So we had an incident where we had to disable all ability for a user to get into any Office365 services and disable any sending/receiving of email. But the account needed to stay active for a while.
So I changed the password on the account Monday at 4:30pm. On Tuesday afternoon they were still sending email to employees. It appears all emails were coming from an android phone.
What gives? Shouldn't the phone ask them to enter a new password? Why are they still able to send email.
Because of this I went into Office365, gave myself full access to the account, disabled sign-on in the users section, deleted their phone from the accepted devices list, disabled ActiveSync, and disabled OWA. Hopefully that works. I didn't expect this to happen. I get that there can be a period of time where they might still have access, but it was basically 24...