SOP-04: Account Compromise & Impossible Travel

Analyst playbook for account compromise and impossible travel alerts. Covers KQL-based travel math, inbox rule and MFA change detection, full Entra ID containment sequence, OAuth consent grant revocation, and safe recovery gate.

2026-06-15T02:57:59.326Z
Rudra Verma, Senior Security Architect & Researcher