What should I check after a cloud account has been secured?¶
After a cloud account has been secured, check whether unauthorised access, persistence or data movement continued through another route.
Evidential caution: that a successful password reset means the incident is finished.
What this means¶
Review active and historical sessions, token revocation, trusted devices, application consent, API keys, administrator roles, recovery settings and mailbox or file rules.
Continued events may indicate another session, token, application or account rather than a failed password reset.
Confirm whether “sign out everywhere” actually revoked all relevant sessions and applications.
Review sharing links, forwarding rules, external collaborators and deleted or altered security alerts.
Where data may have been accessed, identify the affected files, messages, mailboxes or resources and preserve the relevant audit trail.
Document the containment actions, exact times, systems affected and who performed them.
Where the incident involved several users or shared resources, verify that containment was not limited to one account. A compromised application, administrator or shared token may affect the wider tenant.
What to check or do next¶
- Check whether any suspicious applications or service accounts remain authorised.
- Look for activity after the containment time.
- Compare post-containment activity with the expected behaviour of synchronisation, automation and security tools.
- Do not remove all configuration without preserving the audit evidence needed to explain what happened.
Evidential limits¶
Set a defined monitoring period after containment where proportionate. Some surviving tokens or automated rules may not generate activity immediately and can be missed by a single follow-up check.
Operational takeaway
After securing the account, verify sessions, tokens, applications, roles and rules, and check for continued activity that may reveal surviving access or persistence.