Cloud account compromise

The visible artifact is rarely the mechanism. Removing it and resetting the password feels like a response and frequently is not one.

Trigger. Impossible travel, an unrecognised inbox rule, or a reported invoice-fraud attempt.

The first 60 minutes2 of 5 expire
030 min60
  1. 01

    Revoke sessions first, then reset the password

    by 10 min

    In that order. Reversing them leaves a window in which the old refresh token still works. Then reset, then enrol MFA.

  2. 02

    Enumerate OAuth grants and service principals

    by 20 min

    This is the step that is usually skipped and usually the actual mechanism. A consent grant with offline_access survives the password reset, the MFA enrolment and the rule deletion, because it never meets a login prompt.