Microsoft 365 Security

Microsoft 365 Phishing: How to Spot It and What to Do

Microsoft 365 is the single most valuable target in most small businesses — one compromised login opens email, SharePoint files, Teams conversations, and often connected financial systems. Here's what M365 phishing usually looks like, and how to check a suspicious link or email before it costs you access to everything.

Scan a Link or Email — Free →

Why attackers target Microsoft 365 specifically

Most businesses run their entire day through M365 — email, file storage, chat, and single sign-on into other tools. Compromising one account often means compromising all of it at once, which is why M365 credential phishing is one of the most common attacks small businesses face.

Common Microsoft 365 phishing patterns

  • Fake login pages that copy Microsoft's branding pixel-for-pixel, hosted on a lookalike domain.
  • "Your password expires today" urgency emails linking to a credential-harvesting page.
  • Malicious OAuth app consent requests that ask you to grant a third-party app permission to your mailbox — see the FAQ below.
  • Shared "document" notifications ("someone shared a file with you") linking to a fake sign-in wall instead of a real document.

How to verify a Microsoft 365 link before you click

Hover over the link (or long-press on mobile) to see the actual destination before clicking, then paste that URL into TrustCan's link checker. TrustCan's lookalike-domain detection specifically flags common Microsoft-brand impersonation patterns.

If your Microsoft 365 account may already be compromised

  • Check inbox rules for anything forwarding or silently deleting mail.
  • Review sign-in logs for unfamiliar locations or devices.
  • Revoke active sessions and reset the password.
  • Contact Phenicie Business Management for a free incident triage — see below.

Frequently asked questions

How do I check if a Microsoft 365 login link is real?
Paste the link into TrustCan before you enter anything. A real Microsoft sign-in should land on a microsoftonline.com or your organization's actual verified domain — not a lookalike domain with extra words, hyphens, or a different top-level domain.
What is OAuth consent phishing?
Instead of stealing your password directly, the attacker tricks you into granting a malicious third-party app permission to access your mailbox and files — through a legitimate-looking Microsoft consent screen. Because it doesn't touch your password, it can bypass MFA entirely, which is what makes it dangerous.
How do I know if my Microsoft 365 account has been compromised?
Check your inbox rules for anything you didn't create (especially rules that forward or delete mail silently), review your account's sign-in activity for unfamiliar locations or devices, and check connected apps under your account's app permissions for anything you don't recognize.
Can Phenicie Business Management review our M365 tenant configuration?
Yes — this is part of the free security baseline offer below, which includes a review of your Microsoft 365 configuration alongside email security, endpoint protection, and backups.
Worried someone already clicked, downloaded a file, entered a password, or sent money? Contact Phenicie Business Management now at (406) 957-1576.

Someone interacted with a suspicious email or link?

Phenicie Business Management offers a free initial incident triage to help determine the next action.

Protect your business before the next phishing attack.

Request a free business security baseline covering email security, endpoint protection, Microsoft 365, backups, and common cyber-insurance requirements.

TrustCan is a free tool from Phenicie Business Management, a Montana-based IT and cybersecurity provider.

Call (406) 957-1576