Last updated: April 29, 2026
Module 7 (Blue Team) covered IR generally. This is the Azure-specific actions.
Compromised account playbook
- Disable user account in Entra ID
- Revoke active sessions and refresh tokens (
Revoke-AzureADUserAllRefreshToken) - Reset password
- Review AD audit logs for the user (last 30 days)
- Check for created service principals or app registrations
- Review M365 mailbox forwarding rules
- Review consent grants
- Re-enable with new MFA after investigation
Custom team training + practitioner advisory
Beyond the free academy — we run private workshops, vCISO advisory, and red-team exercises tailored to your stack. For Indian SMBs scaling past their first hire.