Containment operations

Containment Aid+

Aid+ workspace Aid+ overview
Affected usersBulk
Evidence exportTracked
Containment modeTenant-scale
Platforms3

Containment workflows

Identity and SaaS response
WorkflowMass compromise focusEvidence priorityAction
Azure and M365 Containment Check Review Entra ID, Azure and Microsoft 365 containment actions for both targeted and mass compromise scenarios, including bulk user scoping, service principals, consent abuse, legacy auth, mailbox abuse and audit evidence. Sessions, new users, apps, auth APIs, admin activity and audit exports Open
Okta Containment Check Review Okta containment actions for both single-user and mass compromise scenarios, including bulk user scoping, session revocation, MFA, admin role abuse, suspicious apps, OAuth grants, network zones and System Log evidence. Sessions, new users, apps, auth APIs, admin activity and audit exports Open
Salesforce Containment Check Review Salesforce containment actions for both single-user and tenant-scale incidents, including bulk user scoping, session revocation, connected apps, OAuth, audit trails, Event Monitoring, jobs and export evidence. Sessions, new users, apps, auth APIs, admin activity and audit exports Open

Response timeline

Scope

Confirm affected tenants, users, service principals, connected apps and suspicious API/auth events.

Contain

Revoke sessions, block risky apps, reset credentials at scale and isolate affected integrations.

Evidence

Export audit, sign-in, mailbox, job and SaaS activity before retention windows expire.

Expected outputs

  • Containment readiness review
  • Tenant-scale incident action plan
  • Evidence export checklist
  • Executive and technical response outputs