In this section

Cloud Incident Response for Microsoft 365: Course Orientation

Module 0
A responder working a Microsoft 365 incident across identity, cloud, and on-prem telemetry
PRACTICAL INCIDENT RESPONSE · MODULE 00
Respond to any Microsoft 365 incident, from the first alert to regulatory closure.
By the end of this course you investigate, contain, and close real M365 compromises the way a working responder does, with the playbooks, queries, and decision discipline to do it under pressure. This module shows you what you will build, where you will work, and how the course gets you there.
12 modules
plus a multi-stage capstone
6 phases
preparation to post-incident
M365 E5
a real 810-staff estate
No prerequisites
every concept built up

Why this course exists

Every organization now operates under constant threat: ransomware that halts operations, identity attacks that bypass the password entirely, business email compromise that drains accounts, supply-chain intrusions, and data theft that ends in extortion and regulatory exposure. The common thread is that the work, the data, and the identities have moved to the cloud, and Microsoft 365 sits at the center of it for most organizations. That is exactly why attackers go there, and why the ability to respond in that environment has become a core security capability rather than a specialism.

The problem is that most teams are not ready when an incident lands. In M365 the perimeter is identity, the keys are tokens, and the evidence is scattered across a dozen log sources that each expire on their own schedule. An attacker can read a mailbox from a stolen token without dropping malware or tripping an endpoint alert, and the first sign is often a forwarding rule nobody created. This course builds the capability to respond when attacks succeed, not in theory, but against the same telemetry and the same pressure you would face on the job.

The M365 threat reality 600M+ identity attacks every day +146% AiTM phishing, year over year 31% of M365 breaches: token theft $3.04B BEC losses reported in 2025

What you will be able to do

This course is built around what you can do at the end, not what you have read. Every module puts you through the work, and you leave with capability you can use on Monday.

Triage and scope
Take an M365 alert and scope the full incident from the first signal, preserving evidence before it ages out.
Collect forensic evidence
Pull and read evidence across Entra ID, Exchange, SharePoint, OneDrive, and Teams, including MailItemsAccessed and hidden inbox rules.
Contain a live compromise
Cut off an active attacker with emergency Conditional Access, token revocation, and OAuth remediation, without breaking the business.
Run threat-specific playbooks
Work BEC, AiTM and token theft, malicious OAuth apps, and M365 ransomware as drilled procedures, not improvisation.
Meet the legal clock
Map breach-notification obligations, coordinate counsel, and brief executives and regulators with defensible facts.
Hunt and improve
Hunt for persistence that survives remediation, then close the loop with root cause analysis and stronger controls.

You also leave with artifacts you keep: an incident response plan, Conditional Access containment configurations, a library of KQL investigation queries, threat-specific playbooks, a breach-notification timeline, and a personalized IR action plan for your own organization.

From where you start to where you finish You can read an alert Triage and scope Forensics and containment Playbooks and compliance You lead M365 IR detection to regulatory closure

The environment you will work in

You investigate inside Northgate Engineering, a fictional 810-staff engineering company running Microsoft 365 E5, Entra ID, Microsoft Sentinel, and Defender XDR over an estate of 865 endpoints and 12 servers, six Red Hat and two Ubuntu, behind a Palo Alto firewall and a Squid proxy. It is small enough to hold in your head and real enough that the evidence behaves the way production evidence does.

Northgate Engineering topology: Microsoft 365, Entra ID, Sentinel and Defender XDR in the cloud, over an on-prem estate of workstations, RHEL and Ubuntu servers, a Palo Alto firewall, and a Squid proxy

Incident response lives in the evidence, so this course spends most of its time in the M365 log sources where attacks actually leave traces: Entra ID sign-in and audit logs for identity and token abuse, the mailbox audit log with MailItemsAccessed and message trace for email compromise, SharePoint, OneDrive, and Teams activity for data access, Defender XDR for endpoint and device signal, and Sentinel as the place it all converges. Every query you write and every playbook you run targets this estate.

How the course is built

Twelve modules move you across six phases, from getting ready before anything happens to learning from an incident after it closes. The path is deliberate: you cannot contain what you cannot scope, and you cannot scope what you have not prepared to see.

PHASE 1 Foundations and preparation Modules 1 to 3: frameworks, IR capability, Zero Trust readiness PHASE 2 Detection, investigation, and containment Modules 4 to 6: triage, M365 forensics, cloud-native containment PHASE 3 Threat-specific response Module 7: BEC, identity attacks, OAuth abuse, ransomware, insider threat PHASE 4 Legal, compliance, and communication Module 8: breach notification, counsel, executive and regulator briefing PHASE 5 Hunting and improvement Modules 9 to 10: proactive hunting, root cause, continuous improvement PHASE 6 Simulations and advanced topics: Modules 11 to 12, capstone and hybrid or multi-cloud

What you need and who this is for

There are no prerequisites. This course is for anyone who wants to learn how to respond to threats in Microsoft 365, and every concept is explained the first time it appears. You do not need to live entirely in the cloud to get the full value from it. If your primary infrastructure is on-prem and you only use parts of the stack, Exchange Online, Defender XDR, or Sentinel, the investigation methodology, the decision discipline, and the response process transfer directly to any environment you work in. The platform here is M365, but what you actually learn is how to run incident response, and that travels with you.

