← SC-200: investigation and security operations response
09 / 10 · 50 MIN

Investigating across Microsoft services

Connect identity, email, applications, and resources in an investigation with verifiable actions.

Case management and shift continuity

Incident cases, in preview, bring together alerts, assets, evidence, and activities. Set an owner, priority, tasks, and deadline; describe what the next shift must confirm. Security Data Read permits viewing, while managing the case requires the corresponding management permission; response actions have additional requirements. Resolving a case synchronizes the related incident’s state but does not automatically resolve every alert. A closed status without demonstrated remediation creates a false impression of safety. In closing notes, connect conclusions to evidence, completed actions, and residual risks handled through the applicable process.

Email and sensitive data

In Defender for Office 365, investigate recipients, delivery, clicks, and actions taken. Removing a delivered message may be necessary but does not undo executed code or compromised sessions. Distinguish proposed action, approval, and result. For Purview DLP alerts, examine policy, activity, and evidence with appropriate content access. A blocked sharing attempt differs from a completed transfer. Correlate user, file, and device without distributing sensitive content to every participant. At handover, identify which surfaces were addressed and which still require investigation.

Cloud applications, workloads, and hybrid identity

Defender for Cloud provides threat context for protected workloads; changing alert status does not repair the resource. Defender for Cloud Apps connects application activity with governance actions available for each connector. Confirm permissions and action results: suspending a synchronized identity may be reversed by its on-premises source. Defender for Identity relies on sensors, auditing, and action accounts to act in AD. Connect signal timelines through stable identifiers. A same-named account in another tenant is not automatically the same entity. Coordinate with owners so operational automation does not reactivate an account contained during the incident.

Microsoft Graph requests as evidence

MicrosoftGraphActivityLogs records HTTP requests processed by Graph in the tenant when collection is configured. It differs from using the Graph API to retrieve sign-in logs. Connect AppId, ServicePrincipalId, or UserId with RequestMethod, RequestUri, ResponseStatusCode, and time. A 403 response indicates that request was denied; it does not demonstrate that all requests failed. A successful response also needs context to assess misuse. Consider delivery delay and tenant scope. In an example with seven denied requests and one successful request, investigate the successful request and its identity without counting eight exfiltrations or declaring the activity harmless.

Automatic containment and assisted investigation

Automatic attack disruption uses correlated signals and depends on deployed products and prerequisites. Do not promise universal containment merely because a license exists. In particular, a device group’s Semi level does not mean every attack-disruption containment action awaits manual approval. Confirm actions and dependencies in the Action center. Copilot can summarize evidence and assist investigation; analysts still verify sources, chronology, and limits. Agentic playbook sessions associated with cases depend on access to the documented capability, including Project Perception. Agent output is not proof that a remote action completed.

IN PRACTICE

A suspicious email, an OAuth application, and a batch server appear in one fictional investigation. Reporting distinguishes requested action, confirmed effect, and still-unknown scope.

Common pitfalls

Closing a case as remediation; 403 as exfiltration; summary as proof; read access as response authorization.

Related topics: Hunting with the lake, graphs, and notebooks · SOC collection and permissions

Take this idea with you

Maintain a shared timeline and confirm service-specific effects before declaring recovery.

Create account

Reference: Manage incident cases · SC-200 objectives effective 2026-07-28; Microsoft product documentation reviewed 2026-10-01; 2026-10-21 English update compared separately