Microsoft Defender XDR
Identity protection

Sop Documentation Template

In brief

The template was revised with clearer wording and added guidance for prerequisites, user validation, containment, MFA review, impact assessment, remediation, recovery, and prevention of recurrence.

What Defender admins need to know

Administrators using the template have more complete guidance for structuring and responding to compromised identity incidents.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

[!INCLUDE Microsoft Defender XDR rebranding]

Use this articleSOP template to create a reusable standard operating procedure (SOP) for compromised identity incidents. Replace each placeholder with organization-specific values before you publish or upload the SOP.

Prerequisites

Before you customize or publish this SOP, confirm the following prerequisites:

  • Confirm who owns the SOP and who can approve changes for your organization.
  • Verify that your analysts can access the SigninLogs data and any other sources that your SOP references.
  • If you plan to upload the SOP as a guidebook, review the supported file types, size limits, and permission requirements in Customize incident responses for your organization.

SOP metadata

Use this section to identifyRecord the SOP owner, scope, and data sources.sources in the following metadata fields.

  • Name: <Compromised identity incident response SOP>
  • Version: <v1.0>

Purpose

Use thisthe compromised identity incident response SOP to triage, contain, investigate, remediate, and prevent incidents that indicate a compromised identity. Customize the scope, decision points, and escalation paths so that analysts can respond consistently during incidents that affect <User>, <Group>, or <Business unit>.

Triggers (when to invoke this SOP)

Invoke thisthe compromised identity incident response SOP when an incident, alert, or user report suggests that an identity might be compromised.

  • Alert examples include Impossible travel, Unfamiliar sign-in properties, Password spray, MFA fatigue, and Suspicious inbox forwarding rules.
  • Use thisInvoke the compromised identity incident response SOP when <User> reports unexpected MFA prompts, suspicious sign-in notifications, or account changes they didn't make.
  • Use thisInvoke the compromised identity incident response SOP when analysts observe successful sign-ins from unusual locations, risky IP addresses, or unfamiliar applications.

Triage phase

Validate with the user

Validate the suspicious activity directly with the affected user before you decide on next actions.

  1. Contact <User> through an approved channel.
  2. Ask whether they recognize the sign-ins, locations, devices, applications, and MFA prompts.
  3. Ask whether they recently approved an MFA request, entered credentials into a prompt, shared a device, or traveled.

Contain the identity

Use the following actions to contain the compromised identity while preserving evidence and minimizing business disruption.

  1. Revoke active sessions and refresh tokens for <[email protected]>.
  2. Force a password reset or secret rotation, based on the identity type.
  3. Disable the account temporarily if risk remains active and business approval allows it.

Investigation phase

Use thisthe investigation phase to identify the likely entry point, validate control gaps, and define the blast radius.

Perform root cause analysis

Evaluate MFA

Review MFA status and behavior to determine whether authentication controls failed or were bypassed.

  1. Determine whether MFA was enabled for <[email protected]> at the time of the incident.
  2. Check whether the attacker satisfied MFA, bypassed MFA, or enrolled a new authentication method.
  3. Identify gaps in Conditional Access, authentication strengths, token protection, or registration controls.

Analyze blast radius and impact

Assess the scope of access and potential business impact before closing the investigation.

  1. Review incident evidence for access to email, files, collaboration tools, cloud resources, or privileged roles.
  2. Check for suspicious inbox rules, forwarding rules, consent grants, mailbox access, lateral movement, or privilege escalation.
  3. Identify related accounts, devices, applications, and workloads that the compromised identity accessed.

Complete the actions that remove attacker persistence and return the identity to a trusted state.

Remediate and recover

  1. Reset the password, rotate secrets, and require fresh sign-in for all active sessions.
  2. Remove malicious inbox rules, forwarding rules, OAuth app consent, or unauthorized authentication methods.
  3. Restore approved MFA settings and re-register authentication methods if required.

Use lessons from the incident to reduce the likelihood of recurrence.

Prevent recurrence

  1. Enforce phishing-resistant MFA, stronger Conditional Access policies, and sign-in risk controls where available.
  2. Disable legacy authentication and remove unused service accounts, applications, or credentials.
  3. Improve detections for unusual sign-ins, MFA abuse, token abuse, impossible travel, and consent activity.