Beyond the Inbox: How BEC Leads to SSO Abuse
For years, many business email compromise (BEC) investigations have followed a familiar playbook: an attacker phishes credentials, logs into the victim's mailbox, establishes persistence with inbox rules, monitors communications, and waits for an opportunity to steal money or sensitive information.
Today, we're seeing something different at LevelBlue.
Across multiple recent investigations, we've observed attackers treating a compromised mailbox as just the first step. Rather than stopping at email, threat actors are immediately leveraging the victim's Microsoft 365 identity to access applications connected through Single Sign-On (SSO), including platforms like Salesforce and other third-party SaaS services.
This isn't just mailbox compromise anymore, it's identity compromise.
The identity is more valuable than the mailbox
Modern organizations rely on Microsoft Entra ID (formerly Azure AD) or similar identity providers to authenticate users across dozens or even hundreds of cloud applications.
Once an attacker successfully authenticates as a user, that same identity often provides seamless access to:
- CRM platforms such as Salesforce
- HR systems
- Financial applications
- Internal knowledge bases
- Collaboration platforms
- Customer support portals
- Other federated SaaS applications
By compromising a user’s identity in Microsoft 365, an attacker can leverage that identity to potentially access all apps connected to the SSO. Microsoft Entra ID, like other modern identity providers, offers a centralized portal where users can access applications and resources assigned to them. For a compromised identity, Microsoft My Apps serves as a convenient launchpad, enabling attackers to quickly discover connected applications to expand their access.
Figure 1. Microsoft My Apps Example. Identifying information has been anonymized.
In several recent investigations, we observed threat actors compromising Microsoft 365 credentials and then quickly pivoting into federated applications using the victim's existing SSO relationship.
In many cases, there was no need to steal additional passwords.
The Microsoft identity became the master key.
Threat actors leveraging a compromised mailbox to access third-party services is not new. Historically, attackers have used access to a victim's email account to initiate password resets, retrieve authentication links or tokens, and gain control of other accounts associated with the victim's email address. The widespread adoption of SSO has made this pivot even more direct. Rather than resetting credentials or waiting for access emails, an attacker who controls a federated identity may be able to authenticate directly to connected applications using the victim's existing SSO session or credentials.
LevelBlue has also observed threat actors searching compromised mailboxes for emails associated with third-party platforms, including access links, authentication tokens, and other information that could facilitate access to additional services (Figures 2 and 3).
Figure 2. Example of a Salesforce identity verification email containing a one-time verification code that could be leveraged to facilitate access to a third-party account. Identifying information has been anonymized.
Threat actors may also establish additional methods of access after pivoting to a third-party platform. For example, API tokens can provide authenticated access to application resources without requiring the attacker to repeatedly interact with the victim's mailbox or traditional user authentication workflow.
LevelBlue Email Security eliminates threats before they breach your security.

Figure 3. Example of an email notification indicating the creation of an API token for a third-party SaaS platform. Identifying information has been anonymized.
These examples highlight an important consideration during BEC investigations: access to the mailbox may provide opportunities to pivot into additional services, while access obtained within those services may enable the threat actor to establish additional authentication mechanisms and expand the scope of the compromise.
Why this matters
Traditional BEC investigations often focus on answering questions like:
- Was email accessed?
- Were inbox rules created?
- Were messages sent?
- Was sensitive mail stolen?
Those questions are still important.
But investigators increasingly need to ask a different question: What else did this identity have access to?
A compromised mailbox may simply be the visible symptom of a much broader compromise.
For example, the screenshot below illustrates how activity associated with a compromised Microsoft 365 identity may appear within available audit logs. Following a successful compromise, a threat actor may leverage the victim’s identity to access data stored across SharePoint, OneDrive, and other connected services. In this example, Microsoft 365 Unified Audit Log (UAL) activity shows file download events performed through the Microsoft Graph API, demonstrating how a compromise can extend beyond the mailbox and facilitate access to organizational data.
Figure 4. Example of M365 UAL activity illustrating file downloads performed through Microsoft Graph API. Identifying information has been anonymized.
When reviewing this type of activity, investigators should consider the application IDs associated with the events. In addition to the Microsoft Graph application ID shown in Image 4, LevelBlue has also observed application ID d326c1ce-6cc6-4de2-bebc-4591e5e13ef0 associated with SharePoint activity.
A successful Microsoft 365 sign-in could provide access to:
- Customer records
- Sales forecasts
- Contract information
- Personally identifiable information (PII)
- Internal documentation
- Business intelligence
- Intellectual property
Without ever needing another phishing email.
From an adversary perspective, connected applications are not simply destinations, but opportunities. During investigations, LevelBlue has observed attackers searching Microsoft and affiliated applications for additional credentials or access mechanisms that could allow them to pivot from SSO to other accounts, storage locations, and services.
Why we're seeing more of this
Attackers are adapting to modern enterprise environments.
Organizations have spent years strengthening email security with:
- Multi-factor authentication
- Conditional Access
- Email security gateways
- User awareness training
Rather than focusing solely on the mailbox, threat actors are increasingly taking advantage of the fact that organizations have centralized authentication.
One successful identity can unlock an entire ecosystem of connected services.
From an attacker's perspective, this is efficient.
Instead of stealing credentials for five separate applications, they only need one.
What to look for in a DFIR investigation
When responding to a suspected BEC, investigators should expand the scope beyond Exchange Online.
Some questions worth asking include:
- Which applications are federated with the compromised identity?
- Were new SaaS applications accessed immediately after the Microsoft sign-in?
- Are there unusual logins into Salesforce, ServiceNow, Workday, Box, or other third-party services?
- Do those applications maintain independent audit logs?
- Was data viewed, exported, or downloaded?
- Did the attacker create API tokens or OAuth connections inside those applications?
- Do sessions in connected applications can or need to be terminated independently?
The investigation shouldn't stop once mailbox activity has been reviewed.
Recommendations for organizations
Organizations should consider treating Microsoft identities as enterprise identities rather than simply email accounts.
Some practical steps include:
- Maintain an inventory of applications using SSO.
- Ensure critical SaaS platforms generate and retain audit logs.
- Review sign-in activity across connected applications during incident response.
- Apply Conditional Access consistently across federated applications where possible.
- Regularly review SSO integrations and remove unused applications.
Understanding what an identity can access is just as important as understanding the mailbox itself.
Final thoughts
One trend doesn't establish a long-term pattern, but seeing this behavior repeatedly across unrelated investigations suggests attackers recognize the value of cloud identities beyond email. For defenders and incident responders, that means a successful Microsoft 365 compromise should no longer trigger only a mailbox investigation, this should trigger an identity investigation, because once an attacker owns the identity, the inbox may be only the beginning of the Path of Intrusion.

Figure 5. What is the path of an email intrusion?
ABOUT LEVELBLUE
LevelBlue secures what's next with intelligence-led security delivering visibility and speed to stop threats faster. As the world’s largest and most analyst-recognized pure-play managed security services provider, our AI-powered managed services and cyber expertise across managed, advisory, and incident response services help clients operate with confidence. Learn more about us.