Group Purchasing
Group Purchasing

Harnessing Entra ID Snapshots for Effective Post-Security Incident Detection and Containment

Harnessing Entra ID Snapshots for Effective Post-Security Incident Detection and Containment (PDF, 1.07MB)Published: 03 Mar, 2025
Created by:
David Fletcher

The techniques employed by advanced persistent threats (APTs) necessitate an adaptive incident response strategy. With cyber-attacks increasing in complexity and frequency, security incident responders must detect and contain threats swiftly.

This study explores the incorporation of identity snapshots as part of a defense-in-depth strategy and the effectiveness of snapshots in assisting incident responders. Periodic identity snapshots enhanced the accuracy and confidence of incident responders when detecting and containing threats within an organization's identity provider. By maintaining a scheduled log of identities, incident responders can compare the state of identities before and after a compromise, facilitating more targeted investigations. Although identity snapshots are not a comprehensive solution for all threat actors, they serve as a valuable supplementary tool for investigating identity providers such as Entra ID.

This research focuses on implementing identity snapshots within Microsoft's Azure Entra ID, demonstrating their potential to significantly enhance the efficiency and effectiveness of post-incident detection and containment.