Lesson 12 — Investigating Identity Compromise
Identity incidents rarely begin and end with one risky sign-in.
A complete investigation can involve user risk, authentication methods, MFA, Conditional Access, audit changes, privileged roles, mailbox activity, endpoint evidence, cloud access and session abuse.
This lesson explains how Security Copilot supports Microsoft Entra and Defender identity investigations while the analyst validates every sign-in, change, relationship and remediation decision.

What you will learn
This lesson develops a complete identity-compromise investigation across Microsoft Entra and Defender.
Identity-compromise investigation workflow
↓
Confirm the exact identity and tenant
↓
Generate the Copilot risk or identity summary
↓
Review user risk, sign-in risk and detections
↓
Validate IP, location, application, device, MFA and Conditional Access
↓
Review audit changes, roles, consent and authentication methods
↓
Correlate mailbox, endpoint, Sentinel and cloud evidence
↓
Build a single chronological identity timeline
↓
Separate confirmed compromise, suspicious activity and legitimate context
↓
Apply approved remediation
↓
Monitor for persistence and repeated activity
Identity evidence domains
| Domain | Evidence | Investigation question |
|---|---|---|
| Sign-in evidence | IP, location, application, client, device, MFA and Conditional Access. | Was the authentication malicious or legitimate? |
| User risk | Risk detections, history, criticality and identity context. | Is the identity likely compromised? |
| Audit evidence | Password, methods, roles, groups, consent and policy changes. | Did the attacker establish persistence or privilege? |
| Mailbox evidence | Rules, forwarding, delegate access and sent messages. | Was the identity used for email abuse? |
| Endpoint evidence | Processes, browsers, credentials, alerts and device activity. | Was the account used from or stolen on a device? |
| Cloud and data evidence | Applications, resources, files and sensitive data access. | What did the identity access after compromise? |
Learning objectives
- Distinguish user risk from sign-in risk.
- Investigate suspicious authentication and MFA.
- Review audit, privilege and consent changes.
- Correlate mailbox and endpoint evidence.
- Build an identity timeline.
- Validate remediation actions.
- Document confidence and uncertainty.
What is identity compromise?
Identity compromise occurs when an attacker gains or abuses authentication material, sessions, permissions or account access.
User risk versus sign-in risk
User risk reflects the likelihood an identity is compromised, while sign-in risk reflects the likelihood a specific authentication attempt is malicious.
Start with the risky user
Use Microsoft Entra ID Protection and Security Copilot to summarise why the user risk level was elevated.
Risk summary is orientation
The Copilot summary helps prioritise evidence but does not prove compromise.
Confirm the identity
Verify the exact user, object ID, tenant, role, department and account type before correlating activity.
Review identity criticality
Privileged, service and business-critical identities require heightened urgency and stronger review.
Review sign-in history
Compare suspicious sign-ins with the user’s normal locations, devices, applications and authentication patterns.
Check IP ownership
Identify whether the source belongs to a VPN, proxy, mobile carrier, cloud provider, corporate network or malicious infrastructure.
Check location carefully
Geographic distance can be misleading when VPNs, proxies, mobile networks or token replay are involved.
Check application context
Confirm which application, resource and client type were involved in the sign-in.
Check authentication method
Review password, MFA, passwordless, certificate and federated authentication evidence.
Check MFA details
Determine whether MFA succeeded, failed, was interrupted, bypassed or completed by an unexpected method.
Check authentication strength
Confirm whether the sign-in met the intended Conditional Access authentication strength.
Check Conditional Access
Review policies applied, not applied, interrupted or reported in the sign-in record.
Check device context
Confirm device ID, compliance, management, trust type, operating system and browser.
Check session context
Review session identifiers, token use, refresh activity and evidence of session theft or replay.
Check risk detections
Review the specific Entra detections that contributed to user or sign-in risk.
Check risk timing
Some detections occur in real time while others appear after offline analysis.
Check risk state
Understand whether the risk is at risk, confirmed compromised, remediated, dismissed or confirmed safe.
Check risk history
Review changes to risk state and previous detections for the identity.
