Skip to the main content.

Modernize & Transform

Built to help you reimagine IT operations, empower your workforce, and leverage AI-powered tools to stay ahead of the curve.

Untitled design (3)

Empower My Team

We bring together the best of Microsoft’s cloud ecosystem and productivity tools to help your people thrive.

Untitled design (3)

Build My Infrastructure

We offer a comprehensive suite of infrastructure services tailored to support your business goals today and scale for the future

Untitled design (3)

IT Services

Our managed and co-managed IT service plans deliver a responsive and innovative engagement to support your IT needs, improve employee experience, and drive growth for your business. 

Untitled design (3)

Cybersecurity Services

Sourcepass offers innovative solutions, including SOC, GRC, Security Assessments, and more to protect your business.

Untitled design (3)

Professional Services

Grow your business with cloud migrations, infrastructure refreshes, M&A integrations, staff augmentation, technical assessments, and more.

Untitled design (3)

Industries

We understand what most managed service providers don’t – when it comes to industry-specific technology, one-size-fits-all solutions don’t exist.

Untitled design (3)

Public Sector

Sourcepass GOV, a division of Sourcepass, is dedicated to providing specialized IT solutions for the public sector.

Untitled design (3)

Locations

We have coverage across the United States, with phyiscal locations across 8 states. Wherever you are, Sourcepass has your back.

Untitled design (3)

Resource Library

Stay ahead, stay connected, and discover the future of IT with Sourcepass.

Untitled design (3)

Events & Webinars

Dive into a dynamic calendar of webinars and in-person gatherings designed to illuminate the latest in managed IT services, cybersecurity, and automation.

Untitled design (3)

Resources by Role

Explore key resources, eBooks, video trainings, and more curated for CEOs, CFOs, CIOs, CISOs, and technology leaders!

Untitled design (3)

The Sourcepass Story

Sourcepass aims to be different. It is owned and operated by technology, security, and managed services experts who are passionate about delivering an IT experience that clients love.

Untitled design (3)

The Sourcepass Experience

At Sourcepass, we’re rewriting the IT and cybersecurity experience by helping businesses focus on what they do best, while we deliver the infrastructure, insights, and innovation to help them thrive.

Untitled design (3)

 

How Business Email Compromise Happens in Microsoft 365

 
How Business Email Compromise Happens in Microsoft 365

Business Email Compromise (BEC) has become one of the most costly and disruptive cyber threats facing organizations today. Unlike ransomware or malware campaigns, BEC attacks often rely on legitimate user accounts, trusted communications, and normal business processes. That makes them particularly difficult to detect.

For organizations operating in Microsoft 365, business email compromise is fundamentally an identity security challenge. Attackers no longer need to break through a network perimeter when they can gain access to a trusted account and operate as a legitimate user.

Understanding how BEC attacks occur, what warning signs to watch for, and how identity threat detection can reduce risk is critical for executives, operations leaders, and IT decision-makers responsible for protecting business communications and financial processes.

 

What Is Business Email Compromise?

Business Email Compromise is a cyberattack in which a threat actor gains access to or impersonates a trusted email account to manipulate employees, vendors, customers, or business partners.

Unlike traditional phishing attacks that often contain malicious links or attachments, BEC attacks frequently involve legitimate email accounts and authentic-looking communications. The goal is typically to influence a business process, such as approving a payment, changing banking information, or accessing sensitive information.

According to guidance from the Internet Crime Complaint Center, business email compromise remains one of the highest financial-loss cybercrime categories globally.

 

Why Microsoft 365 Is a Target for Business Email Compromise

Microsoft 365 sits at the center of business operations for many organizations.

A single Microsoft 365 account can provide access to:

  • Exchange Online email
  • Microsoft Teams conversations
  • SharePoint content
  • OneDrive files
  • Calendars and contacts
  • Third-party SaaS applications connected through Microsoft identity services

For an attacker, compromising one identity can provide visibility into how an organization operates, who approves payments, which vendors are used, and where sensitive information resides.

