Your company uses Microsoft Defender for Identity to monitor on-premises Active Directory. You receive an alert about a potential lateral movement attack involving a service account. The alert indicates that the account was used to log in to multiple servers from a non-domain-joined machine. You need to investigate the alert and determine if the account is compromised. What should you do first?
Reviewing the activity timeline provides a detailed record of all logins and accessed resources, enabling you to trace the lateral movement and decide on next steps. This is the correct first action.
Why this answer
The correct first step because Microsoft Defender for Identity provides an activity timeline for each account, allowing you to review all logins, resources accessed, and other suspicious activities. This helps determine if the account is compromised before taking any action. Option A is incorrect because the account may be a member of privileged groups, but that alone does not confirm compromise; the activity timeline provides more context.
Option B is incorrect because immediately resetting the password could disrupt legitimate operations and destroy evidence. Option D is incorrect because the user of a service account is typically not a person, and lateral movement alerts indicate automated or unauthorized behavior, so contacting a user is not appropriate.