Watching for compromise.
WHAT TO MONITOR
Sign-in logs, including failures Audit logs of directory changes Risk detections Administrative role usage
WHAT SIGNALS WARRANT ATTENTION
Sign-in from unexpected locations Impossible travel between sign-ins Many failed attempts followed by a success Authentication method added or changed unexpectedly New applications granted access Administrative role assigned
WHAT TO DO ON SUSPECTED COMPROMISE
Block sign-in immediately Revoke active sessions and refresh tokens Reset the password Review and remove unexpected authentication methods Check for mailbox rules and forwarding Review what the account accessed
WHY REVOKING SESSIONS MATTERS
A password reset alone does not end existing sessions, and the attacker remains signed in.
WHAT TO CHECK BEYOND THE ACCOUNT
Whether applications were granted consent Whether other accounts were affected Whether anything was exfiltrated
WHAT TO RECORD
Times, actions taken, and what was found.
WHY TIMES
Notification obligations frequently run from when you became aware.
WHAT TO PREPARE IN ADVANCE
A written procedure, so nobody improvises during an incident.