Task 04: Contain and remediate
Security Architecture Team
-
If malicious emails continue to arrive, you can:
- Go to Email and collaboration > Explorer.
- Filter by Subject, URL, or Sender address.
- Select an email on the table.
- Select Take action > Select Move or delete > Soft delete or Hard delete > Submit.
- Go to Investigation & response > Actions & submissions > Action center.
- Check Pending/History to validate remediation results.
-
If a device exhibits credential-theft behavior:
- Go to Assets > Devices, then select the device.
- Open the context menu (…) and select an action like Isolate device or Run antivirus scan.
- Validate the action’s success in Action center under Pending/History.
Security Engineering and Administration
General information for the Engineering team.
-
Isolate a device:
- Go to Assets > Devices, then select the device.
- Select the context menu (…) > Isolate device.
-
Quarantine a file:
- Go to Incidents & alerts > Incidents, then select the EICAR_Test_File incident.
- Select Evidence and response > File > Quarantine (or Undo quarantine).
-
Purge email for impacted recipients:
- Go to Email and collaboration > Explorer.
- Select the email message.
- Select Take action > Move or Delete.
-
Revoke OAuth app consents or disable an app:
- Go to Cloud Apps > Cloud App catalog.
- Select the app and select Sanction or Unsanction.
-
Safeguard affected users:
- Go to
entra.microsoft.com, select Users, then select the user. - Select Revoke sessions.
- Go to
SOC Analyst
General information for the SOC Analysts.
-
Queue and monitor actions:
- Go to Incidents, select the incident, then select Evidence and response.
- Select items (Device/File/Email/User/Cloud App) and queue necessary actions.
- Open Action center and verify Pending or History actions.
-
Add incident comments:
- In Manage incident, record the containment timeline. For example, “10:24 NZDT - VM fully isolated; 10:29 - email soft-deleted org-wide; residual: monitor OAuth app re-consent.”
-
Resolve the incident once all actions are complete.