Knowledgebase

Monitoring Identity and Responding to Incidents Print

  • microsofttechnology, microsoft, hacked, password, email, guide, howto, solution
  • 0

Watching for compromise.

WHAT TO MONITOR

Sign-in logs, including failures Audit logs of directory changes Risk detections Administrative role usage

WHAT SIGNALS WARRANT ATTENTION

Sign-in from unexpected locations Impossible travel between sign-ins Many failed attempts followed by a success Authentication method added or changed unexpectedly New applications granted access Administrative role assigned

WHAT TO DO ON SUSPECTED COMPROMISE

Block sign-in immediately Revoke active sessions and refresh tokens Reset the password Review and remove unexpected authentication methods Check for mailbox rules and forwarding Review what the account accessed

WHY REVOKING SESSIONS MATTERS

A password reset alone does not end existing sessions, and the attacker remains signed in.

WHAT TO CHECK BEYOND THE ACCOUNT

Whether applications were granted consent Whether other accounts were affected Whether anything was exfiltrated

WHAT TO RECORD

Times, actions taken, and what was found.

WHY TIMES

Notification obligations frequently run from when you became aware.

WHAT TO PREPARE IN ADVANCE

A written procedure, so nobody improvises during an incident.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot