Microsoft 365 Incident Response Runbook: First 60 Minutes After a Compromised Account (2026)
Field notes on the first sixty minutes of Microsoft 365 incident response: triage, containment, blast radius mapping, evidence preservation and communication.
Microsoft Purview DLP + Power Automate: Automated Response to Policy Violations
Microsoft Purview DLP can now trigger Power Automate flows the moment a policy violation happens. This article shows how to build automated response workflows for alerting, logging, and remediation without treating DLP as a manual queue.