Account Takeover (ATO)

Account Takeover (ATO) is the takeover of a legitimate user account by attackers. This is not only about stolen passwords, but about the misuse of a digital identity – including access to emails, cloud applications, sensitive data and internal communication. Especially in Microsoft 365 and SaaS environments, account takeover is particularly critical because a compromised account quickly becomes the starting point for data exfiltration, phishing from within the organization's own tenant or lateral movement.

Account takeover protection comprises measures for detecting, investigating and defending against compromised accounts. Modern approaches observe not only logins but also cloud activities, rule changes in the mailbox, location changes, suspicious usage patterns and signs of data exfiltration. This is important because multi-factor authentication alone does not exclude all risks. The aim is to detect suspicious login, session and behavioral patterns before an account compromise turns into a major security incident. Defending against account takeovers is thus a core use case of Identity Security.