This is why modern attackers increasingly focus on credential theft and account compromise rather than traditional malware delivery.

 

How Business Email Compromise Happens

 

Credential Phishing

Many BEC incidents begin with a phishing campaign designed to steal Microsoft 365 credentials.

Attackers create convincing login pages that resemble Microsoft sign-in experiences and attempt to capture usernames, passwords, and sometimes multifactor authentication information.

Once access is obtained, attackers can begin monitoring communications without immediately revealing their presence.

 

Session Token Theft

Modern attackers increasingly target authenticated sessions instead of passwords.

Through adversary-in-the-middle attacks and token theft techniques, attackers may gain access to active Microsoft 365 sessions even when multifactor authentication is enabled.

Because the session appears legitimate, unauthorized activity can be difficult to distinguish from normal user behavior.

 

Password Reuse and Credential Exposure

Employees frequently use multiple platforms and services throughout their daily work.

If credentials are reused across personal and business accounts, exposure from a third-party breach can create opportunities for attackers to gain access to Microsoft 365 environments.

The problem is often compounded when dormant accounts, weak passwords, or insufficient monitoring remain in place.

 

Unauthorized Application Consent

Microsoft 365 allows users to authorize third-party applications to access organizational information.

Attackers may use deceptive consent requests to convince users to grant permissions to malicious applications. Once approved, these applications may maintain access to email, files, and other resources without requiring the user's password.

This technique allows attackers to establish persistence while avoiding many traditional security controls.

 

What Attackers Do After Accessing a Microsoft 365 Account

Many organizations assume compromise will be obvious. In reality, sophisticated BEC activity is often quiet and deliberate.

 

Monitoring Communications

Attackers frequently spend time learning how the organization operates before taking action.

They may monitor:

  • Executive communications
  • Finance processes
  • Vendor relationships
  • Contract discussions
  • Accounts payable workflows

This reconnaissance helps attackers craft requests that appear legitimate.

 

Creating Mailbox Rules

One common tactic involves creating hidden mailbox rules.

These rules may:

  • Forward messages externally
  • Delete security notifications
  • Hide conversations from users
  • Redirect responses to attacker-controlled accounts

Microsoft 365 users may remain unaware these rules exist unless they are actively reviewed.

 

Impersonating Trusted Employees

Once attackers understand communication patterns, they may begin impersonating executives, finance personnel, or operational leaders.

Common requests include:

  • Urgent wire transfers
  • Vendor payment changes
  • Payroll updates
  • Confidential document requests
  • Gift card purchases

Because messages originate from legitimate or compromised accounts, recipients often trust the request.

 

Expanding Access Across the Environment

Attackers may attempt to compromise additional accounts and gain broader visibility across:

  • Microsoft Teams
  • SharePoint Online
  • OneDrive
  • Executive mailboxes
  • Finance systems

What begins as a single compromised account can quickly evolve into a broader security incident.

 

Why Traditional Email Security Tools Often Miss BEC Attacks

Traditional email security platforms are highly effective at blocking many forms of phishing, malware, and spam.

However, BEC attacks often occur after authentication has already succeeded.

When attackers use valid credentials:

  • Emails originate from trusted accounts
  • Authentication appears legitimate
  • Devices may already be known
  • User permissions are valid

From a traditional security perspective, the activity may appear normal.

The challenge becomes identifying behavior that differs from a user's established patterns rather than simply validating account access.

 

The Role of Identity Threat Detection and Response

Identity Threat Detection and Response (ITDR) addresses this gap by focusing on what happens after someone successfully authenticates.

Instead of only asking, "Did the user sign in successfully?" ITDR helps answer:

  • Is the behavior typical for this user?
  • Are mailbox actions unusual?
  • Are permissions changing unexpectedly?
  • Is sensitive data being accessed differently than normal?
  • Are signs of account takeover present?

This behavioral approach is becoming increasingly important in Microsoft 365 security strategies.

