Microsoft 365 and Google Workspace Email Security: How to Protect Business Accounts from Cyber Threats and Recover a Hacked Email Account
Business email has become one of the most valuable targets for cybercriminals. A compromised Microsoft 365 or Google Workspace account may give an attacker m...
Business email has become one of the most valuable targets for cybercriminals. A compromised Microsoft 365 or Google Workspace account may give an attacker much more than access to email. Depending on the user's permissions and services in use, the attacker may potentially reach cloud files, contacts, calendars, internal communications, shared documents, customer information, invoices, password-reset messages, and other business systems.
A particularly serious threat is Business Email Compromise (BEC). Instead of simply sending spam, an attacker takes control of or impersonates a legitimate business email account and uses the trust associated with that account to request payments, redirect invoices, obtain confidential information, or attack other employees and customers.
Microsoft specifically notes that compromised credentials can provide access not only to a Microsoft 365 mailbox but also to associated resources such as OneDrive and SharePoint. Microsoft therefore recommends investigating both the affected identity and connected services after compromise.
Protecting business email should therefore be treated as an identity-security project, not merely an email-spam problem.
1. How Can Microsoft 365 Accounts Be Protected from Cyber Threats?
Microsoft 365 security should use multiple defensive layers. No single control—including a strong password—is sufficient.
1.1 Require Multi-Factor Authentication
Multi-factor authentication (MFA) is one of the most important security controls for Microsoft 365.
With MFA, possession of the username and password alone should not be sufficient to access the account.
Authentication can involve:
- Password
- Microsoft Authenticator
- Passkey
- Windows Hello for Business
- FIDO2 hardware security key
- Certificate-based authentication
- Other organization-approved authentication methods
Microsoft recommends MFA broadly and specifically recommends phishing-resistant MFA for privileged administrative roles.
Prefer phishing-resistant authentication
Traditional MFA is substantially better than password-only authentication, but organizations handling sensitive information should move toward phishing-resistant MFA.
Examples include:
- FIDO2 security keys
- Passkeys
- Windows Hello for Business
- Appropriate certificate-based authentication
Microsoft identifies phishing-resistant MFA as its strongest built-in authentication-strength category.
This is particularly important for:
- Global Administrators
- Exchange Administrators
- Security Administrators
- Conditional Access Administrators
- User Administrators
- Helpdesk Administrators
- Billing Administrators
- Application Administrators
Administrative accounts are high-value targets because compromising one account can potentially expose an entire Microsoft 365 tenant.
1.2 Use Conditional Access Where Licensing Supports It
Microsoft Entra Conditional Access allows administrators to make access decisions using identity and contextual signals.
A policy can effectively say:
If these conditions occur, require these security controls before granting access.
For example, an organization might require MFA when:
- A user signs in from an unusual location
- A privileged administrator accesses Microsoft 365
- A user accesses sensitive cloud applications
- The device does not meet organizational requirements
- Sign-in risk exceeds an acceptable threshold
Microsoft describes Conditional Access as a key Zero Trust policy engine for identity-based access control.
Organizations should design Conditional Access carefully and test policies before broad enforcement to avoid accidental lockouts.
1.3 Protect Administrator Accounts More Aggressively
A normal employee account and a Global Administrator account should not necessarily have identical security policies.
Recommended practices include:
- Use separate administrator and everyday user accounts.
- Do not routinely browse the internet or read ordinary email using highly privileged accounts.
- Require strong MFA for administrators.
- Prefer phishing-resistant authentication.
- Minimize the number of Global Administrators.
- Regularly review privileged role assignments.
- Remove administrative permissions that are no longer necessary.
- Maintain carefully controlled emergency-access procedures.
The principle of least privilege should apply: users receive only the permissions required to perform their jobs.
2. Use Strong and Unique Passwords
Every Microsoft 365 account should have a unique credential.
Never reuse a Microsoft 365 password for:
- Personal Gmail
- Social media
- Banking websites
- Other business portals
- Vendor portals
- Remote-access accounts
- Unrelated cloud applications
Password reuse creates a credential-stuffing risk. If an unrelated website is breached, attackers may test the stolen email/password combination against Microsoft 365.
A reputable password manager can help employees maintain long, unique credentials.
3. Control Legacy and Unnecessary Authentication
Older authentication mechanisms can weaken modern account protection.
Organizations should identify applications, devices, scanners, scripts, and email clients that depend on older authentication technologies and migrate them to supported modern authentication where possible.
Before disabling an older protocol, however, administrators should verify whether business-critical applications still depend on it.
4. Protect Against Phishing
Microsoft 365 credentials are frequently stolen through fake login pages.
A phishing email might claim:
- Your password is expiring.
- Your mailbox is full.
- A document has been shared with you.
- Your Microsoft 365 account will be suspended.
- You have received a secure voicemail.
- An invoice requires approval.
- Your administrator requires account verification.
The victim clicks a link and reaches a website designed to resemble a Microsoft sign-in page.
Users should verify suspicious login requests rather than automatically entering credentials.
5. Consider Microsoft Defender for Office 365
Organizations requiring enhanced email threat protection should evaluate the protections available in their Microsoft 365 subscription and Microsoft Defender for Office 365.
Depending on licensing and configuration, security capabilities can help address threats involving:
- Phishing
- Malicious links
- Malicious attachments
- Impersonation
- Business Email Compromise
- Suspicious messages
- Post-delivery threats
Licensing and available functionality vary, so administrators should verify which protections are included in their Microsoft 365 plan.
6. Monitor Microsoft 365 Sign-In Activity
Account compromise often leaves evidence.
Administrators should investigate indicators such as:
- Sign-ins from unexpected countries
- Unfamiliar IP addresses
- Unusual sign-in times
- Multiple failed authentication attempts
- New authentication methods
- Unexpected devices
- Unexpected applications receiving consent
- Unexplained password changes
Microsoft recommends examining Entra sign-in information and audit data when investigating a compromised account.
Security logs should therefore be treated as an important part of incident response.
7. Watch for Malicious Inbox Rules and Forwarding
Attackers who compromise a mailbox frequently try to maintain surveillance without attracting attention.
They may create rules that:
- Forward emails externally
- Delete specific messages
- Hide replies
- Move messages into unusual folders
- Redirect financial correspondence
- Hide security notifications
Microsoft lists suspicious Inbox rules and newly configured external forwarding among common indicators of mailbox compromise.
Administrators investigating an incident should therefore examine both mailbox rules and forwarding configuration.
8. Control Third-Party Applications and OAuth Permissions
An attacker does not always need to keep the victim's password.
A malicious application may convince the user to grant OAuth permissions. Depending on the permissions granted, the application could retain access even after a password change.
Administrators should regularly review:
- Enterprise applications
- User-consented applications
- OAuth permissions
- Application registrations
- Suspicious third-party integrations
Microsoft specifically recommends reviewing and revoking unauthorized application consent during compromised-account remediation.
9. How Can Google Workspace Accounts Be Protected from Cyber Threats?
The same fundamental principles apply to Google Workspace: secure the identity, enforce strong authentication, control applications, monitor activity, protect administrators, and train users against phishing.
9.1 Enforce 2-Step Verification
Organizations should enforce 2-Step Verification (2SV) rather than leaving protection entirely to individual users.
Google recommends 2-Step Verification because a stolen password alone is then insufficient for normal account access.
For high-value accounts, stronger authentication should be preferred.
10. Use Passkeys or Security Keys for High-Risk Accounts
Google supports passkeys and hardware security keys.
Google notes that passkeys provide strong protection against phishing because they cannot simply be copied or typed into a fraudulent website in the same manner as passwords.
Security keys are especially appropriate for:
- Super administrators
- Senior management
- Finance teams
- Payroll employees
- Accounts personnel
- IT administrators
- Employees handling confidential information
Google's administrator security guidance recommends 2-Step Verification for administrators and identifies security keys as a strong phishing-resistant option.
11. Never Share Google Workspace Administrator Accounts
Every administrator should have an individual account.
Avoid arrangements such as several IT employees sharing:
admin@company.com
Shared administrator accounts make accountability difficult because audit logs cannot clearly establish which administrator performed a particular action.
Google specifically recommends providing administrators with individually identifiable accounts rather than sharing one administrator login.
12. Protect Google Super Administrator Accounts
Super administrator accounts deserve exceptional protection because they can control users and organizational settings.
Recommended practices include:
- Enforce strong 2-Step Verification.
- Prefer security keys/passkeys.
- Do not share credentials.
- Maintain more than one appropriately controlled Super Admin for recovery.
- Minimize routine use of Super Admin accounts.
- Review administrative activity.
- Maintain secure recovery procedures.
Google recommends having multiple Super Admin accounts managed by separate individuals rather than relying on one shared administrator identity.
13. Perform Google Security Checkups
Users should periodically review account security information.
Google's Security Checkup can identify recommendations involving areas such as:
- Recovery options
- Authentication
- Account access
- Security alerts
- Connected applications
Google recommends periodically using Security Checkup and keeping recovery information current.
14. Review Third-Party Application Access
Google Workspace environments frequently integrate with CRM applications, backup products, document utilities, browser extensions, accounting tools, and other SaaS platforms.
Every integration expands the potential attack surface.
Administrators should periodically determine:
- Which applications have access?
- What data can they access?
- Which users authorized them?
- Is the application still required?
- Is the vendor trustworthy?
- Are requested permissions excessive?
Remove unused or suspicious integrations.
15. Protect Endpoints, Not Just Email Accounts
MFA cannot solve every security problem.
If the employee's computer is infected by an information-stealing malware family, attackers may attempt to steal:
- Browser cookies
- Session tokens
- Saved passwords
- Browser data
- Authentication information
- Documents
- Email content
Therefore, Microsoft 365 and Google Workspace security should be combined with endpoint security.
Business computers should have:
- Supported operating systems
- Current security patches
- Antivirus/endpoint protection
- EDR where appropriate
- Firewall protection
- Browser updates
- Controlled administrator privileges
- Disk encryption where appropriate
Google similarly recommends removing unnecessary applications and browser extensions, particularly on devices that access sensitive information.
16. Configure SPF, DKIM and DMARC
Protecting the mailbox login is only part of email security.
Organizations should also configure email authentication technologies.
SPF
Sender Policy Framework (SPF) identifies servers authorized to send mail for a domain.
DKIM
DomainKeys Identified Mail (DKIM) cryptographically signs outgoing messages so receiving systems can verify that authorized infrastructure sent them and that relevant message content has not been improperly modified.
DMARC
Domain-based Message Authentication, Reporting and Conformance (DMARC) builds on SPF and DKIM and allows domain owners to specify how receivers should handle messages that fail authentication and alignment checks.
Correct implementation helps reduce domain spoofing and improves visibility into unauthorized use of the organization's domain.
DMARC policies should be deployed carefully. Organizations should understand legitimate mail sources before moving aggressively to restrictive policies.
17. Train Employees Against Business Email Compromise
Technology cannot eliminate every BEC scenario.
Employees—particularly finance and accounts teams—should have a separate verification procedure for:
- Bank-account changes
- Large payments
- Urgent wire transfers
- Vendor account changes
- Payroll changes
- Requests for confidential information
For example, a request saying:
"Our bank account has changed. Please send all future payments to this account."
should be independently verified using a known telephone number or another trusted communication channel—not contact information supplied in the suspicious email itself.
18. What Should I Do If My Business Email Account Is Hacked?
A suspected compromise should be treated as a cybersecurity incident.
Speed matters, but simply changing the password is not enough.
Step 1: Isolate the affected account
If administrators control the account, consider temporarily disabling or suspending access while investigating.
Microsoft recommends disabling a compromised Microsoft 365 account during investigation when feasible.
The objective is to stop continued attacker activity.
Step 2: Reset the password
Set a completely new and unique password.
Do not:
- Reuse the previous password.
- Use a password already used elsewhere.
- Send the new password to the compromised mailbox.
If the same password was used on other services, those credentials should also be changed.
Step 3: Revoke active sessions
This step is extremely important.
Changing a password does not mean administrators should assume every existing authenticated session has immediately become harmless.
For Microsoft 365, revoke the user's active sign-in sessions as part of remediation. Microsoft specifically includes session revocation in its compromised-account response procedure.
For Google accounts, review devices and account access and remove unauthorized sessions/devices as part of securing the compromised account.
Step 4: Verify MFA/2SV methods
Attackers sometimes register their own authentication method after gaining access.
Check for unknown:
- Phone numbers
- Authenticator registrations
- Security keys
- Passkeys
- Recovery addresses
- Authentication devices
Remove anything that cannot be positively identified.
Microsoft explicitly recommends reviewing registered MFA devices after account compromise.
Step 5: Check forwarding configuration
Look for unauthorized forwarding to external addresses.
Attackers may silently forward copies of incoming correspondence to themselves.
Remove every unexplained forwarding destination.
Step 6: Inspect Inbox rules and filters
Check for malicious rules that:
- Delete messages
- Archive messages
- Forward messages
- Move security alerts
- Hide replies
- Redirect payment-related communication
A malicious rule may remain after the attacker loses direct access.
Step 7: Review third-party applications
Revoke suspicious OAuth applications, connected applications and other integrations.
This is critical because changing the password without removing unauthorized application access may leave another route into company data.
Step 8: Review sign-in and audit logs
Determine:
- When did the compromise begin?
- Which IP addresses were involved?
- Which locations were involved?
- Which devices were used?
- What applications were accessed?
- Were security settings changed?
- Were administrator privileges changed?
For Microsoft 365, investigate Microsoft Entra sign-in logs, relevant audit logs and mailbox activity. Microsoft also recommends using message tracing and reviewing sent messages during the affected period.
Step 9: Check Sent, Deleted, Draft and Other Mail Folders
Look for messages that the legitimate employee did not send.
Pay particular attention to:
- Payment requests
- Password-reset messages
- Vendor communications
- Invoice changes
- Requests for confidential documents
- Messages sent to customers
- Internal phishing emails
Determine the time window during which the attacker controlled the account.
Step 10: Scan the employee's devices
If credentials were stolen by malware, securing the cloud account while leaving the infected computer untouched may result in another compromise.
Scan the endpoint for:
- Information stealers
- Remote-access Trojans
- Keyloggers
- Malicious browser extensions
- Unauthorized remote-access software
- Credential-stealing malware
Where serious compromise is suspected, an organization may need a formal endpoint investigation rather than relying solely on a quick antivirus scan.
19. Check Whether Other Accounts Are Compromised
If one employee has been compromised, investigate whether the attacker moved laterally.
Check:
- Other employees who received messages from the compromised mailbox
- Administrator accounts
- Finance/accounts accounts
- Shared mailboxes
- Similar suspicious sign-ins
- Recently created forwarding rules
- Newly registered authentication methods
- Suspicious OAuth applications
Attackers commonly use a trusted internal mailbox to target other employees.
20. Protect Customers and Vendors
If fraudulent messages were sent externally, affected recipients may need to be warned.
For example:
Do not process any payment or bank-account-change instructions received from our compromised email account during the affected period until independently verified.
This can be especially important if attackers attempted invoice fraud.
21. Contact Financial Institutions Immediately When Money Is Involved
If a compromised mailbox resulted in:
- Fraudulent bank transfers
- Changed beneficiary information
- Unauthorized payments
- Credit-card exposure
- Invoice diversion
contact the relevant bank or payment institution immediately.
Time can be critical in financial-fraud incidents.
Google's compromised-account guidance similarly recommends contacting financial institutions or appropriate authorities when sensitive financial or identity information may have been affected.
22. Preserve Evidence
Do not immediately delete every suspicious message or log entry before investigation.
Preserve useful evidence such as:
- Suspicious emails
- Email headers
- Sign-in logs
- Audit logs
- IP addresses
- Timestamps
- Inbox rules
- Forwarding settings
- OAuth applications
- Security alerts
- Screenshots
- Malicious URLs
Evidence can help determine what happened and whether customers, regulators, insurers, law enforcement, or other parties need to be informed.
