Access is one part of the scope
An incident can leave changes beyond the original session. A useful review considers how access was used and whether anything added during that period could still matter.
Look at the connected changes
Microsoft’s compromised-account guidance includes sessions, authentication methods, application consent, administrative roles, forwarding, and inbox rules. These are connected parts of the investigation rather than interchangeable checks. Follow your organisation’s incident-response procedures when reviewing and remediating them.
Keep an account of the response
Record the evidence behind each finding, the action taken, and the questions that remain. This gives the next person reviewing the incident something more useful than a closed alert.
The Sentry perspective
Sentry connects automated remediation to incident scope, evidence, and response policy. A response should be understandable as well as timely.