A client's Microsoft 365 tenant appears to have been taken over. The attacker gained Global Administrator access despite MFA being enabled, removed the break-glass account, and locked out the legitimate administrators and support contacts. A case has been opened with Microsoft's data governance team, and the CSP has also tried to escalate it, but there has been little progress after roughly a day and a half. We can provide business ownership evidence, domain records, tenant details, and other documentation. What escalation paths or emergency steps have worked to recover the tenant or remove the attacker quickly?
5 Answers
Report the incident to Australia’s cyber authorities immediately through the official Cyber.gov.au report-and-recover process. Treat this as an active business compromise, not just an account-recovery ticket, and preserve evidence while the recovery process is underway.
If you have a Microsoft partner, managed service provider, or other enterprise contact, ask them to open an emergency tenant-recovery escalation to restore Global Administrator access. Partner or GDAP access may also provide a legitimate recovery route, but do not assume it still exists—verify it and document the result.
If the attacker is actively sending mail from the tenant, consider temporarily removing the Microsoft 365 MX record and reviewing SPF, DKIM, and DMARC so outbound abuse is limited. This should be coordinated carefully because it can interrupt legitimate mail and will not remove the attacker from the tenant. Preserve DNS records and screenshots before changing anything.
The commercial agreement determines the best escalation route. Confirm whether the tenant is billed directly, through a Microsoft Customer Agreement, or through a CSP. Have the billing owner, enterprise account contact, or CSP explicitly classify the case as an account takeover with active malicious administrator access rather than opening it as a routine support request. Include the tenant ID, primary domains, last known legitimate Global Administrators, invoice information, and a newly created DNS TXT record proving control of the domain.
The recovery timeline can be lengthy, sometimes taking weeks. MFA being enabled does not rule out phishing, token theft, malicious OAuth consent, or malware on an administrator’s device. Once access is restored, investigate sign-in logs, token activity, application consents, and the administrator’s endpoint.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures