Azure Security Incident Investigation: Sentinel, Entra, and Defender

Azure security incident investigation requires connecting Identity, Audit Logs, API actions, resources, Regions, and Sessions. Start by preserving evidence and building a Timeline, then perform documented Containment.
Cloud investigation requires connecting identities, Control Plane, resources, keys, Sessions, and security services. Since activity is distributed across services and regions, a Timeline and understanding permissions are critical. This article focuses on Azure security incident investigation and is intended for SOC and Cloud analysts. The goal is to provide a working methodology that can be applied in practice, during professional interviews, and in a work environment, without settling for a dictionary definition.
The main challenge is that data is almost always partial. Microsoft Sentinel, Entra sign-ins, and Activity Logs can indicate a direction, but their meaning depends on time, asset, user, and expected activity. Therefore, we will build the investigation around an investigative question, required evidence, and a clear completion criterion.
The practical scenario in the article is: a scenario of unusual permission and resource change. All examples are laboratory data or process descriptions. When dealing with Penetration Testing, Web, or Cloud, one must work only with explicit permission, a defined Scope, and the ability to stop the test.




