Microsoft Cloud Incident Response
Investigate, Contain, and Recover from M365 Incidents
Build the complete incident response capability for Microsoft 365 environments. From configuring the environment that preserves evidence to running the investigation that finds the attacker to executing the containment that stops them.
What you'll be able to do
Course Syllabus
Every module and every lesson. The first three modules are open; the rest open on a click.
Download the full syllabus (PDF)
Phase 1: Orientation and Foundations
What a Microsoft 365 investigation can physically reach, how to work through the course, the estate every example runs on, where the evidence lives, and the toolkit.
Who owns the evidence in a Microsoft 365 tenant, what it can and cannot establish, the deadlines that run regardless, and what a responder can defensibly claim.
Show 13 lessonsHide lessons
- 1.1IR1.1 The Shared Responsibility Model, and the Half Nobody Logs For You
- 1.2IR1.2 Identity Is the Perimeter, and What That Costs an Investigation
- 1.3IR1.3 The Threat Landscape: Attacks That Collect Authentication Rather Than Break It
- 1.4IR1.4 The Framework Stopped Telling You How
- 1.5IR1.5 Where the Framework Stops Describing a Tenant
- 1.6IR1.6 The Clock Starts at Awareness, Not at Certainty
- 1.7IR1.7 How You Find Out Decides What Is Left
- 1.8IR1.8 The Questions a Tenant Cannot Answer at Any Speed
- 1.9IR1.9 What You Can Defend, and at What Confidence
- 1.10IR1.10 The Access You Need Before You Need It
- 1.11IR1.11 See It Done: One Case, End to End
- 1.12IR1.12 The Two Hunting Surfaces
- 1.13Check My Knowledge
The tenant configuration that decides whether an investigation is possible: log export, the two retention systems, what to switch on, and who can reach it.
Show 11 lessonsHide lessons
- 2.1IR2.1 The Export That Has No Retroactive Fix
- 2.2IR2.2 Two Retention Systems, Not One
- 2.3IR2.3 Choosing Where the Records Go
- 2.4IR2.4 Retention Per Record Type
- 2.5IR2.5 Turning On What Is Off
- 2.6IR2.6 The Permissions Your Rota Needs
- 2.7IR2.7 Alerting on the Durable Artifacts
- 2.8IR2.8 Practicing the Collection
- 2.9IR2.9 Documenting What the Tenant Records
- 2.10IR2.10 What You Can Now Promise
- 2.11IR2.11 Simulating the Attack You Prepared For
Phase 2: Detection, Investigation, and Containment
Where a case reaches you from, what each source can tell you when it arrives, and how the records in a Microsoft 365 tenant turn a signal into a scoped incident.
Show 12 lessonsHide lessons
- 3.1IR3.1 Detection Sources in Microsoft 365
- 3.2IR3.2 Unified Audit Log Fundamentals
- 3.3IR3.3 Entra ID Sign-in and Risk Analysis
- 3.4IR3.4 Email Threat Detection with Defender for Office 365
- 3.5IR3.5 Defender XDR Incidents and Alert Correlation
- 3.6IR3.6 Mailbox and Exchange Forensic Signals
- 3.7IR3.7 OAuth Apps, Consent Grants and Persistence Detection
- 3.8IR3.8 SharePoint, OneDrive and Teams Activity Analysis
- 3.9IR3.9 Advanced Hunting with KQL
- 3.10IR3.10 Triage, Scoping and Investigation Timeline Building
- 3.11IR3.11 See It Done: One Case, Ten Surfaces
- 3.12Check My Knowledge
Evidence taken in a way that will hold. What you cannot image, what preservation buys, the index that omits without telling you, and the package somebody else will rely on.
Show 12 lessonsHide lessons
- 4.1IR4.1 What You Cannot Image
- 4.2IR4.2 Preserve Before You Collect
- 4.3IR4.3 The Tool That Replaced Three
- 4.4IR4.4 The Index That Quietly Omits
- 4.5IR4.5 Exporting the Audit Record
- 4.6IR4.6 Capture Before Removal
- 4.7IR4.7 What a Hash Proves
- 4.8IR4.8 Custody Without Custody
- 4.9IR4.9 What You Can Notify On
- 4.10IR4.10 The Package Somebody Else Reads
- 4.11IR4.11 See It Done: The Same Week, From the Collection Side
- 4.12Check My Knowledge
What the tenant can still tell you, and what it never recorded. Retention that follows the user who acted, an endpoint that omits half the sign-ins, a mailbox that stops logging when it matters, and a report bounded by all three.
Show 12 lessonsHide lessons
- 5.1IR5.1 Evidence Inventory, Collection Planning, and What You Can Claim
- 5.2IR5.2 Entra ID Forensic Artifacts
- 5.3IR5.3 Mailbox and Exchange Forensics
- 5.4IR5.4 SharePoint, OneDrive, and Teams Forensics
- 5.5IR5.5 OAuth, Tokens, and Application Forensics
- 5.6IR5.6 Graph Activity Logs: What the Token Did
- 5.7IR5.7 Collection Tooling and Automation
- 5.8IR5.8 Timeline Reconstruction and Cross-Source Correlation
- 5.9IR5.9 M365 Anti-Forensic Techniques
- 5.10IR5.10 Hybrid Identity Forensics
- 5.11IR5.11 See It Done: A Question Four Months Late
- 5.12Check My Knowledge
An attacker removed, and the removal verified. Four access paths that fail independently, the order that stops a revocation handing over a fresh session, and the checks that can tell a clean containment from a broken query.
Show 12 lessonsHide lessons
- 6.1IR6.1 Containment Without Infrastructure
- 6.2IR6.2 Revocation, and the Four Populations It Misses
- 6.3IR6.3 The Policy You Write Under Pressure and Delete Afterwards
- 6.4IR6.4 Disabled, Contained, or Left Running
- 6.5IR6.5 The Reset That Leaves a Method Behind
- 6.6IR6.6 Application and Workload Identity Containment
- 6.7IR6.7 The Mailbox Footholds, and the Limits on Removing Them
- 6.8IR6.8 Sharing Links Outlive Identity
- 6.9IR6.9 Proving It Landed
- 6.10IR6.10 The Sync Boundary
- 6.11IR6.11 See It Done: The Morning It Was Already Contained
- 6.12Check My Knowledge
Phase 3: Responding by Attack Type
The same lifecycle behaves differently depending on what the attacker came for. Nine attack types, the decision each one turns on, and what to do when two of them are running at once.
Show 12 lessonsHide lessons
- 7.1IR7.1 The Window Between Access and Containment
- 7.2IR7.2 When the Session Is What Was Stolen
- 7.3IR7.3 Consent Phishing and the App That Stays
- 7.4IR7.4 Business Email Compromise
- 7.5IR7.5 Ransomware Without an Endpoint
- 7.6IR7.6 When the Subject Works Here
- 7.7IR7.7 When the Compromise Is the Vendor's
- 7.8IR7.8 When the Identity Is an AI
- 7.9IR7.9 The Identity That Leaves Your Tenant
- 7.10IR7.10 When Two of These Are Running at Once
- 7.11IR7.11 See It Done: One Campaign, Four Playbooks
- 7.12Check My Knowledge
Phase 4: Hunting and the Aftermath
Asking a question no rule was written for. Where hypotheses come from, how far back the tenant will answer, what survives a clean response, and how a day of analyst time becomes coverage that runs without anybody.
Show 12 lessonsHide lessons
- 8.1IR8.1 Hunting Without an Alert
- 8.2IR8.2 A Hypothesis You Can Be Wrong About
- 8.3IR8.3 How Far Back You Can Actually Look
- 8.4IR8.4 The Identity Tables and the Date in October
- 8.5IR8.5 Hunting What the Response Left Behind
- 8.6IR8.6 When Nothing Was Added
- 8.7IR8.7 A Result Is Not Yet a Finding
- 8.8IR8.8 From a Hunt to a Rule That Runs Without You
- 8.9IR8.9 The Rule You Wrote a Year Ago
- 8.10IR8.10 When the Hunt Finds Nothing
- 8.11IR8.11 See It Done: One Hypothesis, Start to Finish
- 8.12Check My Knowledge
A report, a notification and a control change. What an organization can defensibly say about a closed incident once the evidence behind it has started expiring, and how to tell whether the changes it produced are still true a year later.
