What to Do If You Clicked a Phishing Link (Microsoft 365)

Microsoft Defender logo

An office manager at a small business recently contacted us after clicking a download link in an email, only to realise the sender’s account had been hacked. She hadn’t entered her password on the page, but wanted to make sure her account and computer were safe. We ran a full security scan, reviewed sign-in and audit logs in Microsoft Entra, found no evidence of compromise, and reset her password as a precaution. This guide walks through exactly what to do if you or a staff member find yourself in the same situation.

Symptoms

You may need this guide if:

  • You clicked a link in an email that now looks suspicious
  • You realised the sender’s email account may have been hacked or spoofed
  • A link took you to a page asking for your Microsoft 365 login credentials
  • You downloaded a file from an unexpected or suspicious email
  • You entered your credentials on a page and now suspect it was a phishing site

“I clicked a link in an email and I think the sender’s account was hacked. I didn’t enter my password but I want to make sure I’m not compromised.”

Cause

Phishing emails are designed to trick users into clicking malicious links or downloading harmful files. These emails often come from legitimate contacts whose accounts have been compromised, making them harder to spot. Even if you did not enter your credentials, clicking a link can potentially expose your device to malware, tracking scripts, or browser-based exploits.

Immediate Steps (What You Should Do Right Now)

If you or a staff member has clicked a suspicious link, take the following steps immediately:

1. Disconnect from the Network (If You Downloaded a File)

If you downloaded a file from the suspicious link, disconnect your computer from Wi-Fi or unplug the ethernet cable. This prevents any potential malware from spreading across your network. If you only clicked a link and did not download anything, you can skip this step.

2. Do Not Enter Credentials on the Suspicious Page

If the link took you to a login page, close it immediately. Do not enter your username, password, or any other information. If you already entered your credentials, skip to step 4 immediately.

3. Run a Full Security Scan

  1. Open Windows Security on your computer
  2. Go to Virus & threat protection
  3. Click Scan options, then select Full scan
  4. Click Scan now and let it complete

If your organisation uses an endpoint protection tool like ThreatLocker or Microsoft Defender for Endpoint, notify your IT team so they can check for any flagged activity on your device.

4. Change Your Password Immediately

Even if you did not enter your credentials on the suspicious page, changing your password is a sensible precaution:

  1. Go to https://mysignins.microsoft.com/security-info
  2. Click Change password
  3. Choose a strong, unique password that you have not used before

5. Report the Email

  1. In Outlook, select the suspicious email
  2. Click the Report button in the ribbon (or right-click > Report > Report phishing)
  3. This sends the email to Microsoft for analysis and helps protect other users

How Your IT Team Investigates

When you report a potential phishing incident to your IT provider, here is what they will typically check:

Review Sign-in Logs in Microsoft Entra

Your IT team will check Microsoft Entra (formerly Azure AD) sign-in logs to look for:

  • Sign-ins from unfamiliar locations or IP addresses
  • Sign-ins from unknown devices or browsers
  • Failed sign-in attempts that could indicate someone trying your credentials
  • Any sign-ins that bypassed multi-factor authentication (MFA)

Review Audit Logs

Audit logs show account changes that could indicate compromise:

  • New inbox rules created (attackers often create rules to hide their activity)
  • Mail forwarding added to the account
  • Changes to MFA settings or authentication methods
  • New OAuth app consents

Check Endpoint Security

If your organisation uses Microsoft Defender for Endpoint, ThreatLocker, or a similar tool, your IT team will review:

  • Whether any malicious files were detected or quarantined
  • Whether the suspicious URL was blocked by web filtering
  • Any unusual processes or network connections from your device

Preventing Future Incidents

Take these steps to reduce the risk of phishing attacks across your organisation:

  • Enable multi-factor authentication (MFA) on all Microsoft 365 accounts. This is the single most effective defence against credential phishing.
  • Use a link protection service like Microsoft Defender for Office 365 Safe Links, which scans URLs in emails at the time of click.
  • Train staff regularly on how to spot phishing emails. Look for urgency, unexpected attachments, mismatched sender addresses, and unusual requests.
  • Deploy conditional access policies to block sign-ins from untrusted locations or non-compliant devices.
  • Enable security defaults or a Zero Trust posture in Microsoft Entra to enforce modern authentication across all apps.
  • Report suspicious emails using the built-in Report button in Outlook so Microsoft and your IT team can take action.

Important Notes

  • Even if no compromise is found, always reset the password as a precaution. It takes less than a minute and eliminates the risk of stolen credentials being used later.
  • If the user did enter credentials on a phishing page, treat it as a confirmed compromise. Reset the password, revoke all active sessions, review MFA methods, and check for inbox rules and mail forwarding immediately.
  • Encourage a no-blame culture around phishing reports. Staff who feel safe reporting incidents will report them faster, reducing the window for attackers.

If you think you may have been compromised, contact our team immediately.

Was this article helpful?
Ready to secure and simplify your IT? Talk to a GCIT expert today.