Agent Foskett Academy • Microsoft Security Copilot • Module 2 • Lesson 12

Lesson 12 — Investigating Identity Compromise

Identity incidents rarely begin and end with one risky sign-in.

A complete investigation can involve user risk, authentication methods, MFA, Conditional Access, audit changes, privileged roles, mailbox activity, endpoint evidence, cloud access and session abuse.

This lesson explains how Security Copilot supports Microsoft Entra and Defender identity investigations while the analyst validates every sign-in, change, relationship and remediation decision.

A risky sign-in is a clue. Identity compromise is a conclusion that must be proven.
Agent Foskett Investigating Identity Compromise lesson
What you will learn

This lesson develops a complete identity-compromise investigation across Microsoft Entra and Defender.

✓ Risky users and suspicious sign-ins
✓ MFA, sessions and authentication changes
✓ Privileges, mailbox and endpoint evidence
✓ Validated remediation and monitoring

Identity-compromise investigation workflow

Open the risky user, identity alert or incident

Confirm the exact identity and tenant

Generate the Copilot risk or identity summary

Review user risk, sign-in risk and detections

Validate IP, location, application, device, MFA and Conditional Access

Review audit changes, roles, consent and authentication methods

Correlate mailbox, endpoint, Sentinel and cloud evidence

Build a single chronological identity timeline

Separate confirmed compromise, suspicious activity and legitimate context

Apply approved remediation

Monitor for persistence and repeated activity

Identity evidence domains

DomainEvidenceInvestigation question
Sign-in evidenceIP, location, application, client, device, MFA and Conditional Access.Was the authentication malicious or legitimate?
User riskRisk detections, history, criticality and identity context.Is the identity likely compromised?
Audit evidencePassword, methods, roles, groups, consent and policy changes.Did the attacker establish persistence or privilege?
Mailbox evidenceRules, forwarding, delegate access and sent messages.Was the identity used for email abuse?
Endpoint evidenceProcesses, browsers, credentials, alerts and device activity.Was the account used from or stolen on a device?
Cloud and data evidenceApplications, resources, files and sensitive data access.What did the identity access after compromise?

Learning objectives

  • Distinguish user risk from sign-in risk.
  • Investigate suspicious authentication and MFA.
  • Review audit, privilege and consent changes.
  • Correlate mailbox and endpoint evidence.
  • Build an identity timeline.
  • Validate remediation actions.
  • Document confidence and uncertainty.

What is identity compromise?

Identity compromise occurs when an attacker gains or abuses authentication material, sessions, permissions or account access.

User risk versus sign-in risk

User risk reflects the likelihood an identity is compromised, while sign-in risk reflects the likelihood a specific authentication attempt is malicious.

Start with the risky user

Use Microsoft Entra ID Protection and Security Copilot to summarise why the user risk level was elevated.

Risk summary is orientation

The Copilot summary helps prioritise evidence but does not prove compromise.

Confirm the identity

Verify the exact user, object ID, tenant, role, department and account type before correlating activity.

Review identity criticality

Privileged, service and business-critical identities require heightened urgency and stronger review.

Review sign-in history

Compare suspicious sign-ins with the user’s normal locations, devices, applications and authentication patterns.

Check IP ownership

Identify whether the source belongs to a VPN, proxy, mobile carrier, cloud provider, corporate network or malicious infrastructure.

Check location carefully

Geographic distance can be misleading when VPNs, proxies, mobile networks or token replay are involved.

Check application context

Confirm which application, resource and client type were involved in the sign-in.

Check authentication method

Review password, MFA, passwordless, certificate and federated authentication evidence.

Check MFA details

Determine whether MFA succeeded, failed, was interrupted, bypassed or completed by an unexpected method.

Check authentication strength

Confirm whether the sign-in met the intended Conditional Access authentication strength.

Check Conditional Access

Review policies applied, not applied, interrupted or reported in the sign-in record.

Check device context

Confirm device ID, compliance, management, trust type, operating system and browser.

Check session context

Review session identifiers, token use, refresh activity and evidence of session theft or replay.

Check risk detections

Review the specific Entra detections that contributed to user or sign-in risk.

Check risk timing

Some detections occur in real time while others appear after offline analysis.

Check risk state

Understand whether the risk is at risk, confirmed compromised, remediated, dismissed or confirmed safe.

Check risk history

Review changes to risk state and previous detections for the identity.

