Microsoft 365 Incident Response Checklist: What To Do During the First 60 Minutes
top of page
Search

Microsoft 365 Incident Response Checklist: What To Do During the First 60 Minutes

  • Hanna Korotka
  • 30 minutes ago
  • 3 min read
Microsoft 365 Incident Response Checklist

Cyberattacks rarely happen at a convenient time. Whether it's a compromised user account, a phishing attack, suspicious sign-in activity, or malware, the first hour is often the most important.


Taking the right actions quickly can limit damage, prevent attackers from moving further through your environment, and preserve the evidence needed for a proper investigation.


This Microsoft 365 Incident Response Checklist outlines the immediate steps recommended by Microsoft and commonly followed by security teams when responding to a Microsoft 365 security incident.


1. Confirm That the Incident Is Real


Before making changes, determine whether you're dealing with an actual security incident or a false positive.


Useful places to start include:

  • Microsoft Defender XDR Incidents

  • Microsoft Defender for Office 365 alerts

  • Microsoft Entra sign-in logs

  • Microsoft Entra risky users and risky sign-ins

  • Microsoft Purview Audit


Collect basic information such as:

  • Which user or device is affected?

  • What alert was triggered?

  • When did the activity begin?

  • Is the activity still ongoing?


Avoid making assumptions until you have enough information.


2. Contain the Threat Immediately


Once malicious activity is confirmed, the priority is preventing further damage.


Depending on the situation, Microsoft recommends actions such as:

  • Block the user's sign-in

  • Disable the compromised account if necessary

  • Revoke active refresh tokens and user sessions

  • Isolate affected devices using Microsoft Defender for Endpoint

  • Block malicious email messages or URLs if they are part of a phishing campaign


The goal is to stop the attacker from maintaining access while minimizing disruption to legitimate users.


3. Preserve Evidence Before Making Major Changes


Many organizations immediately delete emails or remove accounts. While understandable, doing so can make later investigation much more difficult.


Instead, preserve available evidence, including:

  • Sign-in logs

  • Audit logs

  • Security alerts

  • Email headers

  • Device alerts

  • Timeline of events


These records help determine exactly what happened and may be required for compliance or insurance purposes.


4. Determine the Scope of the Incident


The next step is understanding how far the incident has spread.


Ask questions such as:

  • Was only one account affected?

  • Were additional users targeted?

  • Were multiple devices involved?

  • Was sensitive information accessed?

  • Were emails sent from the compromised account?

  • Were mailbox forwarding rules created?

  • Were new administrators added?


Understanding the full scope helps determine the appropriate remediation steps.


5. Look for Signs of Persistence


Simply resetting a password may not completely remove an attacker from your environment.


Check for persistence mechanisms such as:

  • Suspicious mailbox forwarding rules

  • Unexpected inbox rules

  • Unauthorized app consent

  • Newly registered authentication methods

  • Unexpected administrator role assignments


These are common ways attackers attempt to regain access after credentials are changed.


6. Remove the Threat


After identifying the attacker's activity, begin remediation.


Common actions include:

  • Reset the user's password

  • Require new multifactor authentication registration if needed

  • Remove malicious mailbox rules

  • Remove unauthorized application permissions

  • Delete malicious emails using Microsoft Defender where appropriate

  • Remove unauthorized administrator roles

  • Update Conditional Access policies if gaps were identified


Only remove items after you've documented the evidence.


7. Verify That the Environment Is Secure


Once remediation is complete, verify that no malicious activity continues.


Review:

  • New sign-in activity

  • Defender incidents

  • Audit logs

  • User activity

  • Device health

  • Email activity


Continue monitoring closely over the next several days for recurring activity.


8. Document What Happened


Every incident should end with documentation.


Record:

  • Timeline of events

  • Root cause

  • Affected users

  • Systems involved

  • Actions taken

  • Lessons learned

  • Security improvements to implement


A well-documented incident helps improve future response and reduces recovery time.


Common Mistakes During Incident Response


Many organizations unintentionally make the situation worse by:

  • Resetting passwords before collecting evidence

  • Ignoring mailbox rules and forwarding settings

  • Focusing only on one affected user

  • Forgetting to revoke active sessions

  • Not reviewing audit logs

  • Closing the incident before monitoring for recurrence


Avoiding these mistakes can significantly improve the effectiveness of your response.


Be Prepared Before an Incident Happens


An effective response starts long before the first alert.


Organizations should regularly review:

  • Conditional Access policies

  • Multifactor authentication coverage

  • Administrator permissions

  • Audit logging configuration

  • Microsoft Defender alerting

  • Incident response procedures


Having these controls in place makes responding to an incident faster and more effective.


How We Can Help


Responding to a Microsoft 365 security incident requires quick action and a structured process. Our team helps organizations investigate incidents, contain threats, analyze audit logs, review Microsoft Defender alerts, identify the root cause, and strengthen Microsoft 365 security to reduce the risk of future attacks.


If you'd like to improve your Microsoft 365 security posture or prepare an incident response plan, we're here to help.



 
 
 

Get the Latest News to Your Inbox

bottom of page