Show 12 lessonsHide lessons
- 9.1IR9.1 The Report That Outlives the Evidence
- 9.2IR9.2 Where the Causal Chain Actually Stops
- 9.3IR9.3 What the Collection Lets You Notify
- 9.4IR9.4 Three Clocks, One Incident
- 9.5IR9.5 The Numbers Somebody Will Check
- 9.6IR9.6 Privilege Over an Export
- 9.7IR9.7 Four Readers, One Set of Facts
- 9.8IR9.8 The Metric That Improves as Your Evidence Gets Worse
- 9.9IR9.9 Findings Into Tenant Changes
- 9.10IR9.10 What Closed Actually Means
- 9.11IR9.11 See It Done: From a Statement to a Verified Change
- 9.12Check My Knowledge
Phase 5: Recovery
Getting the tenant back, and being able to say so. What Microsoft 365 can restore, what it cannot, the order that stops a restore reinviting the actor, and why recovered is not the same as unexposed.
Show 12 lessonsHide lessons
- 10.1IR10.1 Recovery Is Not Undo
- 10.2IR10.2 The Order That Stops a Restore Reinviting the Actor
- 10.3IR10.3 Mail: The One Window You Control
- 10.4IR10.4 Files: Two Safety Nets, and One Is a User Setting
- 10.5IR10.5 The Identity You Deleted
- 10.6IR10.6 Teams: There Is No Restore
- 10.7IR10.7 When Retention Fights Recovery
- 10.8IR10.8 What Cannot Be Recovered
- 10.9IR10.9 Proving It Came Back
- 10.10IR10.10 Who Declares It Over
- 10.11IR10.11 See It Done: A Library, a Setting, and Four Days
- 10.12Check My Knowledge
Phase 0: Course Resources
Investigation and response queries organized by lifecycle stage, each carrying whether the finding would survive challenge.
Eight procedures, from working an incident through to the report and the review, each with the branches and the record it has to leave.
Show 8 lessonsHide lessons
- 1Working an Incident to Scope
- 2Containing Without Losing the Evidence
- 3Proving Eradication Rather Than Declaring It
- 4Writing the Investigation Report
- 5Collecting Evidence You Can Rely On Later
- 6Preparing the Notification Input
- 7Running the Post-Incident Review
- 8Restoring Without Reinviting the Actor
Five pages to a tenant you can respond in, including what it costs and when, and how to produce an incident worth investigating.
Seven worked cases where the investigation was competent and the conclusion did not hold.
Eight playbooks for responding under a constraint: a running clock, expiring evidence, a live actor, a failed eradication, a filed report that changed.
Show 8 lessonsHide lessons
- 1The Clock Is Running and the Scope Is Open
- 2The Evidence Is Expiring While You Work
- 3The Actor Is Still Moving
- 4A Closed Incident Was Never Eradicated
- 5The Facts Changed After the Report Went Out
- 6A Supplier Tells You They Were Breached
- 7A Legal Hold Arrives Mid-Response
- 8A Restore Brought the Damage Back
Where to practice responding, and the two things about this discipline no practice surface can give you.
The consolidated lookup and the step-by-step procedures from this course, in one place.
Show 2 lessonsHide lessons
External sources this course draws on: vendor documentation, frameworks, standards, and research.
Course Completion
Microsoft Cloud Incident Response end-of-course exam, a simulation-based assessment testing your ability to triage, investigate, contain, and report on a multi-stage Microsoft 365 incident using the skills built across all ten modules.
Show 1 lessonHide lessons
Course overview
Microsoft Cloud Incident Response teaches the complete incident response lifecycle for Microsoft 365 environments. Every module produces a capability you can execute during a real incident. You configure the environment that preserves evidence before you need it. You build the playbooks and runbooks that eliminate improvisation under pressure. You run investigations using KQL, Graph API, and PowerShell against the same log sources and evidence tables you'll query during a real compromise. You execute containment through Conditional Access, session revocation, and OAuth grant removal. You hunt for what the detections missed and convert a finding into a rule that runs without you. You handle the notification, the legal coordination and the post-incident improvement. And you recover the tenant, which is the phase most courses name and skip: what Microsoft 365 can restore, what it cannot, and why a completed recovery is a partial resolution of most modern incidents.