23. Microsoft 365 vs Google Workspace: Recommended Security Baseline
| Security Control | Microsoft 365 | Google Workspace |
|---|---|---|
| Strong unique passwords | Yes | Yes |
| MFA/2SV | MFA | 2-Step Verification |
| Passkeys | Supported | Supported |
| Hardware security keys | Supported | Supported |
| Phishing-resistant authentication | Recommended | Recommended |
| Dedicated administrator accounts | Recommended | Recommended |
| Login monitoring | Entra sign-in/audit capabilities | Google Workspace security/audit capabilities |
| Third-party application review | Yes | Yes |
| Email forwarding monitoring | Yes | Yes |
| SPF/DKIM/DMARC | Recommended | Recommended |
| Endpoint protection | Recommended | Recommended |
| Security-awareness training | Recommended | Recommended |
| Incident-response procedure | Essential | Essential |
24. Recommended Business Email Security Checklist
Every organization using Microsoft 365 or Google Workspace should aim to implement the following baseline:
- Enable MFA/2SV for every user.
- Require stronger phishing-resistant authentication for administrators and high-risk employees.
- Use unique passwords.
- Use a reputable password manager where appropriate.
- Maintain separate administrative accounts.
- Minimize administrator privileges.
- Regularly review login and audit activity.
- Review forwarding rules and mailbox filters.
- Review OAuth and third-party application permissions.
- Keep operating systems and browsers patched.
- Deploy appropriate endpoint protection.
- Configure SPF.
- Configure DKIM.
- Configure DMARC.
- Train employees to recognize phishing.
- Independently verify financial-account changes.
- Maintain secure account-recovery procedures.
- Maintain incident-response procedures.
- Regularly review former employee accounts and access.
- Periodically audit Microsoft 365 or Google Workspace security settings.
Frequently Asked Questions (FAQ)
1. Is a strong password enough to protect Microsoft 365?
No. Strong passwords remain important, but Microsoft 365 accounts should also use MFA. Privileged accounts should preferably use phishing-resistant authentication.
2. Is Google Workspace 2-Step Verification necessary for business users?
Yes. Business organizations should strongly consider enforcing 2-Step Verification instead of relying on employees to enable it voluntarily.
3. Which accounts need the strongest security?
Prioritize:
- Global/Super Administrators
- IT administrators
- Finance personnel
- Accounts employees
- Payroll users
- Directors and executives
- HR users
- Employees with access to sensitive customer information
Ideally, strong authentication should eventually cover the entire organization.
4. Are SMS verification codes secure?
SMS-based verification is generally better than password-only authentication, but stronger phishing-resistant methods such as security keys and passkeys are preferable for high-risk users where practical.
5. Can MFA stop every email attack?
No. MFA significantly improves account security but cannot eliminate malicious OAuth consent, malware, session theft, social engineering, incorrectly configured recovery mechanisms, or authorized-user mistakes.
6. What is phishing-resistant MFA?
It is authentication designed to prevent users from accidentally giving an attacker reusable authentication credentials through a phishing website. FIDO2 security keys and appropriately implemented passkeys are common examples.
7. What is Business Email Compromise?
Business Email Compromise, or BEC, occurs when criminals impersonate or compromise a trusted business identity to manipulate employees, customers, or vendors—frequently for financial fraud or confidential information.
8. How do I know whether my email account has been hacked?
Warning signs can include:
- Unknown sent messages
- Missing emails
- Unexpected password resets
- Unknown forwarding
- Suspicious Inbox rules
- Unknown authentication methods
- Unexpected login locations
- Unrecognized devices
- Unexpected OAuth applications
- Customers reporting strange emails
Microsoft specifically identifies suspicious rules, deleted or missing mail, unexpected forwarding, suspicious sent messages and unexplained account activity as possible compromise indicators.
9. Should I change my password immediately after an email hack?
Yes, but password reset should be part of a broader response that includes session revocation, authentication-method review, forwarding/rule inspection, application-consent review and investigation of logs.