 

How Petra Security Supports BEC Detection

According to Petra Security's MSP program information, the platform focuses on identity-based threats within Microsoft 365 environments, including account compromise, suspicious user behavior, business email compromise, mailbox manipulation, and unauthorized access activity. Petra utilizes behavioral monitoring and response capabilities designed to help identify threats operating through legitimate credentials. 

The Sourcepass Petra Security program materials similarly describe Petra as a behavioral identity threat detection and response platform focused on monitoring for compromised accounts, suspicious sign-in activity, business email compromise indicators, and unauthorized account activity across Microsoft 365 environments. 

 

Reducing Business Email Compromise Risk

While no technology can eliminate risk entirely, organizations can significantly reduce exposure by combining preventive controls with behavioral monitoring.

 

Strengthen Identity Controls

Core Microsoft 365 security controls should include:

  • Multifactor authentication
  • Conditional Access
  • Least-privilege access
  • Privileged account management
  • Strong password policies

Microsoft identifies identity protection as a foundational component of cybersecurity resilience in cloud environments through guidance published by Microsoft Security.

 

Improve User Awareness

Employees remain one of the most important layers of defense.

Training should focus on:

  • Identifying social engineering attempts
  • Verifying financial requests
  • Reporting suspicious activity
  • Reviewing unexpected permission requests

The objective is behavior change, not simply compliance.

 

Monitor Identity Activity Continuously

Continuous monitoring helps identify suspicious activity that preventive controls may not stop.

Organizations with dedicated identity monitoring capabilities are often better positioned to:

  • Detect compromised accounts sooner
  • Reduce attacker dwell time
  • Investigate incidents more efficiently
  • Respond consistently across Microsoft 365 environments

 

Business Email Compromise Is Ultimately an Identity Security Problem

As organizations continue to operate in cloud-first environments, attackers increasingly target identities rather than infrastructure.

Business email compromise succeeds because attackers abuse trust. They leverage legitimate accounts, valid credentials, and familiar communication channels to blend into normal operations.

Protecting against these attacks requires more than email filtering. It requires visibility into how identities behave within Microsoft 365 and the ability to detect when trusted accounts begin exhibiting signs of compromise.

For modern organizations, strengthening identity security is one of the most practical ways to reduce business email compromise risk, improve incident response readiness, and support long-term operational resilience.

 

FAQ

What is business email compromise?

Business email compromise is a cyberattack in which attackers compromise or impersonate legitimate email accounts to manipulate employees, vendors, customers, or partners into performing actions such as transferring funds or sharing sensitive information.

How does business email compromise happen in Microsoft 365?

Business email compromise in Microsoft 365 commonly begins through credential phishing, session token theft, password reuse, or unauthorized application consent. After gaining access, attackers often monitor communications and impersonate trusted users.

Can multifactor authentication stop business email compromise?

Multifactor authentication significantly reduces risk and should be enabled for all users. However, attackers may still exploit stolen session tokens, compromised devices, social engineering techniques, or authorized application permissions. Additional identity monitoring remains important.

What are common signs of a compromised Microsoft 365 account?

Common indicators include unusual sign-in activity, unexpected mailbox forwarding rules, suspicious payment requests, unauthorized application permissions, abnormal file access patterns, and changes to account settings.

What is Identity Threat Detection and Response?

Identity Threat Detection and Response (ITDR) is a cybersecurity discipline focused on identifying, investigating, and responding to threats involving user identities and authenticated accounts. ITDR helps organizations detect account compromise and business email compromise activity that may be missed by traditional security tools.

How does Petra Security help detect business email compromise?

According to Petra Security's MSP information and Sourcepass program documentation, Petra focuses on behavioral identity threat detection within Microsoft 365 environments, helping identify suspicious account activity, business email compromise indicators, mailbox manipulation, and other identity-based threats.

Why is business email compromise considered an identity security issue?

Business email compromise relies on the misuse of trusted identities rather than malware. Because attackers use legitimate accounts and valid credentials, the attack is fundamentally an identity security challenge rather than a traditional endpoint or network security issue.