Start with the source IP address tied to the suspicious login or mailbox change, then review 30 days of login activity for that user and for the IP itself. Compare location, user agent, and account patterns against normal behaviour. If mailbox auditing is enabled, pivot into inbox rules, forwarding settings, and delegated access to scope the campaign.
Trace the first login and mailbox-change pivot point
The fastest way to narrow a suspected Microsoft 365 BEC lead is to anchor the investigation on the first suspicious source IP, then build outward from that event. Treat the login and any mailbox-setting change as a single campaign entry point until proven otherwise, because BEC operators often reuse the same access path to stage mailbox rule changes, forwarding, or delegated access.
Once you have that pivot, compare it with the account’s normal geographic pattern, user agent history, and device or session behaviour. A lead becomes materially stronger when the same IP, or a closely related login pattern, appears across more than one account in the tenant. For a Microsoft 365 environment, mailbox-level artifacts are often the quickest way to distinguish opportunistic access from an active campaign.
Investigation is more reliable when you preserve the original login evidence before moving into mailbox contents. That means keeping the source IP, timestamps, sign-in method, and session metadata together so later review can distinguish a simple anomalous login from a broader compromise path.
Work the prior 30 days of identity and mailbox evidence
Use a 30-day window to test whether the suspicious activity was a one-off event or part of a longer foothold. Review sign-ins for the user and the source IP separately, then compare them to each other for unusual repetition, new geographies, impossible travel, unfamiliar clients, and changes in login rhythm. If mailbox auditing is available, extend that same window into inbox rules, forwarding changes, delegated mailbox grants, and any modifications that could redirect messages silently.
This lookback period matters because BEC activity often starts with low-noise access, then shifts into persistence or message redirection after the operator confirms the account is usable. Searching only the triggering event misses the surrounding behaviour that explains scope, dwell time, and whether other mailboxes may be involved. MITRE ATT&CK Enterprise Matrix is useful here because it helps teams map the login-and-mailbox sequence to credential access and follow-on abuse patterns.
In practice, the best evidence is a timeline that ties authentication, mailbox configuration, and message-flow changes to the same actor or infrastructure. That timeline is what lets responders decide whether they are dealing with a single compromised user, a reused access path, or a wider tenant intrusion.
Scope the campaign, not just the alert
A suspected BEC lead should be treated as a scoping problem, not just an account problem. Review whether the source IP has touched other users, whether similar user agents or sign-in times appear elsewhere, and whether forwarding or delegation changes are clustered around the same period. If the activity is consistent, the issue may already extend beyond the first mailbox and into adjacent accounts or shared operational mailboxes.
For the response team, the key question is whether the suspicious access changed how mail is received, hidden, or redirected. If inbox rules, auto-forwarding, or delegated access exist, they can create durable access even after the initial password or session is reset. That is why scoping should include both compromise evidence and business-flow impact, especially in tenants where finance, payroll, or executive mailboxes are frequent targets. NIST SP 800-53 Rev 5 Security and Privacy Controls is relevant because audit, access control, and account monitoring controls support exactly this kind of traceable investigation.
Where a mailbox can forward mail externally or allow another principal to read and send on behalf of the user, the investigation should extend to downstream recipient accounts and any business process that depends on that mailbox. In BEC, the visible account is often only the first stage of the abuse chain.
Risk and Threat Considerations
A suspected BEC lead is risky because mailbox access is often enough to observe conversations, intercept invoices, and redirect payments without needing broader tenant compromise. The main danger is not only account takeover, but silent persistence through rules, forwarding, or delegated access that keeps working after the original sign-in is contained.
Failure mechanism: Attackers use a valid login, stolen session, or mailbox change to establish durable mail-flow control, then hide in normal-looking access patterns while continuing the fraud campaign.
Impact: Teams can miss the true scope of the compromise, leave redirect paths in place, and allow business email fraud to continue after the first alert is closed.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1078 — Valid Accounts | BEC investigations hinge on valid login use and account abuse. |
| T1114 — Email Collection | Mailbox access and message interception are core BEC objectives. | |
| Recommendation — Map suspicious sign-ins to valid-account abuse and hunt for follow-on persistence. Trace mailbox access and forwarding changes to identify message collection and diversion. | ||
| NIST SP 800-53 Rev 5 | AU-6 — Audit Review, Analysis, and Reporting | Investigating logins and mailbox changes depends on audit review and correlation. |
| AC-6 — Least Privilege | Delegated access and mailbox permissions can enable or limit BEC abuse. | |
| IA-5 — Authenticator Management | Suspicious Microsoft 365 access often involves compromised credentials or sessions. | |
| Recommendation — Correlate sign-in and mailbox audit records to reconstruct the compromise timeline. Review and minimize mailbox permissions that enable unauthorized message access. Rotate or revoke compromised authenticators and session material immediately. | ||
Practitioner Guidance
What to verify: Confirm the source IP, the first suspicious sign-in, and the first mailbox-setting change before you trust any higher-level summary. If those three do not line up, you may be looking at a secondary symptom rather than the entry point.
Common mistake: Teams often reset the password and stop there. For BEC, that is usually incomplete unless inbox rules, forwarding, delegated access, and any external message redirection have also been checked.
Practitioner takeaway: The investigation succeeds when it explains how mail flow changed, not just how access began, because BEC is usually a persistence and redirection problem as much as an authentication problem.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org