Microsoft 365 Incident Response Checklist: What To Do During the First 60 Minutes
- Hanna Korotka
- 30 minutes ago
- 3 min read

Cyberattacks rarely happen at a convenient time. Whether it's a compromised user account, a phishing attack, suspicious sign-in activity, or malware, the first hour is often the most important.
Taking the right actions quickly can limit damage, prevent attackers from moving further through your environment, and preserve the evidence needed for a proper investigation.
This Microsoft 365 Incident Response Checklist outlines the immediate steps recommended by Microsoft and commonly followed by security teams when responding to a Microsoft 365 security incident.
1. Confirm That the Incident Is Real
Before making changes, determine whether you're dealing with an actual security incident or a false positive.
Useful places to start include:
Microsoft Defender XDR Incidents
Microsoft Defender for Office 365 alerts
Microsoft Entra sign-in logs
Microsoft Entra risky users and risky sign-ins
Microsoft Purview Audit
Collect basic information such as:
Which user or device is affected?
What alert was triggered?
When did the activity begin?
Is the activity still ongoing?
Avoid making assumptions until you have enough information.
2. Contain the Threat Immediately
Once malicious activity is confirmed, the priority is preventing further damage.
Depending on the situation, Microsoft recommends actions such as:
Block the user's sign-in
Disable the compromised account if necessary
Revoke active refresh tokens and user sessions
Isolate affected devices using Microsoft Defender for Endpoint
Block malicious email messages or URLs if they are part of a phishing campaign
The goal is to stop the attacker from maintaining access while minimizing disruption to legitimate users.
3. Preserve Evidence Before Making Major Changes
Many organizations immediately delete emails or remove accounts. While understandable, doing so can make later investigation much more difficult.
Instead, preserve available evidence, including:
Sign-in logs
Audit logs
Security alerts
Email headers
Device alerts
Timeline of events
These records help determine exactly what happened and may be required for compliance or insurance purposes.
4. Determine the Scope of the Incident
The next step is understanding how far the incident has spread.
Ask questions such as:
Was only one account affected?
Were additional users targeted?
Were multiple devices involved?
Was sensitive information accessed?
Were emails sent from the compromised account?
Were mailbox forwarding rules created?
Were new administrators added?
Understanding the full scope helps determine the appropriate remediation steps.
5. Look for Signs of Persistence
Simply resetting a password may not completely remove an attacker from your environment.
Check for persistence mechanisms such as:
Suspicious mailbox forwarding rules
Unexpected inbox rules
Unauthorized app consent
Newly registered authentication methods
Unexpected administrator role assignments
These are common ways attackers attempt to regain access after credentials are changed.
6. Remove the Threat
After identifying the attacker's activity, begin remediation.
Common actions include:
Reset the user's password
Require new multifactor authentication registration if needed
Remove malicious mailbox rules
Remove unauthorized application permissions
Delete malicious emails using Microsoft Defender where appropriate
Remove unauthorized administrator roles
Update Conditional Access policies if gaps were identified
Only remove items after you've documented the evidence.
7. Verify That the Environment Is Secure
Once remediation is complete, verify that no malicious activity continues.
Review:
New sign-in activity
Defender incidents
Audit logs
User activity
Device health
Email activity
Continue monitoring closely over the next several days for recurring activity.
8. Document What Happened
Every incident should end with documentation.
Record:
Timeline of events
Root cause
Affected users
Systems involved
Actions taken
Lessons learned
Security improvements to implement
A well-documented incident helps improve future response and reduces recovery time.
Common Mistakes During Incident Response
Many organizations unintentionally make the situation worse by:
Resetting passwords before collecting evidence
Ignoring mailbox rules and forwarding settings
Focusing only on one affected user
Forgetting to revoke active sessions
Not reviewing audit logs
Closing the incident before monitoring for recurrence
Avoiding these mistakes can significantly improve the effectiveness of your response.
Be Prepared Before an Incident Happens
An effective response starts long before the first alert.
Organizations should regularly review:
Conditional Access policies
Multifactor authentication coverage
Administrator permissions
Audit logging configuration
Microsoft Defender alerting
Incident response procedures
Having these controls in place makes responding to an incident faster and more effective.
How We Can Help
Responding to a Microsoft 365 security incident requires quick action and a structured process. Our team helps organizations investigate incidents, contain threats, analyze audit logs, review Microsoft Defender alerts, identify the root cause, and strengthen Microsoft 365 security to reduce the risk of future attacks.
If you'd like to improve your Microsoft 365 security posture or prepare an incident response plan, we're here to help.

