-rest user password for log in and O365
-sign user out of all active sessions
-log onto users machine
-check event viewer - check logs in security for 4625 / 4697 / 7045 / netlogon errors / antivirus
-check to see if any services were created - #service name or made up of numbers
-check file path -c>users>administrator>appdata>Roaming>Microsoft>Windows look for powershell command folder
-check Outlook desktop app and OWA for any erroneous rules create
-run Antvirus scan