Review audit logs

Look for password resets, authentication-method changes, group changes, app consent and policy modifications.

Authentication method changes

New phone numbers, FIDO2 keys, passkeys or authenticator registrations can indicate persistence.

Password changes

Determine who changed the password, when it occurred and whether it was expected.

Session revocation

Confirm whether refresh tokens and active sessions were revoked during response.

Privilege changes

Review directory roles, PIM activations, group membership and privileged assignments.

Service principal activity

Investigate application identities separately from human user accounts.

Consent grants

Check delegated and application consent for unexpected OAuth permissions.

Mailbox evidence

Review inbox rules, forwarding, delegate access, sent mail and suspicious message activity.

Compromised email behaviour

Attackers may use a compromised mailbox to send internal or external phishing.

Endpoint evidence

Correlate identity activity with device alerts, process execution, browser behaviour and credential theft.

Defender identity summary

Microsoft Copilot in Defender can summarise account creation, criticality, roles, sign-in patterns, methods and Entra risks.

Defender user page

Use the identity entity page to pivot across alerts, devices, sessions and related activity.

Sentinel correlation

Use Sentinel to connect identity events with broader network, application and cloud telemetry.

Advanced hunting

Use KQL to verify sign-ins, identity changes, endpoint activity and related alerts.

Normal behaviour baseline

Compare suspicious activity with known user behaviour rather than relying on rarity alone.

Travel context

Check approved travel, remote work, business schedules and known device use.

Impossible travel limitations

Do not treat an impossible-travel detection as proof without checking VPN and session context.

Legacy authentication

Review legacy authentication because it can bypass modern controls and indicate password abuse.

Token theft

A stolen token can allow access without a new password or visible MFA challenge.

MFA fatigue

Repeated MFA prompts followed by acceptance may indicate push-bombing or social engineering.

Adversary-in-the-middle

Session theft can occur after successful MFA through phishing infrastructure.

Password spray

Look for repeated failed sign-ins across many accounts from common infrastructure.

Credential stuffing

Review repeated attempts using leaked credentials and previously used passwords.

Privilege escalation

Determine whether the attacker gained roles, group membership or application permissions after access.

Persistence

Look for authentication methods, app consent, inbox rules, federation changes and new credentials.

Lateral movement

Review whether the identity accessed other devices, shares, servers, applications or cloud resources.

Data access

Check SharePoint, OneDrive, Exchange, Purview and application activity for sensitive data access.

Timeline first

Build a chronological identity timeline from sign-in, audit, mailbox, endpoint and cloud evidence.

Separate confirmed and suspected

Do not label the account compromised until the evidence supports that conclusion.

Ask for alternative explanations

Compare attack hypotheses with legitimate travel, administration, automation and support activity.

Request missing evidence

Ask Copilot which logs, permissions or products are unavailable.

Use risk recommendations carefully

Copilot recommendations can guide mitigation but remain subject to policy and analyst approval.

Mark user compromised only with evidence

The action changes risk state and should reflect a validated investigation.

Confirm safe carefully

Dismiss risk only when the activity is understood and supported as legitimate.

Self-remediation

Risk-based Conditional Access can require MFA or secure password change to remediate risk.

Manual remediation

Administrators may need to reset credentials, revoke sessions, disable accounts or remove persistence.

Automatic attack disruption

Defender can automatically contain compromised identities during high-confidence active attacks.

Review automatic actions

Confirm why an identity was contained and whether the disruption remains appropriate.

Preserve evidence

Capture relevant sign-in, audit, mailbox and endpoint records before major remediation changes.

Coordinate with the user

Use a trusted communication channel to verify travel, device use, MFA prompts and recent actions.

Do not contact through a compromised channel

Avoid relying only on the suspected mailbox or Teams account for verification.

Document identity scope

Record accounts, sessions, devices, applications, roles and data known to be affected.

Document uncertainty

State clearly what remains unknown, especially around token theft and data access.

Close with monitoring

After remediation, monitor for repeated sign-ins, new persistence and related identity activity.

Example identity-investigation prompt

Investigate the identity risk for user alexw@contoso.com.

Use Microsoft Entra, Defender XDR and available Sentinel evidence.