The course follows the incident response lifecycle across five phases: orientation and foundations, detection and investigation and containment, responding by attack type, hunting and the aftermath, and recovery. Guided walkthroughs in every module put you through end-to-end scenarios. Incident Lab scenarios let you practice investigation queries against synthetic data with known answers.
How this course works
Every module in this course runs the same six-step loop against a Microsoft 365 tenant. It is the habit the course is built to install, because it is the sequence that produces a claim somebody else can check rather than an account somebody has to take on trust.
1. Establish what the tenant recorded. Before any query, know which operations are collected at your license tier, how long they are kept, and what was never written down. An empty result means one of three things and only one of them is about the incident.
2. Scope from the record rather than from the alert. The alert is where the case reached you. The scope comes from reading the audit trail, both sign-in tables and the file and mail activity, and it is almost always larger than the alert suggested.
3. Preserve before you collect. Preservation stops a clock; collection takes a copy. Doing the second without the first means the material can expire between the decision and the export.
4. Contain across the four paths. Sessions, credentials, application identities and sharing links fail independently. Closing three properly still leaves the fourth open, and it is usually the one nobody looked at.
5. Verify that the action landed. Taking an action and proving it worked are separate pieces of work. Every check needs a positive control, because an empty result is a claim about your query as much as about the tenant.
6. State what the evidence supports, and what it does not. A figure without its basis is a figure somebody else will derive differently. A gap in the record is a finding with an owner rather than an apology.
Recovery closes the loop and does not undo it. What can be restored, in what order, and why the copy that already left is unaffected by any of it.
What this course assumes
No minimum experience and no prerequisite course. Every concept is explained where it is first used, including the ones a syllabus like this would normally assume: what the unified audit log is, why there are two sign-in tables, what a refresh token does. If you have never opened the Defender portal, start at module zero and nothing will be missing.
What does make it go faster: a Microsoft 365 tenant you can read, even a developer one, and enough comfort with a command line to run a PowerShell cmdlet and read what comes back. Neither is required. Every query in the course can be practiced against the Practice Hub instead, which holds populated tables and known answers, and the lab module walks through building a tenant from nothing if you want one.
What the course does not cover, deliberately: endpoint forensics beyond what Microsoft 365 reaches, memory analysis, and malware reverse engineering. Those are separate disciplines with their own courses, and a cloud investigation that pretends to teach them alongside teaches neither properly.
Who this course is for
Anyone who wants to learn cloud incident response. The course is built for security analysts, SOC engineers, IT administrators responsible for M365 security, and anyone who needs to investigate or respond to incidents in Microsoft 365 and Entra ID environments. No minimum experience required. Every concept is explained at first use, and experienced cybersecurity professionals can skip ahead using the module structure.
What you'll learn
Key course takeaways
Course Resources - what comes with the modules
Every course carries a resources phase built for that course and no other. It is the part subscribers keep going back to long after they have read the modules once.
Things you need to know
What are the prerequisites?
None. The course teaches cloud incident response from first principles. Familiarity with Microsoft 365, Entra ID, and KQL will help you move faster, but none are required. Every tool, technique, and concept is explained at first use.
What tools does this course use?
KQL (Kusto Query Language) for investigation queries in Sentinel and Defender XDR. Microsoft Graph PowerShell for evidence collection and containment. The Microsoft Extractor Suite for bulk evidence export. All tools are free. The course walks through installation and configuration.
Do I need an M365 tenant?
An M365 E5 developer tenant is recommended for hands-on practice. The course provides setup guidance. Investigation queries can also be practiced against the Incident Lab's synthetic NE Corpus data without a tenant.
How will this course benefit your career?
Cloud incident response is one of the most in-demand skills in cybersecurity. Organizations running M365 need people who can investigate a compromise, contain the attacker, determine what was accessed, and produce a report that leadership and legal can act on. This course builds that capability end to end.
Usage rights and disclaimer
Course materials: Licensed for individual professional development. You may deploy investigation queries, PowerShell scripts, playbooks, and containment runbooks in your production environment. You may not redistribute course content or share account credentials.
Fictional environment: All scenarios use Northgate Engineering (NE). Any resemblance to real organizations is coincidental.
End of Course Exam
Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.
One random scenario per attempt. Certificate issued on pass.