How should I document cloud-account containment?¶
Document cloud-account containment so that another investigator can understand the original state, the actions taken and their effect on the evidence.
Evidential caution: that the technical team’s incident ticket will contain everything needed for the investigation.
What this means¶
For each action, record who authorised it, who performed it, the exact time and the control used.
Distinguish password reset, session revocation, token revocation, application removal, account disablement and role removal.
Document later checks for continued access and any additional actions taken.
What to check or do next¶
- Record the provider, service, tenant, account, date, time zone and reason for containment.
- Capture the account state before action where operationally possible.
- Record active sessions, tokens, trusted devices, connected applications, roles, forwarding or sharing rules and recovery methods.
- Record what the provider or administrator stated each action would do and what was actually observed.
- Preserve screenshots, exports, event IDs, audit records and incident-response notes.
- Identify any unavoidable gaps where containment took priority over preservation.
- Do not rewrite the original state after the fact. Keep the pre-containment evidence separate from the post-containment environment.
- Record any provider messages, error codes or delays encountered during containment. These may explain why access continued briefly after an action was requested or why one control did not affect another application.
Evidential limits¶
Where several teams act at once, maintain one coordinated timeline. Separate technical tickets can otherwise produce conflicting times, duplicate actions and uncertainty about which control caused the observed change.
Operational takeaway
Document containment as a timed sequence of account state, authorised actions and observed effects so that evidential changes and surviving access routes can be explained.