Skip to content
← Back to the guide

Microsoft 365 incident response runbook

4slides. Screenshot a slide, download it as a PNG, or use your browser's Print → Save as PDF for a LinkedIn-ready multi-page carousel — each slide becomes one page.

M
solvingmicrosoft365.com
1 / 4

Microsoft 365 incident response runbook

A structured incident response runbook for Microsoft 365 — detection, triage, containment, eradication, recovery, lessons.

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/microsoft-365-incident-response

Slide 1Download PNG
M
solvingmicrosoft365.com
2 / 4
01

What should a Microsoft 365 incident response plan cover?

Who is on call and which roles they hold, the containment runbooks (compromised account, phishing wave, ransomware in SharePoint, mass deletion, external-sharing exposure), where the logs are and how long they last, the…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/microsoft-365-incident-response

Slide 2Download PNG
M
solvingmicrosoft365.com
3 / 4
02

Which Microsoft 365 logs do incident responders need?

The unified audit log (actions), Entra sign-in logs including non-interactive (sessions), Defender XDR incidents and advanced hunting tables, Exchange message trace, and — if licensed — Defender for Cloud Apps activity.…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/microsoft-365-incident-response

Slide 3Download PNG
M
solvingmicrosoft365.com
4 / 4
03

Can Microsoft help during an incident?

Microsoft Support handles service issues; the Detection and Response Team (DART, now Microsoft Incident Response) is a paid engagement for serious compromises; Defender Experts is a subscription for managed detection. P…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/microsoft-365-incident-response

Slide 4Download PNG

Auto-generated from Microsoft 365 incident response runbook. This page is not indexed and isn't part of the guide itself.