In this section

Northgate Engineering: The Worked Environment for M365 Incident Response

Module 0

Introduction

Every worked example in this course happens at one organization. This section describes it, because a scenario you can picture teaches better than one you have to reconstruct each time, and because the shape of this particular organization is why the problems in the material bite the way they do.

It also covers what to do with it, which is to read Northgate as a comparison against your own estate rather than as a case study to memorize.

Scenario

Northgate Engineering has 810 staff, Microsoft 365 E5, Sentinel, Defender XDR and a security team of four. It is large enough to hold data that a regulator cares about and small enough that one person is frequently the entire response. That combination is not unusual. It is the most common shape of organization to have a serious incident and no dedicated incident response function.

01

The Organization

Eight hundred and ten people, and four in security

It is described here in one place rather than reintroduced per module, so a scenario later in the course can name Rachel or refer to the contractor population without explaining who they are.

Every course on this platform uses the same fictional organization, so a reader who has taken another one will recognize it. What follows is the version that matters for incident response.

Northgate is an engineering firm. It designs and builds things, it has clients with contracts and drawings, and its intellectual property is worth stealing.

The four rows below are the ones that decide what an investigation there can do.

The estate

People

810 staff, plus contractors on shorter engagements

Identity and productivity

Microsoft 365 E5, Entra ID

Security tooling

Microsoft Sentinel, Defender XDR

Endpoints and servers

865 endpoints, 12 servers

The intellectual property point matters for the scenarios. An engineering firm's drawings and client contracts are the kind of material that has a buyer, which makes exfiltration a plausible objective rather than a theoretical one, and it means a compromise has a commercial consequence somebody outside security will ask about.

Why a well-equipped estate still has four gaps E5, Sentinel, Defender XDR detection, monitoring, alerts four people, business hours no dedicated IR function nobody owns log export, licensing spread, on-call permissions A plan approved, filed and never read, which is what keeps the other three invisible Investment produced the left column. Nothing in it assigns the right one to anybody.

That is a well-equipped organization by most standards, and it is worth noticing before the course starts finding problems with it. Northgate bought the top licensing tier, deployed a SIEM and an XDR, and has people whose job is security.

Sentinel and Defender XDR together are a serious detection investment, and the course does not treat them as sufficient. Both are in place at Northgate throughout, and several of the incidents in the later modules are ones neither of them raised.

Four people in security across 810 staff is neither generous nor unusual. It is enough to run detection and monitoring during working hours, and not enough to have somebody whose only job is incident response, which is the constraint most of the operational decisions in this course are made under.

The problems in this course are not the problems of an under-invested estate. They are the problems that survive investment, which is a more useful thing to study because the reader probably works somewhere similar.

Twelve servers and 865 endpoints is a hybrid estate rather than a pure cloud one, which matters for scope. A compromise that begins in the tenant can reach a server, and one that begins on an endpoint can reach the tenant, so several scenarios cross that boundary and the course says where its own coverage stops.

The size is the point. Under a hundred people and there is no security team to have a process; over ten thousand and there is a dedicated response function with its own budget. Between those, one person is the process, and that is where most of this material lands.

02

The People You Will Meet

Six names, and what each one wants

Incidents are not run by roles, and the scenarios name individuals for that reason.

The same handful of people appear throughout the course, and knowing what each of them is optimizing for makes the scenarios read faster.

None of them is an antagonist, which is worth saying because incident scenarios frequently write the business as an obstacle.

What somebody wants from an incident predicts what they will ask you for and when, which is more useful to know than their title.

The same six people appear throughout the course. What each wants from an incident predicts what they will ask you for, and when.

Who
What they want from an incident
Rachel Okafor
CISO · To know the scope and what to tell the board, early and honestly
Phil Greaves
IT Director · The business working, and to understand what a containment step costs
Marcus Webb
Security Architect · The control change that stops it recurring
Tom Ashworth
SOC analyst · To know whether this alert is the one that matters
Priya Sharma
SOC analyst · The same, on the other shift, with different context
Elena Petrova
GRC · Whether a clock is running, and what has to be said to whom

Phil deserves a note because he is easy to read as an obstacle and is not. An IT Director resisting a containment step that stops 810 people working is doing his job, and the responder's task is to give him a decision rather than an instruction.

Rachel is the one most scenarios route through, because a CISO is who an incident escalates to and who has to speak to people outside security. Elena appears whenever a clock starts, which per the later modules is earlier than most people expect.

Who an incident reaches, and what each one asks for Tom or Priya, SOC Rachel, CISO Elena, GRC Phil, IT Director Marcus, Architect is this the one? is a clock running? what does containment cost? what stops it recurring? Four questions, arriving at different moments. None of them is the one the responder is currently answering.

