← SC-200: investigation and security operations response
05 / 10 · 35 MIN

Identity, content, and handover

Distinguish evidence sources and communicate certainty.

Concept and mechanism

A risky sign-in guides investigation but does not alone prove attribution or compromise. Check signals, context, and remediation actions. When revoking access, consider tokens, continuous access evaluation support, and sessions maintained by the application. Do not promise that an identity-provider command instantly eliminates every session in every system. Record what was revoked, the confirmed effect, and what still needs resource-side action. In hybrid incidents, one person can have several identities and applications using different models. Use suitable identifiers and sources, avoiding display names as global keys or assuming all activity belongs to one actor.

Guided application

Purview Audit supports analysis of recorded activities; eDiscovery supports content search and review. Do not treat an event as a complete document backup. The current experience integrates Content Search into eDiscovery, with case permissions and scope to verify. If a Copilot summary goes beyond evidence, review references and correct the report before communicating it. A blocked attempt is neither automatically confirmed exfiltration nor proof that the entire incident ended. For international handover, write facts, hypotheses, completed actions, pending actions, owner, and next deadline. Keep source and retention limits visible so the next shift does not turn missing data into a definitive conclusion.

IN PRACTICE

“Attempt blocked; scope still under investigation” describes a different state from “confirmed exfiltration.”

Common pitfalls

Risk as guilt; revocation as universal instant effect; logs as documents; automated summary as proof.

Related topics: KQL for reasoning about events · Hunting, coverage, and continuity

Take this idea with you

The strength of the conclusion should follow the strength of the evidence.

Create account

Reference: Investigate incident cases · SC-200 objectives effective 2026-07-28; Microsoft product documentation reviewed 2026-10-01; 2026-10-21 English update compared separately