A user reports that they cannot access their Microsoft 365 apps after clicking a link in an email. You suspect token theft. In Microsoft Defender XDR, which incident investigation action should you take first to verify the scope?
Sign-in logs in Microsoft Entra ID reveal the authentication events tied to the suspected token theft, showing anomalous locations, IP addresses and session details. Reviewing them first establishes which accounts and sessions are affected, defining the incident scope before deeper investigation.
Why this answer
When token theft is suspected, the first investigative step is to determine scope by reviewing the user's sign-in logs in Microsoft Entra ID for anomalous locations, IPs, or impossible-travel patterns. This confirms whether the token was used from an unexpected location and helps identify other affected accounts before taking containment actions. Verifying scope precedes remediation.
Exam trap
SC-200 often tests the order of operations in incident response, and candidates who jump to containment (isolate device) before scoping (review sign-in logs) fall into the trap of acting before understanding the incident's breadth.
How to eliminate wrong answers
Option B is wrong because isolating the device is a containment action that should follow scope verification—if the token was stolen and used elsewhere, isolating the user's device may not address the attacker's access. Option C is wrong because checking for malware is a device-focused investigation that may be relevant but does not first establish the scope of the token theft across identities. Option D is wrong because investigating the email in Defender for Office 365 examines the delivery vector, not the scope of the compromised token or affected accounts.