Review audit logs
Look for password resets, authentication-method changes, group changes, app consent and policy modifications.
Authentication method changes
New phone numbers, FIDO2 keys, passkeys or authenticator registrations can indicate persistence.
Password changes
Determine who changed the password, when it occurred and whether it was expected.
Session revocation
Confirm whether refresh tokens and active sessions were revoked during response.
Privilege changes
Review directory roles, PIM activations, group membership and privileged assignments.
Service principal activity
Investigate application identities separately from human user accounts.
Consent grants
Check delegated and application consent for unexpected OAuth permissions.
Mailbox evidence
Review inbox rules, forwarding, delegate access, sent mail and suspicious message activity.
Compromised email behaviour
Attackers may use a compromised mailbox to send internal or external phishing.
Endpoint evidence
Correlate identity activity with device alerts, process execution, browser behaviour and credential theft.
Defender identity summary
Microsoft Copilot in Defender can summarise account creation, criticality, roles, sign-in patterns, methods and Entra risks.
Defender user page
Use the identity entity page to pivot across alerts, devices, sessions and related activity.
Sentinel correlation
Use Sentinel to connect identity events with broader network, application and cloud telemetry.
Advanced hunting
Use KQL to verify sign-ins, identity changes, endpoint activity and related alerts.
Normal behaviour baseline
Compare suspicious activity with known user behaviour rather than relying on rarity alone.
Travel context
Check approved travel, remote work, business schedules and known device use.
Impossible travel limitations
Do not treat an impossible-travel detection as proof without checking VPN and session context.
Legacy authentication
Review legacy authentication because it can bypass modern controls and indicate password abuse.
Token theft
A stolen token can allow access without a new password or visible MFA challenge.
MFA fatigue
Repeated MFA prompts followed by acceptance may indicate push-bombing or social engineering.
Adversary-in-the-middle
Session theft can occur after successful MFA through phishing infrastructure.
Password spray
Look for repeated failed sign-ins across many accounts from common infrastructure.
Credential stuffing
Review repeated attempts using leaked credentials and previously used passwords.
Privilege escalation
Determine whether the attacker gained roles, group membership or application permissions after access.
Persistence
Look for authentication methods, app consent, inbox rules, federation changes and new credentials.
Lateral movement
Review whether the identity accessed other devices, shares, servers, applications or cloud resources.
Data access
Check SharePoint, OneDrive, Exchange, Purview and application activity for sensitive data access.
Timeline first
Build a chronological identity timeline from sign-in, audit, mailbox, endpoint and cloud evidence.
Separate confirmed and suspected
Do not label the account compromised until the evidence supports that conclusion.
Ask for alternative explanations
Compare attack hypotheses with legitimate travel, administration, automation and support activity.
Request missing evidence
Ask Copilot which logs, permissions or products are unavailable.
Use risk recommendations carefully
Copilot recommendations can guide mitigation but remain subject to policy and analyst approval.
Mark user compromised only with evidence
The action changes risk state and should reflect a validated investigation.
Confirm safe carefully
Dismiss risk only when the activity is understood and supported as legitimate.
Self-remediation
Risk-based Conditional Access can require MFA or secure password change to remediate risk.
Manual remediation
Administrators may need to reset credentials, revoke sessions, disable accounts or remove persistence.
Automatic attack disruption
Defender can automatically contain compromised identities during high-confidence active attacks.
Review automatic actions
Confirm why an identity was contained and whether the disruption remains appropriate.
Preserve evidence
Capture relevant sign-in, audit, mailbox and endpoint records before major remediation changes.
Coordinate with the user
Use a trusted communication channel to verify travel, device use, MFA prompts and recent actions.
Do not contact through a compromised channel
Avoid relying only on the suspected mailbox or Teams account for verification.
Document identity scope
Record accounts, sessions, devices, applications, roles and data known to be affected.
Document uncertainty
State clearly what remains unknown, especially around token theft and data access.
Close with monitoring
After remediation, monitor for repeated sign-ins, new persistence and related identity activity.
Example identity-investigation prompt
Use Microsoft Entra, Defender XDR and available Sentinel evidence.
Include:
1. User risk and sign-in risk detections
2. Suspicious sign-ins with IP, location, application, device and MFA details
3. Conditional Access results
4. Password, authentication-method, role, group and consent changes
5. Mailbox rules, forwarding and suspicious sent messages
6. Related endpoint and cloud activity
7. Confirmed facts, likely inference and legitimate alternatives
8. Evidence supporting or contradicting compromise
9. Recommended containment and investigation steps
10. Missing data and confidence level
Use one stated time zone and cite the source for every major finding.
Agent Foskett investigation: “The sign-in was impossible…”
↓
Security Copilot summarised the user as high risk
↓
The account appeared in Australia and Singapore within minutes
↓
The analyst prepared to disable the account
↓
Agent Foskett checked the IP ownership
↓
The Singapore address belonged to the organisation’s approved secure web gateway
↓
The Australian address belonged to the user’s home internet connection
↓
Both sign-ins used the same compliant corporate device
↓
MFA and Conditional Access succeeded as expected
↓
No password, authentication method, role or mailbox changes existed
↓
Endpoint telemetry showed normal browser activity
↓
The sign-in risk was confirmed safe
↓
No account disablement was required
↓
The risky event was real
↓
The compromise was not
Identity-compromise validation checklist
| Area | Question | Validation action |
|---|---|---|
| Identity | Is the correct user or workload identity selected? | Confirm object ID, tenant and account type. |
| Risk | Is this user risk, sign-in risk or both? | Review detections and history. |
| Network | Who owns the IP and network path? | Check VPN, proxy, carrier and gateway context. |
| Authentication | How was the sign-in authenticated? | Review MFA, methods and Conditional Access. |
| Device | Was the device known, compliant and managed? | Confirm device identity and posture. |
| Changes | Were credentials, methods, roles or consent modified? | Review Entra audit logs. |
| Mailbox | Were rules, forwarding or messages abused? | Review Exchange and Defender evidence. |
| Endpoint | Was credential theft or malicious use observed? | Review Defender device evidence. |
| Impact | What applications, resources or data were accessed? | Validate cloud and Purview activity. |
| Remediation | Is the proposed action supported and approved? | Apply policy and record ownership. |
Key takeaways
- Microsoft Entra ID Protection detects and helps investigate user and sign-in risk.
- Security Copilot can summarise risky users and provide investigation context and recommendations.
- User risk and sign-in risk represent different questions and should not be confused.
- IP location alone does not prove malicious access.
- MFA success does not eliminate token theft or adversary-in-the-middle risk.
- Audit logs reveal password, authentication-method, privilege and consent changes.
- Mailbox, endpoint, Sentinel, cloud and data evidence can establish scope and impact.
- Confirmed compromise, suspicious activity and legitimate explanations must be separated.
- Remediation can include credential reset, session revocation, account disablement and persistence removal.
- The analyst remains responsible for validating risk state and approving response.
What Agent Foskett checked
- User and object ID
- Risk detections
- IP ownership
- Device identity
- MFA result
- Conditional Access
- Audit changes
- Mailbox activity
- Endpoint evidence
- Final risk state
Best practices
- Confirm the identity.
- Separate user and sign-in risk.
- Check network ownership.
- Review MFA and sessions.
- Inspect audit changes.
- Correlate mailbox and endpoint evidence.
- Build one timeline.
- Preserve evidence.
- Approve remediation.
- Monitor after closure.
Related Agent Foskett resources
Continue the Microsoft Security Copilot Academy
How do you investigate identity compromise with Microsoft Security Copilot?
Security Copilot can use Microsoft Entra and Defender identity context to summarise risky users, suspicious sign-ins, authentication methods, roles, risk detections and recommended investigation actions.
Microsoft Entra risky user investigation
Analysts should validate user risk, sign-in risk, IP ownership, MFA, Conditional Access, device context, audit changes and legitimate explanations before confirming compromise.
Identity compromise investigation workflow
A complete workflow correlates Entra, Defender XDR, Sentinel, mailbox, endpoint, cloud and data evidence before approved remediation and post-incident monitoring.