Include:
1. User risk and sign-in risk detections
2. Suspicious sign-ins with IP, location, application, device and MFA details
3. Conditional Access results
4. Password, authentication-method, role, group and consent changes
5. Mailbox rules, forwarding and suspicious sent messages
6. Related endpoint and cloud activity
7. Confirmed facts, likely inference and legitimate alternatives
8. Evidence supporting or contradicting compromise
9. Recommended containment and investigation steps
10. Missing data and confidence level

Use one stated time zone and cite the source for every major finding.

Agent Foskett investigation: “The sign-in was impossible…”

Microsoft Entra flagged an impossible-travel sign-in

Security Copilot summarised the user as high risk

The account appeared in Australia and Singapore within minutes

The analyst prepared to disable the account

Agent Foskett checked the IP ownership

The Singapore address belonged to the organisation’s approved secure web gateway

The Australian address belonged to the user’s home internet connection

Both sign-ins used the same compliant corporate device

MFA and Conditional Access succeeded as expected

No password, authentication method, role or mailbox changes existed

Endpoint telemetry showed normal browser activity

The sign-in risk was confirmed safe

No account disablement was required

The risky event was real

The compromise was not
The location looked impossible until the network path was understood.

Identity-compromise validation checklist

AreaQuestionValidation action
IdentityIs the correct user or workload identity selected?Confirm object ID, tenant and account type.
RiskIs this user risk, sign-in risk or both?Review detections and history.
NetworkWho owns the IP and network path?Check VPN, proxy, carrier and gateway context.
AuthenticationHow was the sign-in authenticated?Review MFA, methods and Conditional Access.
DeviceWas the device known, compliant and managed?Confirm device identity and posture.
ChangesWere credentials, methods, roles or consent modified?Review Entra audit logs.
MailboxWere rules, forwarding or messages abused?Review Exchange and Defender evidence.
EndpointWas credential theft or malicious use observed?Review Defender device evidence.
ImpactWhat applications, resources or data were accessed?Validate cloud and Purview activity.
RemediationIs the proposed action supported and approved?Apply policy and record ownership.

Key takeaways

  • Microsoft Entra ID Protection detects and helps investigate user and sign-in risk.
  • Security Copilot can summarise risky users and provide investigation context and recommendations.
  • User risk and sign-in risk represent different questions and should not be confused.
  • IP location alone does not prove malicious access.
  • MFA success does not eliminate token theft or adversary-in-the-middle risk.
  • Audit logs reveal password, authentication-method, privilege and consent changes.
  • Mailbox, endpoint, Sentinel, cloud and data evidence can establish scope and impact.
  • Confirmed compromise, suspicious activity and legitimate explanations must be separated.
  • Remediation can include credential reset, session revocation, account disablement and persistence removal.
  • The analyst remains responsible for validating risk state and approving response.

What Agent Foskett checked

  • User and object ID
  • Risk detections
  • IP ownership
  • Device identity
  • MFA result
  • Conditional Access
  • Audit changes
  • Mailbox activity
  • Endpoint evidence
  • Final risk state

Best practices

  • Confirm the identity.
  • Separate user and sign-in risk.
  • Check network ownership.
  • Review MFA and sessions.
  • Inspect audit changes.
  • Correlate mailbox and endpoint evidence.
  • Build one timeline.
  • Preserve evidence.
  • Approve remediation.
  • Monitor after closure.

Related Agent Foskett resources

Continue through Module 2 and review the Entra and Defender learning paths that provide the underlying identity evidence.

Continue the Microsoft Security Copilot Academy

Lesson 12 investigates identity compromise across Entra and Defender. The next lesson focuses on endpoint incidents.
⬅ Previous lesson
Lesson 11 — Summarising Security IncidentsCreate validated attack stories, timelines and audience-specific reports.
🏠 Academy home
Microsoft Security Copilot AcademyReview the complete 40-lesson roadmap.
📚 Module 2
Lesson 13 — Investigating Endpoint IncidentsSummarise endpoint alerts, process trees, files, network activity, persistence and device timelines.

How do you investigate identity compromise with Microsoft Security Copilot?

Security Copilot can use Microsoft Entra and Defender identity context to summarise risky users, suspicious sign-ins, authentication methods, roles, risk detections and recommended investigation actions.

Microsoft Entra risky user investigation

Analysts should validate user risk, sign-in risk, IP ownership, MFA, Conditional Access, device context, audit changes and legitimate explanations before confirming compromise.

Identity compromise investigation workflow

A complete workflow correlates Entra, Defender XDR, Sentinel, mailbox, endpoint, cloud and data evidence before approved remediation and post-incident monitoring.