What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

If you suspect a SharePoint compromise, open an incident, follow your organization’s approval and incident-command process, and contain the affected identity and sessions while preserving evidence. Then use Microsoft Entra sign-in records and Microsoft Purview audit records to determine what happened, remove the attacker’s access path, and recover only from a known-good state. A password reset or the return of deleted files alone does not establish that the incident is resolved.

1. Open the incident and establish authority

Record when the suspicion arose, the affected user or workload, the indicators that prompted concern, and who owns the response. Follow your organization’s incident command, legal, privacy, and approval processes; notification and evidence-handling obligations depend on your circumstances and jurisdiction.

Before disabling an identity or rotating credentials, check what kind of identity it is and what it supports. A break-glass account, service principal, or sensitive executive account may require a different approval path or coordinated containment to avoid disrupting critical services. Microsoft’s Create a compromised identity incident response SOP template advises responders to “Contain the risk before you complete the full investigation, but apply organization-specific approval logic first.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Contain access and preserve initial evidence

Once authorized, reduce the attacker’s ability to keep using the identity. Actions should fit the identity type and available evidence; coordinate changes that could interrupt business-critical services.

#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
  • Revoke active user sessions and refresh tokens. Reset the user’s password, or rotate the relevant secret for a non-user identity, as appropriate.
  • If active risk remains, temporarily disable the user when business approval allows it. Block known malicious IP addresses, devices, applications, or tokens when those controls are available and relevant.
  • Preserve incident IDs, alerts, sign-in screenshots or exports, and user statements. Record when each item was captured and retain the original exports where possible.
  • Do not treat a password change as proof that access is contained. Investigate other access or persistence routes indicated by the evidence, including sessions, authentication changes, applications, and privileged access.

Keep a contemporaneous record of containment actions, their times, and who approved them. Follow your organization’s legal-hold, privacy, and evidence-handling requirements. Microsoft’s guidance gives examples of evidence and investigation steps, but does not establish a universal chain-of-custody procedure.

3. Establish the identity timeline and likely access path

Review successful Microsoft Entra sign-ins around the suspected start of the incident. Compare the first successful sign-in that appears suspicious with alert times and the user’s account of events. Microsoft recommends assessing details such as time, IP address or location, device, application, MFA result, and recent authentication-method changes.

Look for a timeline that explains how the access began and continued. Phishing, reused passwords, adversary-in-the-middle activity, stolen tokens, and MFA fatigue are possible hypotheses—not findings. Treat one as a cause only when the evidence supports it. Also assess whether the identity could access other Microsoft 365 services, devices, applications, cloud resources, or privileged roles; a SharePoint alert may be only one part of the incident.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

4. Find which SharePoint content was accessed or changed

Search Microsoft Purview audit records for the affected user, the SharePoint Online workload, and the incident timeframe. Examine records for file access, creation, modification, and deletion, then identify affected sites and content. Export relevant results and preserve the search filters and date range so another responder can understand how the scope was determined.

Audit search requires the Audit Logs or View-Only Audit Logs role. The records may include IP and client information, but coverage, availability, retention, and permissions depend on tenant configuration and licensing. Verify what the affected tenant actually retains; do not assume that every customer has identical audit data.

If you suspect a stolen token, Microsoft documents correlating Entra sign-in activity with SharePoint Online audit activity using the Session ID (SID) or Unique Token Identifier (UTI). Search the relevant timeframe and workload, filter for the affected user and identifiers, and compare the resulting events. This can help associate file access or modification with the session under investigation, but it does not by itself prove who operated the session.

Rank #3
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

Expand the investigation when the identity’s permissions or the evidence point beyond SharePoint. Include related identities, devices, applications, privileged roles, and other services the account could reach. Keep the scope tied to observed access and plausible access paths rather than assuming that every available resource was affected.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

5. Remove the access path before restoring

Identify and address the cause and any persistence route supported by the evidence. Depending on the incident, that may mean securing credentials, invalidating exposed tokens, reversing unauthorized authentication changes, removing a malicious application, or correcting excessive permissions. Microsoft describes eradication as evicting the adversary and mitigating the vulnerability that enabled re-entry.

Confirm that the known vulnerable paths have been eliminated before treating the environment as ready for restoration. A file restore cannot remove an attacker’s access, and restoring content into an environment with the same exposed access path can leave it vulnerable again.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

6. Choose a recovery route based on what happened

First establish whether the content is in a recycle bin, was hard-deleted, or is present but corrupted or affected by malware. Check the item, site, elapsed time, applicable retention policies, and the confidence you have in the proposed clean state. Preserve evidence before taking cleanup actions; emptying a recycle bin can destroy material needed for recovery or investigation.

Situation Potential route What to verify
Item remains in its original site’s first-stage Recycle Bin Restore the item from that bin. Confirm the item is the affected content and that returning it will not reintroduce malicious or unwanted material.
Item has moved to the second-stage (site-collection) Recycle Bin Restore it from the second-stage bin if it remains there. Microsoft’s 2026 deletion guidance says an item deleted from its original location remains in the site Recycle Bin for 93 days unless someone removes it from that bin or empties it; it can then reside in the second-stage bin for the remainder of the retention period. Verify the actual item and tenant context.
Content was hard-deleted, corrupted, or affected by malware and cannot be recovered through other methods Ask Microsoft Support promptly about a full site-collection or subsite point-in-time restore. Microsoft’s 2026 documentation describes an additional 14-day backup period beyond actual deletion for this support-assisted restore route and says it is unavailable after that period. It is not a guaranteed self-service restore; confirm eligibility for the case.
Content is still present but altered, or a broader site recovery is being considered Evaluate the suitable SharePoint recovery mechanism for the item or site, using a known-good state. Compare the affected scope, recovery point, business impact, and evidence-preservation needs. The appropriate mechanism and availability depend on the incident and tenant.

Microsoft says that purging an item from the second-stage Recycle Bin permanently removes it. Some API delete operations can also purge content directly instead of routing it through the recycle bins. Do not empty bins during an incident unless that is an intentional, approved part of the response.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For any proposed restore, confirm what will be restored and from when, whether the recovery point is known-good, and whether the action could overwrite useful evidence or affect unaffected users. Validate the restored content and permissions against the intended state; a successful restore is not, by itself, evidence that the incident has ended.

7. Validate recovery and watch for recurrence

After restoration, inspect the affected content and access permissions, then verify that the entry and persistence routes identified during the investigation remain closed. Continue heightened monitoring for suspicious sign-ins, authentication-method changes, unexpected applications or permissions, and renewed file access or changes. The monitoring period and escalation thresholds should follow your organization’s incident plan and the risks found in the case.

Document the impact, evidence reviewed, unresolved uncertainties, containment and recovery actions, and the basis for closing or escalating the incident. If audit coverage is incomplete or the suspected deletion exceeds the documented restore window, record that limitation plainly and consult the appropriate internal teams or Microsoft Support rather than assuming the content is recoverable.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.