Your organization uses Microsoft 365 E5 and experiences a security incident where a user's account is compromised. You need to immediately prevent the attacker from accessing Microsoft 365 services while preserving the user's data for investigation. Which action should you take?
Blocking sign-in in Microsoft Entra ID flips the user account to a disabled state (Sign-in enabled = No), which immediately rejects all new authentication requests for Entra ID and Microsoft 365 services. This prevents the attacker from obtaining any additional access tokens, and while previously issued tokens may remain technically valid until expiration, most resource access attempts will fail on the next revalidation. Crucially, this action preserves all user data such as mailbox and OneDrive contents, allowing forensic investigation without any deletion of evidence.
Why this answer
Blocking sign-in for the user in Microsoft Entra ID immediately prevents the attacker from authenticating to any Microsoft 365 service, while the user's data remains intact in Exchange Online, SharePoint, and OneDrive for forensic analysis. This action does not delete or alter any data, preserving the full investigation trail.
Exam trap
The trap here is that candidates confuse 'revoke sessions' (which only kills current sessions but allows re-authentication) with 'block sign-in' (which prevents all future authentication), leading them to choose Option C as a quick fix without realizing the attacker can simply log back in.
How to eliminate wrong answers
Option B is wrong because deleting the user account permanently removes the user object and all associated data (mailbox, OneDrive files, SharePoint access) from Microsoft 365, destroying evidence needed for investigation. Option C is wrong because revoking sessions only terminates active tokens and sessions but does not prevent the attacker from re-authenticating with the compromised credentials, leaving the account still vulnerable. Option D is wrong because resetting the password alone does not invalidate existing refresh tokens or active sessions; the attacker could still use cached tokens or non-expired sessions to access services until those tokens expire or are explicitly revoked.