The tensions between them are real and they are not personality clashes. Phil's job makes him cautious about a containment step that stops people working; Rachel's makes her want scope before she has it; Elena's makes her ask about notification while the investigation is still establishing facts.

Six names is enough to run every scenario in the course and few enough to remember. Where a scenario needs somebody outside this list it says who they are.

The two analysts are deliberately a pair rather than one person. Tom and Priya work different shifts, see different parts of the same activity, and hand over between them, which is where a great deal of real detail is lost and where several of the scenarios in this course turn.

Those pressures appear in the worked cases because they appear in real incidents, and a responder who has only rehearsed the technical work is unprepared for the half of an incident that consists of other people.

Marcus is the counterweight to the response work. His interest is the control that stops it happening again, which is a different question from the one the responder is answering, and the tension between finishing an incident and fixing its cause runs through the last three modules.

Watchpoint SOC is the external partner where a scenario needs one, covering out-of-hours triage. It is the arrangement most organizations of this size have, and per the later modules it introduces its own questions about who investigates and who holds the evidence.

03

Why the Licensing Detail Matters

E5 is the tenant, not every account

One detail of the estate does enough work in the later modules to be worth pulling out here.

Northgate runs Microsoft 365 E5, which is the top tier and the one that answers most investigative questions. That fact does more work in this course than it first appears, and not in the direction you would expect.

The instinct is to read E5 as the answer to every licensing question in the course, and it is not.

Licensing in Microsoft 365 frequently follows the user rather than the tenant. An organization on E5 still has populations outside it: contractors on cheaper licenses, guests from partner organizations, service accounts, and anybody added since the last licensing review.

The mechanism is worth holding now because it reappears in three separate modules. What an audit record retains, and whether some record types exist at all, follows the person who generated it, so a tenant-level statement about licensing is not a statement about any particular investigation.

Who sits outside the tenant's licensing tier

  • Contractors on cheaper licenses.
  • Guests from partner organizations.
  • Service accounts and anything added since the last review.
  • The population most likely to be attacked is not reliably in the well-licensed group.

The consequence for reading this course is small and specific. When a section says Northgate is E5, that is a fact about the organization; when it says a particular question cannot be answered, that is a fact about one account, and the two are compatible.

That is why Northgate is an E5 organization with a contractor problem rather than an E3 organization with a licensing problem. The second would be a simple story with an obvious fix; the first is what organizations actually have, and it is invisible until an investigation asks a question about the wrong person.

It also means a reader whose organization is on a lower tier should not skip the licensing material. The mechanism is the same and the affected population is simply larger, so the technique for establishing who is outside it transfers directly.

Module one works this in detail. The point here is that Northgate was chosen to be well-licensed precisely so the course cannot lean on the easy explanation that somebody should have bought more.

04

What Northgate Has Not Done

The gaps are ordinary, not negligent

A worked organization with no problems teaches nothing, and one with obvious problems teaches the wrong lesson.

The estate has specific weaknesses, and each one exists for a reason somebody could defend at the time.

Four gaps that appear across the course

  • No log export, so the identity evidence lives on the platform's own retention.
  • Mixed licensing, so some populations cannot be investigated to the same depth.
  • An on-call rota whose permissions were never tested from the on-call account.
  • A plan approved, filed, and not read since.

Read them together and a pattern appears. Each gap is invisible while nothing is wrong, each becomes decisive during an incident, and none of them would be found by an audit that checks whether controls exist rather than whether they can be used.

Each of the four is defensible at the moment it was decided and indefensible afterwards, which is the shape of almost every readiness gap.

None of those is negligence. An export costs money and nobody could name the question it would answer. Mixed licensing is a procurement decision made on price by people with no visibility of this consequence. The rota's permissions were tested, by somebody whose account made the test meaningless.

The fourth is the one most organizations will recognize immediately. A plan approved and filed is a plan whose assumptions have not been tested against anything, and per the later modules the citation and the structure both go stale without anybody noticing.

That is the argument for describing them as ordinary rather than as failures. A course whose fictional organization is incompetent teaches you to feel superior to it; one whose organization made defensible decisions teaches you to recognize your own.

That is also why the course spends its first module on what the tenant can answer rather than on how to investigate. Three of the four gaps above are questions about the environment rather than about technique, and all three are answerable on an ordinary afternoon.

Each gap is closed somewhere in the course, and the module that closes it also supplies the argument for the cost, which is the thing the original decision was missing.

05

How to Read Northgate

As a comparison, not as a case study

How you read the worked material decides how much you get from it, and the default reading is the less useful one.

The worked examples are not there to be memorized, and the specific numbers in them matter less than the shape.

A worked example is a comparison instrument rather than a body of facts, and reading it as the second is how people finish a course knowing a fictional company well.

