Free Tech Experience: 15-Minute IT SecurityΒ Ticket


Estimated Time:
15–20 minutes
Ticket: IT-0001
Status: Open
Priority: Critical
Assigned To: You

Subject: Compromised Account β€” Stolen Devices

The Situation
It's 8:47 AM. Sterling Mutual's security team just received a call from David Cho in Client Services: his laptop bag β€” company laptop and phone inside β€” was stolen from his car overnight.

Both devices were signed into his corporate account. Whoever has them may right now have access to company email, client files, and internal systems.

Every minute those sessions stay alive is a minute an attacker could be reading client data.

Your Mission

Contain the breach:

  1. Kill every active session (kick the stolen devices out now)
  2. Lock the account (nobody signs in until this is resolved)
  3. Wipe his MFA registration (his authenticator was on the stolen phone β€” it can't be trusted)

Portal: entra.microsoft.com

Your Credentials
β€” choose any available account:
support1@sterlingmutual.onmicrosoft.com

support2@sterlingmutual.onmicrosoft.com

support3@sterlingmutual.onmicrosoft.com
support4@sterlingmutual.onmicrosoft.com
support5@sterlingmutual.onmicrosoft.com

Password: SecureTheBreach!

Important Notices

Authentication: You are using a real Microsoft 365 environment. You may be required to complete a one-time MFA setup upon your first login. Click here for additional instructions.

Automated Reset: These accounts are part of an automated lifecycle. Every hour on the hour, the system automatically wipes all MFA methods, revokes all sessions, and resets passwords to ensure a secure, fresh environment for everyone.

Timing: If you are within the last 15 minutes of the hour, please wait for the top of the hour to begin your ticket to ensure you have enough time to finish before the reset.


SOP: Standard Operating Procedure

Real IT work isn't memorizing buttons β€” it's following documentation under pressure. Here's yours.

Step 1 β€” Locate the User
Log into entra.microsoft.com with your support account. Left menu: Users β†’ All users. Search David Cho, click his name.

Why: Every incident starts with finding the affected identity. In a company of thousands, search is your best friend.

Step 2 β€” Kill Active Sessions
At the top of David's profile, click Revoke sessions and confirm.

Why this comes first: the stolen devices are signed in right now. Revoking sessions instantly disconnects them from email, files, and Teams β€” this is the "slam the door" move, and in a real breach, seconds matter.

Step 3 β€” Lock the Account
On David's Overview page, find the Account status card (under "My Feed"). Click Edit, uncheck Account enabled, click Save.

Why: sessions are dead, but the thief may have his password. Disabling sign-in means even correct credentials won't work until the account is restored.

Step 4 β€” Wipe the MFA
On the left menu of David's profile, click Authentication methods, then Require re-register multifactor authentication.

Why: his authenticator app lived on the stolen phone. When David's account is restored, he must prove his identity fresh on a device he controls.

Before closing the ticket, confirm:

  • Sessions revoked
  • Sign-in disabled
  • MFA re-registration required

Ticket complete!Β 
You just contained a compromised account in a live Microsoft enterprise environment β€” the same steps, in the same portal, that IT and security teams run in real incidents. This is now something you've done, not something you've read about.

Submit Ticket