What should I do if a cloud account may be compromised?¶
Treat suspected cloud-account compromise as an evidence problem and a containment problem at the same time.
A password reset may be necessary, but it is rarely enough on its own. Existing sessions, delegated applications, recovery changes, service accounts or administrator roles may survive it.
Capture the account state before changing it¶
Start by fixing the account, tenant, service and likely time range.
Then preserve the records that explain how control may have changed:
- sign-ins;
- active sessions and tokens;
- trusted devices;
- recovery and MFA changes;
- connected applications;
- API credentials;
- administrator or role changes;
- forwarding and sharing rules; and
- audit events around the suspected compromise.
A useful account snapshot might look like this:
dave@northstar.exampleActive sessions: 3New application consent: APP-441Recovery method added: 2026-09-18 07:52 UTCExternal forwarding rule: enabledThat snapshot gives you something to compare with the post-containment state.
Work out every route that may still provide access¶
Do not reduce compromise to “someone knows the password”.
Possible continuing routes include:
| Route | Why it matters |
|---|---|
| Existing browser session | May continue without another password entry |
| Refresh token | Can renew application access |
| Connected application | May act through delegated permission |
| Service account / API credential | May operate independently of the user's interactive login |
| New administrator | Can retain control even after the original password changes |
| Recovery method | Can help re-establish access later |
What signs may indicate cloud-account compromise? helps identify the pattern before containment.
Contain in a deliberate sequence¶
The exact controls depend on the provider and organisation, but the investigative sequence is stable:
A password reset, session revocation, application removal and key rotation do different jobs. Record them separately.
Verify containment rather than assuming it¶
After the change, ask:
- did the suspected session end;
- did the application lose access;
- did the forwarding or sharing rule disappear;
- were unauthorised roles removed;
- did new activity continue; and
- did another account or device route remain active?
How should I document cloud-account containment? covers the evidential record of those interventions.
The practical point is: contain the account by access route, not by ritual. Preserve the pre-change state, remove the relevant authority and prove what actually stopped.