Managing personal Outlook.com account settings, security, and privacy
For suspected security breaches or unauthorized changes in communication apps and online accounts, take these steps:
- Secure accounts immediately
- Change passwords for email, Microsoft account, and any communication apps (Teams, Skype, etc.).
- Turn on multifactor authentication (MFA) wherever available, especially for email, code repositories, DNS management, and credentials, as many secure services do.
- Sign out of all active sessions in each app/service and sign back in with the new password.
- Check and reset permissions and security settings
- In each communication app and online service, review:
- Connected devices and sessions; remove any unknown ones.
- App permissions/connected apps; remove anything not recognized.
- Security and privacy settings; reset to defaults or to stricter options.
- For telecommunications-related apps (calling, messaging, or compliance/archiving tools), verify:
- Who can access call logs, messages, or recordings.
- Admin roles and delegated access; remove any unexpected admin or shared access.
- In each communication app and online service, review:
- Capture evidence
- Take screenshots of suspicious activity, unexpected permission changes, or alerts.
- Note dates, times, and the names of affected apps/services.
- Report the issue
- Use the in‑product “Report a problem” or “Report abuse/security” option where available in each app.
- If the suspected breach involves a third‑party app integrated with Microsoft 365 (for example, Teams or Outlook add‑ins), locate that app’s security/contact information and report:
- What happened (suspicious messages, calls, or configuration changes).
- When it happened.
- Which accounts or devices are affected.
- For broader fraud or theft concerns (for example, compromised keys or credentials sold or reused), submit a report through Microsoft’s fraud reporting channel such as the one used for product key theft/fraud.
- Monitor for ongoing issues
- Regularly review sign‑in logs and security alerts in account security pages.
- Watch for new suspicious messages, calls, or configuration changes.
- If new events appear, update the incident report with the provider.
If there is evidence of a serious breach (for example, financial loss, identity theft, or large‑scale data exposure), also contact local authorities or a relevant regulatory body in addition to the service providers.
References: