How to search and destroy phishing emails on Microsoft Office 365

1- Go to Office 365 Security & Compliance


2- Open Search

- Search button

3- Search Phishing Emails based on the Query

- Sender address

- If the sender address is spoofed or multiple phishers exist, use keywords from the body text

4. Run the Windows PowerShell as the Administrator.

5. Connect to Office 365 PowerShell via 

$SccSession = New-PSSession -ConfigurationName Microsoft.Exchange -ConnectionUri -Credential $credential -Authentication "Basic" -AllowRedirection

Import-PSSession $SccSession -Prefix cc

*(Note: No worries about the warnings - you should use your admin email address with domain name)

6. Connect to Security & Compliance Center via 

$UserCredential = Get-Credential

$Session = New-PSSession -ConfigurationName Microsoft.Exchange -ConnectionUri -Credential $UserCredential -Authentication Basic –AllowRedirection

Import-PSSession $Session

7. Delete Emails that have been found on the Content Search with Search Name

New-ComplianceSearchAction -SearchName "THE_SEARCH_NAME" -Purge -PurgeType SoftDelete

8. Confirm Delete


9. See Status

Get-ComplianceSearchAction -Identity "THE_SEARCH_NAME_Purge"

*(Note that PowerShell adds “_Purge” to the Search Name, you should add it to search name to get status)

