Access is one part of the scope

An incident can leave changes beyond the original session. A useful review considers how access was used and whether anything added during that period could still matter.

Look at the connected changes

Microsoft’s compromised-account guidance includes sessions, authentication methods, application consent, administrative roles, forwarding, and inbox rules. These are connected parts of the investigation rather than interchangeable checks. Follow your organisation’s incident-response procedures when reviewing and remediating them.

Keep an account of the response

Record the evidence behind each finding, the action taken, and the questions that remain. This gives the next person reviewing the incident something more useful than a closed alert.

The Sentry perspective

Sentry connects automated remediation to incident scope, evidence, and response policy. A response should be understandable as well as timely.

Explore automated remediation