Skip to main content
IT KORR
IT KORRKeeping Organizations Reliable & Resilient

Microsoft 365 Security · Resource

Microsoft Security Operations Playbook

A playbook of specific response actions for common Microsoft 365 security incident scenarios.

IT KORR Knowledge Center

Microsoft Security Operations Playbook

A playbook of specific response actions for common Microsoft 365 security incident scenarios.

Scenario: Compromised User Account

  • Disable sign-in immediately.
  • Revoke all active session tokens.
  • Require password reset with identity verification.
  • Review mailbox rules and forwarding for persistence mechanisms.

Scenario: Compromised Device

  • Isolate the device via Defender for Endpoint.
  • Review Defender XDR incident for related indicators on other devices.
  • Preserve forensic state before remediation.

Scenario: Phishing Campaign in Progress

  • Purge the malicious message across all reached mailboxes.
  • Block the sender domain.
  • Identify and remediate any users who interacted with the message.

Related Resources

  • Microsoft 365 Incident Response — /knowledge-center/cloud-productivity/microsoft-365-security/microsoft-365-incident-response

This document is a starting-point resource, not legal or compliance advice. Review it against your organization's actual systems before adoption — see the full Microsoft 365 Security & Entra ID Hub for the reasoning behind each recommendation, or browse the full Resource Library.

Microsoft 365 Security & Entra ID

Need This Configured and Governed Across Your Tenant?

A checklist documents the target state — IT KORR can assess your current tenant configuration, implement the identity and security controls, and maintain the governance that keeps them from drifting.

No commitment required — we respond within one business day, or call (848) 200-9669 now.

Build: 4fb1bc8 | Built: Oct 6, 2026 8:27 PM EDT