If you already run a SOC, use the section openers to skip what you know. If you are newer, the course builds the ground under you as it goes.

Transferable methodology
The process you build, triage, evidence, containment, eradication, recovery, hunting, works against any SIEM, EDR, or estate. M365 is the worked example, not the limit.
Helpful, not required
Access to an M365 or Sentinel tenant lets you run the techniques live. Without one, you still follow every step against prepared evidence on the page.
How to get the most
Run the queries, predict the output before you reveal it, and work the decision points before reading the answer. The course is built to be done, not skimmed.
Built by responders
The scenarios, decision points, and mistakes are drawn from real M365 investigations, sanitized and adapted for training.

Do I already know this material?

Six quick scenarios across the full range of this course, from the incident response lifecycle to eradication across a hybrid estate. Answer them to find out where you sit, and whether this course fits or it will sharpen knowledge you already have.

An incident is formally declared for a confirmed Microsoft 365 account compromise. Before deep analysis, what should the IR lead establish first?

The exact malware family the attacker used.
Scope and a clear objective: what is affected, what the immediate priority is (contain, preserve, or keep operating), and who owns the decisions.
Response without a defined scope and objective drifts. The lead's first job is to frame the incident, what is in play, what outcome matters most right now, and who decides, so every following action serves it.
A statement for the press.
The real-world identity of the attacker.

Mid-incident you discover the audit logging you need was never enabled, so the activity from two weeks ago is gone. What does this most illustrate?

IR outcomes are largely decided before the incident, by logging coverage, retention, and readiness; preparation is the highest-leverage IR work.
You cannot investigate evidence you never collected. The capacity to respond well is built in advance through logging, retention, and runbooks. When an incident exposes a preparation gap, the lesson is upstream, not in the response.
The attacker successfully covered their tracks.
Microsoft 365 cannot be investigated after the fact.
You should restore the tenant from backup.

You need to preserve evidence of a compromised Microsoft 365 mailbox before remediation. What is the right priority?

Reset the user's password first, then look at what is left.
Export the entire mailbox to a file and delete the account.
Preserve the time-limited cloud evidence, audit logs, sign-in logs, mailbox audit, and message trace, and place a legal hold before remediation ages it out.
Cloud evidence is governed by retention windows and is altered by remediation. You secure the perishable records and a hold first, then remediate, so the account of what happened survives the response.
Nothing special; cloud logs are retained forever.

You have contained a compromised account, sessions revoked and password reset. A teammate wants to declare the incident eradicated. What is missing?

Nothing; containment is the same as eradication.
Eradication requires removing every attacker foothold and persistence mechanism, OAuth grants, inbox rules, added credentials, registered MFA methods, app registrations, not just stopping the active session.
Containment stops the bleeding; eradication removes the means of return. A reset password does nothing to a consented app, an inbox rule, or an attacker-registered MFA method. Until those are gone, the door is still open.
A new tenant-wide password policy.
A user awareness email.

During an active breach with likely personal-data exposure, an executive wants to email all customers immediately. As IR lead, what is the right counsel?

Send it now; speed builds trust.
Refuse to notify anyone until the incident is fully closed.
Let the SOC decide when and what to send.
Coordinate with legal and communications before any external notice: regulatory timelines and wording carry legal weight, and premature or inaccurate notice can increase harm and liability; notify on a defensible basis, not a reflex.
External notification is a legal and reputational act, not an operational one. Timing and wording have regulatory consequences, so the lead routes it through legal and comms and notifies on a defensible basis, rather than reacting under pressure.

After eradicating a cloud account compromise, how do you gain confidence the attacker is actually out of a hybrid environment?

Confirm the user's password was reset.
Wait a week and watch whether anything happens.
Hunt for residual access across the hybrid estate, federation and directory-sync abuse, on-premises footholds, and app and token persistence, and validate; identity compromise often spans cloud and on-prem, and absence of alerts is not absence of the attacker.
In a hybrid estate a cloud compromise can have on-prem roots and vice versa. Confidence comes from actively hunting the places persistence hides across both, not from a quiet week, which only proves the attacker is patient.
Re-image the user's laptop.
This course is for you.
You will build the incident response capability from the ground up: the lifecycle, preparation, detection and analysis, cloud forensics, and containment through recovery, run against Microsoft 365 and hybrid estates.
Start Practical Incident Response
You have the fundamentals. The value here is the harder half.
You understand the lifecycle, so the payoff is the back half: cloud forensics and evidence, eradication completeness, legal and communications under pressure, hunting, and the capstone exercises.
Start with the advanced modules
You clearly know incident response.
You handled cloud evidence, eradication completeness, the legal and communications call, and hybrid hunting, the senior end of the discipline. Take the course to sharpen what you have, close the gaps you did not expect, and turn strong instincts into a response capability you can run and defend.
Start Practical Incident Response

Start here

You are a student of this course now, so start by deciding what you want from it. Are you here to build the capability from the ground up, to close specific gaps in how your team responds today, or to prepare for a role that demands it? Name that outcome, then turn it into a study plan: which phases matter most to you, how much time you will give it each week, and what you want to be able to do by the time you finish.

The rest of Module 0 is built to set you up to do exactly that. Work through the orientation subs to see what the course covers in full, how to get the most from it, where M365 evidence lives, and the toolkit you will use throughout. Take them in order, then begin Module 1 when you are ready.