australia’s national cyber reporting service immediately and preserve all evidence. A hostile tenant takeover should be treated as an active security incident, not just a normal support request. Keep records of the case numbers, timestamps, affected accounts, domains, and any suspicious activity.
If the attacker is sending mail from the organisation’s domain, work with the DNS provider to reduce the immediate abuse. Depending on the situation, temporarily remove Microsoft 365 from the MX and SPF records, remove Microsoft 365 DKIM entries, and apply a strict DMARC reject policy. Be careful not to destroy evidence or disrupt legitimate services without documenting the changes first.
Once access is restored, collect Entra sign-in and audit logs, mailbox forwarding rules, delegate permissions, transport rules, application registrations, consent grants, and Unified Audit data before broadly cleaning up the tenant. Reset credentials, revoke sessions and tokens, remove unknown admin accounts and devices, review authentication methods, and investigate the likely initial compromise—MFA being enabled does not rule out phishing, token theft, malware, or an abused legacy session.
The best escalation route depends on the licensing and purchasing arrangement. If the organisation uses a CSP, MCA, or enterprise agreement, involve the billing owner, Microsoft account team, or partner contacts and explicitly describe it as an account or tenant takeover with active malicious administrator access. Include the tenant ID, primary domains, last known legitimate Global Administrator accounts, invoice or agreement details, and a newly created DNS TXT record proving domain control. Ask for the account-takeover or data-protection escalation path rather than ordinary technical support.

If the organisation has an enterprise agreement or established Microsoft contacts, use those contacts as well as the existing support case. A partner with the appropriate support relationship may also be able to open an emergency access-restoration ticket.