Concept and mechanism
A risky sign-in guides investigation but does not alone prove attribution or compromise. Check signals, context, and remediation actions. When revoking access, consider tokens, continuous access evaluation support, and sessions maintained by the application. Do not promise that an identity-provider command instantly eliminates every session in every system. Record what was revoked, the confirmed effect, and what still needs resource-side action. In hybrid incidents, one person can have several identities and applications using different models. Use suitable identifiers and sources, avoiding display names as global keys or assuming all activity belongs to one actor.
Guided application
Purview Audit supports analysis of recorded activities; eDiscovery supports content search and review. Do not treat an event as a complete document backup. The current experience integrates Content Search into eDiscovery, with case permissions and scope to verify. If a Copilot summary goes beyond evidence, review references and correct the report before communicating it. A blocked attempt is neither automatically confirmed exfiltration nor proof that the entire incident ended. For international handover, write facts, hypotheses, completed actions, pending actions, owner, and next deadline. Keep source and retention limits visible so the next shift does not turn missing data into a definitive conclusion.
“Attempt blocked; scope still under investigation” describes a different state from “confirmed exfiltration.”
Common pitfalls
Risk as guilt; revocation as universal instant effect; logs as documents; automated summary as proof.
Related topics: KQL for reasoning about events · Hunting, coverage, and continuity
The strength of the conclusion should follow the strength of the evidence.
Reference: Investigate incident cases · SC-200 objectives effective 2026-07-28; Microsoft product documentation reviewed 2026-10-01; 2026-10-21 English update compared separately