Skip to content
Skip to main content
Cloud Services Operational Explainer

How should I document cloud-account containment?

Document containment as a timed change from one known account state to another.

The point is to let somebody later explain what access existed before intervention, what control was applied, and what effect that control actually had.

The record you want
Before state → authorised action → observed result. If those three stages are clear, later investigators can separate hostile activity from incident-response activity.

Record the pre-action state

Where operationally possible, capture:

  • provider and product;
  • tenant and stable account ID;
  • active sessions or tokens;
  • trusted devices;
  • connected applications;
  • roles and administrators;
  • sharing or forwarding rules;
  • recovery methods; and
  • relevant audit events.

Use structured exports where available, with screenshots as supporting context rather than the only record.

Record each control separately

A containment timeline should not say only “account secured”.

It should show what actually happened:

14:22Password reset completed by administrator A.
14:24Session S-8841 revoked.
14:26Application APP-441 consent removed.
14:31Verification check shows no remaining active sessions.

For each intervention record:

  • exact time and time zone;
  • authoriser;
  • operator;
  • interface or control used;
  • expected effect;
  • response or error shown; and
  • later verification.

Keep the original and post-containment states distinct

Containment creates new provider events.

A rule removal, password change or role change may appear in later audit data. If you do not preserve the pre-action state, those responder actions can be confused with the activity you were originally investigating.

Before containmentEvidence of the account as foundSessions, roles, apps, sharing and recovery state.
After containmentEvidence of the interventionRevocations, removals, resets and verification checks.

Record unavoidable gaps

Sometimes harm prevention has to come first.

If an account must be disabled immediately, document:

  • why action could not wait;
  • what evidence was captured beforehand;
  • what could not be captured;
  • who made the decision; and
  • what later records may explain the intervention.

The practical point is: a good containment record explains both the account and the response. It should show what changed, when, why and with what measured effect.

Reference: CLD-167Cloud Services