Containment operations
Containment Aid+
Aid+ workspace
Aid+ overview
Containment workflows
Identity and SaaS response| Workflow | Mass compromise focus | Evidence priority | Action |
|---|---|---|---|
| Azure and M365 Containment Check | Review Entra ID, Azure and Microsoft 365 containment actions for both targeted and mass compromise scenarios, including bulk user scoping, service principals, consent abuse, legacy auth, mailbox abuse and audit evidence. | Sessions, new users, apps, auth APIs, admin activity and audit exports | Open |
| Okta Containment Check | Review Okta containment actions for both single-user and mass compromise scenarios, including bulk user scoping, session revocation, MFA, admin role abuse, suspicious apps, OAuth grants, network zones and System Log evidence. | Sessions, new users, apps, auth APIs, admin activity and audit exports | Open |
| Salesforce Containment Check | Review Salesforce containment actions for both single-user and tenant-scale incidents, including bulk user scoping, session revocation, connected apps, OAuth, audit trails, Event Monitoring, jobs and export evidence. | Sessions, new users, apps, auth APIs, admin activity and audit exports | Open |
Response timeline
Confirm affected tenants, users, service principals, connected apps and suspicious API/auth events.
Revoke sessions, block risky apps, reset credentials at scale and isolate affected integrations.
Export audit, sign-in, mailbox, job and SaaS activity before retention windows expire.
Expected outputs
- Containment readiness review
- Tenant-scale incident action plan
- Evidence export checklist
- Executive and technical response outputs