Memory hook: Follow the identity across email, devices, apps and cloud.
Must remember
Triage severity, confidence, affected assets and business impact. An incident groups related alerts; investigate its attack story and entities rather than treating every alert as unrelated. Assign an owner, track hypotheses, preserve evidence and record decisions in incident/case management.
Defender for Office 365 provides email/collaboration threat evidence and remediation capabilities. Trace message delivery, clicks and related sign-ins before deciding the scope. Defender for Identity adds on-premises identity signals; Entra sign-in/risk evidence adds cloud identity context. Password reset, session revocation and device containment solve different parts of account compromise.
Defender for Cloud Apps helps investigate application activity and risky sessions; Defender for Cloud workload protections surface threats affecting protected cloud resources. Purview alerts can indicate risky data handling. Correlate the same user, device, app and time window across sources, then validate that similarly named entities really are the same identity.
Purview Audit records supported activities for investigation. eDiscovery Content search finds relevant content under its permissions and scope; it is not the same as querying activity logs. Microsoft Graph activity logs describe Graph API request activity when configured. Use the correct evidence source for the question and preserve timestamps/time zones.
Contain first when impact demands it, then eradicate and recover under the incident plan. Track lateral movement, persistence and exfiltration, not just initial access. Confirm actions succeeded and measure residual risk. Escalate legal, privacy and business decisions to the appropriate owners; an analyst should not invent a notification deadline from technical evidence alone.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Who accessed or changed an item? | Relevant audit/activity evidence. |
| Find communications/content in scope | Authorized eDiscovery search. |
| Compromised user remains active after password reset | Investigate sessions/tokens and other persistence; apply appropriate revocation/containment. |
Traps
- Content search and activity audit answer different questions.
- Matching a display name is weaker than matching stable entity identifiers.
Active recall
1. Why work at incident level?
To connect related alerts into a coherent attack and coordinated response.
2. Why correlate cloud and on-prem identity signals?
The same compromise can cross both environments.
3. What does Graph activity evidence add?
Visibility into configured Microsoft Graph API request activity.
4. Why verify remediation actions?
A requested action can fail, be pending or cover only part of the attack.
5. What should case notes preserve?
Evidence, timing, affected entities, hypotheses, decisions, actions and ownership.