AzureTracks

Practical Azure and Microsoft 365 security walkthroughs

incident

  • Incident Response Foundations – Identity

    Incident Response Foundations – Identity

    In today’s post I talk about responding to a compromised identity in Microsoft Entra ID. There is a lot of advice floating around on what to do and how to respond; I’m bringing experiences and existing guidelines together to provide a solid foundational starting point for identity based incident response in this post.

    Read article

  • Responding to Incidents in Microsoft Sentinel

    Responding to Incidents in Microsoft Sentinel

    Join me to explore next steps once you have investigated an incident. Taking action to respond to the threat in Microsoft Sentinel provides excellent automated response capabilities that can be used to respond to threats in real-time. Let’s explore!

    Read article