What should I check after a cloud account has been secured?¶
Verify that unauthorised access and automated effects ended across every relevant route. A successful password reset or “sign out everywhere” message does not by itself show that tokens, applications, keys, rules and linked accounts were contained.
Audit the remaining authority¶
Review active and historical sessions, token revocation, trusted devices, connected applications, API keys, service accounts, administrator roles, recovery methods, forwarding rules, sharing links and external collaborators.
Where several users or resources were affected, check the wider tenant. A compromised administrator, tenant-wide application or shared credential may survive containment of one user account.
Examine activity after the control point¶
Create a precise containment timestamp and look for later events. Continued activity may arise from another session or account, a surviving token, delayed synchronisation, automation or security processing. Establish the mechanism rather than assuming the reset failed.
Identify files, messages and other resources accessed or changed, and preserve their audit history. Keep pre-containment configuration evidence before removing remaining footholds.
Set a proportionate monitoring period: dormant tokens or scheduled rules may not generate an immediate event. Document each containment action, the systems it was expected to affect and the observed result.
The point to remember
After securing an account, verify every session, token, application, role and rule, then test post-containment activity for surviving or delayed access.