What to Do If You Clicked a Phishing Link in Microsoft 365?
We've all been there. You're tired, distracted, or in a rush - and suddenly you realise you've clicked a dodgy link. Maybe it looked like a Microsoft login page, a parcel delivery update, or a "your password is expiring" message.
The important thing is this: Don't panic. A phishing click is not the end of the world, provided you act quickly and calmly. Here is exactly what to do if you suspect you've been "hooked" while using Microsoft 365.

1. Stop and Disconnect Immediately
If the suspicious page is still open, close it right now. Don't enter any more data, don't click "Allow" on any prompts, and don't download any files. If you did enter your password, don't worry - we're going to fix that next.
2. Change Your Microsoft 365 Password
This is the single most important step. A phishing page's goal is usually to steal your login details. Changing your password instantly cuts off the attacker's access.
Choose a strong password: Aim for at least 12 characters.
Make it unique: Do not reuse a password from another site.
Use a Password Manager: Ideally, use a password manager to generate something truly random.
3. Sign Out of All Sessions
Microsoft allows you to "kill" every active connection to your account at once. This is a powerful move that forces every device (including the attacker's) to re-authenticate.
Go to your Microsoft Security Info page.
Select "Sign out everywhere".
This ensures that even if someone gained entry, they are kicked out immediately.
4. Reset Your MFA (Multi-Factor Authentication)
If you typed an MFA code into a fake page, the attacker might have "cloned" your session. To be 100% safe, you should reset your authentication methods.
Remove any authentication methods you don't recognise.
Re-add the Microsoft Authenticator app.
Update your backup phone numbers if necessary.
5. Check Your Mailbox Rules (The "Hidden" Danger)
This is a critical step that many people miss. Attackers often create hidden rules to:
Forward your emails to their own address.
Hide incoming messages from your IT admin.
Automatically delete security alerts so you don't see them.
In Outlook: Go to Settings > Mail > Rules. If you see a rule you didn't create, delete it immediately.

6. Review Your Recent Sign-ins
Microsoft logs every single attempt to log into your account. It's worth a quick check to see if anyone succeeded.
Visit the Microsoft "My Sign-ins" page.
Look for unknown locations or devices.
If you see a successful login from a country, you aren't in, mark it as "This wasn't me".
7. Run a Full Antivirus Scan
If the phishing link triggered a download or asked you to "update" something, your device might be infected with malware.
Open Windows Security.
Run a Full Scan with Microsoft Defender.
If you're on a Mac, use your managed security software to sweep the system.
8. Tell Your IT Admin
Phishing is not a personal failure - it's a numbers game. Attackers send millions of these emails because they only need one person to click. Telling your IT admin (or your managed service provider) as soon as possible allows them to:
Block the malicious sender and domain for the whole company.
Run a message trace to see if anyone else was targeted.
Review audit logs to confirm no data was exported.

Need help securing your team?
At I.T. Savvy, we believe in supporting users without judgment. If you're worried about your business's security posture or want to train your staff to spot these links before they click, feel free to reach out.
*Want more practical security tips? Check out our full blog at [itsavvy.com.au/blog](https://www.itsavvy.com.au/blog)*


Comments