Read every Northgate figure as a question about your own estate. When a section says Northgate's identity logs hold thirty days, the useful response is not to note the number but to ask what yours hold, which is what the practice card per IR0.2 will then ask you to establish.

The distinction is small on the page and large in what it produces.

The two readings

  • As a case study: Northgate had a contractor outside E5 licensing.
  • As a comparison: who at my organization is outside it, and do I know?
  • Only the second produces anything, and the first is the default.

The habit is worth forming early because it compounds. By module four you will have compared your retention, your permissions, your licensing distribution and your export configuration against Northgate's, and the accumulated set is most of what module two asks you to produce deliberately.

Differences run both ways and both are useful. Somewhere your estate is worse than Northgate's is a gap to record; somewhere it is better is a section you can move through quickly and a control worth knowing you have.

Where your estate differs, the difference is the finding. A reader whose organization has full log export will find several Northgate problems do not apply, which is worth knowing explicitly rather than assuming, and a reader whose estate is smaller will find some of the tooling absent entirely.

The course is written so that both readers get something. The technique is the same whether the evidence came from a workspace or a portal; what changes is how far back it reaches.

06

The Attack Material

Recognition, and a line that holds

One more thing to say about the material before the course begins, because it shapes what the attack sections contain.

Attacks against Northgate appear throughout, and per IR0.1 they appear as evidence rather than as tradecraft.

This holds for every attack in the course and it is stated here once rather than repeated per section.

You will see what an attack leaves behind: the record it produces, the field that separates it from ordinary activity, and the query that finds it. You will not see the tooling, the commands, or anything that helps somebody run one.

The practical effect is that you will finish this course able to recognize a device code phishing attack in a log and unable to conduct one, which is the correct outcome for a course about response.

That boundary is not negotiable and it holds even where the omission is inconvenient. It also holds in the practice cards. Nothing in this course asks you to run an attack against your own environment, and the lab work in later modules is about producing evidence to investigate rather than about conducting an intrusion.

Where a technique is easier to explain by describing how it is performed, this course describes what it looks like from the defending side instead, which is the side you will be on.

Where the line falls

Shown

the record, the distinguishing field, the query that finds it

Shown

the sequence, at the level a defender needs to recognize it

Not shown

tooling, commands, anything that helps run one

The material also names its sources rather than asserting figures, which matters because attack statistics age quickly and a reader should be able to check whether a number still holds.

The attacks are real ones. They are drawn from published incident research rather than invented, because an invented attack teaches you to recognize an invented artifact. Where a figure appears, it comes from a named source and the section says so.

07

What Northgate Cannot Teach You

The limits of a worked example

Being clear about what a worked example does not do is more useful than claiming it does everything.

A consistent fictional estate has real advantages and two specific limits worth stating.

The advantages are worth stating first. A consistent estate means a technique learned in module three applies to the same tenant in module seven, and the scenarios can build on each other rather than resetting.

It cannot teach you your own environment. Northgate's retention, licensing, tooling and permissions are described precisely so that yours can be compared against them, and no amount of reading substitutes for running the query per IR0.2.

That limit is the reason for the practice cards rather than an argument against the worked example, and per IR0.2 the two are designed to be used together: read what happened at Northgate, then establish the same fact about your own tenant.

And it cannot teach you organizational pressure. The scenarios show Rachel asking for scope before it exists and Phil resisting a containment step, and reading that is not the same as being in the room. The nearest this course gets is the capstone, where the decisions come with time pressure attached.

Both limits point the same way, which is toward the practice cards rather than away from the worked material.

What the worked example is and is not

Is

a consistent estate, so techniques compound across modules

Is

a comparison point for your own environment

Is not

a substitute for running anything yourself

There is a third limit that applies to every fictional scenario and is worth naming. Northgate's incidents resolve, and real ones sometimes do not, so the worked cases are cleaner in outline than the cases you will run. Where a section can show an ambiguous outcome honestly it does.

That is the honest limit of any worked example, and it is the reason every section in this course ends by handing the action to you rather than concluding.

08

Practice

Compare your estate against this one

The exercise below produces the page every later comparison in this course is made against, and it takes about twenty minutes with the portals open.

Do this Write your own version of the estate table
  1. Fill in the four rows from section one for your own organization: people, licensing, security tooling, endpoints and servers.
  2. Name your six people. Who is the Rachel, the Phil, the Elena? In a smaller organization several of them are one person, and knowing which is useful before an incident.
  3. Check the four gaps in section four against your estate. Most organizations have at least two.
  4. Note where you are better off than Northgate, because that decides which parts of this course you can move through quickly.
What you should end up with: a one-page description of your own estate in the same shape as the one you will read about for ten modules. Every later comparison is against this page.

The next section is where evidence actually lives in a Microsoft 365 tenant, which is the map the rest of the course navigates by.