10. Should all sessions be signed out after compromise?
Yes. Revoking active sessions helps invalidate existing authenticated access and is an important part of incident containment.
11. Can hackers continue accessing email after the password is changed?
Potentially. Persistence may involve authenticated sessions, malicious applications, forwarding rules, authentication methods, compromised endpoints or other mechanisms. This is why a password change alone should not be considered complete remediation.
12. Should I check email forwarding after a hack?
Absolutely. Attackers frequently configure forwarding to monitor communications even after the victim believes the incident has been resolved.
13. Should I check Inbox rules?
Yes. Malicious Inbox rules can hide security notifications, delete messages, redirect correspondence or conceal responses from customers and vendors.
14. What should I do if a hacker sent emails to my customers?
Determine which messages were sent, preserve evidence and promptly warn affected recipients when there is a meaningful risk. Payment instructions should be independently reconfirmed.
15. What if money was transferred because of a hacked email?
Contact the bank or payment provider immediately and follow your organization's fraud-response and legal procedures. Depending on the jurisdiction and circumstances, reporting to appropriate authorities may also be necessary.
16. Should administrator accounts be used for normal email?
Ideally, highly privileged administrator identities should be separated from normal day-to-day browsing and email activities whenever practical.
17. What is Conditional Access in Microsoft 365?
Microsoft Entra Conditional Access is an identity-driven policy system that can require controls such as MFA based on users, resources and contextual signals.
18. What is the safest authentication method for Google Workspace administrators?
Google recommends strong 2-Step Verification and highlights security keys as a highly secure, phishing-resistant option for administrator accounts.
19. Do SPF, DKIM and DMARC prevent mailbox hacking?
No. They primarily help authenticate email domains and reduce spoofing/impersonation risks. They complement—but do not replace—MFA, password security, endpoint protection and account monitoring.
20. How often should business email security be reviewed?
Organizations should continuously monitor important alerts and periodically perform formal security reviews. Reviews are also advisable after employee departures, administrator changes, suspicious activity, major configuration changes or security incidents.
Conclusion
Microsoft 365 and Google Workspace security should be built around identity protection, phishing-resistant authentication, least privilege, secure endpoints, monitoring and incident preparedness.
For most businesses, one of the highest-priority improvements is simple:
Do not leave important business email accounts protected only by a password.
Enable MFA or 2-Step Verification throughout the organization, use stronger phishing-resistant authentication for administrators and high-risk employees, monitor account activity, review application permissions, protect endpoints, and configure SPF, DKIM and DMARC.
Most importantly, organizations should have a documented procedure for compromised accounts before an incident occurs.
When a business mailbox is hacked, the response should go beyond changing the password. The organization should contain the account, revoke sessions, verify MFA/2SV methods, inspect forwarding and Inbox rules, revoke suspicious applications, investigate login and audit activity, scan affected endpoints, determine what information was accessed, and notify affected parties when appropriate.
A compromised mailbox should be treated as a business cybersecurity incident, because the consequences can extend far beyond email.
#Tags
#Microsoft365 #GoogleWorkspace #EmailSecurity #CyberSecurity #BusinessEmailSecurity #Microsoft365Security #GoogleWorkspaceSecurity #Office365Security #GmailSecurity #AccountSecurity #EmailProtection #MFA #MultiFactorAuthentication #TwoStepVerification #2StepVerification #Phishing #PhishingProtection #BusinessEmailCompromise #BEC #EmailHacking #HackedEmail #AccountTakeover #CyberThreats #CyberAttack #IdentitySecurity #ZeroTrust #ConditionalAccess #MicrosoftEntra #MicrosoftDefender #GoogleAdmin #SecurityKeys #FIDO2 #Passkeys #PasswordSecurity #CloudSecurity #EndpointSecurity #EDR #MalwareProtection #SPF #DKIM #DMARC #EmailSpoofing #CyberAwareness #InformationSecurity #DataProtection #IncidentResponse #OAuthSecurity #AdminSecurity #CyberSafety #BusinessCyberSecurity
Was this guide useful?
Your answer helps us keep BISONKB accurate and practical.