Microsoft Incident Response tips for managing a mass password reset
ID: 08cc2881-9554-54e6-b263-0c3eed72badd
STIX ID: report--08cc2881-9554-54e6-b263-0c3eed72badd
Feed Name: Microsoft Security
This Microsoft Security blog outlines best practices for conducting mass password resets during incident response, emphasizing the surge in password-based attacks and the need to balance rapid containment with user disruption. It contrasts user-driven and admin-driven reset approaches and recommends layered defenses like Conditional Access, SSPR, Privileged Identity Management, multifactor authentication, and passwordless methods (e.g., FIDO2, passkeys) to secure identities and critical accounts. The guidance focuses on strengthening identity security posture and operational readiness rather than describing a specific incident or campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
