Microsoft Entra ID · Security & Compliance

Entra SOC Identity Responder

Perform identity containment actions for SOC incident response, including disabling users, revoking active sign-in sessions, and resetting passwords.

Scope: Tenant-wide identity containment actions (account disablement, session revocation, password resets) for incident response

Permissions

  • User Management - Disable and enable user accounts during active security incidents
  • Session Management - Force sign-out by invalidating user refresh tokens
  • Credential Management - Reset passwords for all users (privileged)
  • Incident Containment - Execute targeted identity containment from the Microsoft Defender portal
  • Limitation - Scoped to incident containment; cannot modify user profile attributes or security policies

Common use cases

  • SOC analyst performing immediate containment on compromised user accounts during an active incident
  • Revoking active sign-in sessions across devices for compromised identities
  • Resetting passwords for compromised users directly from the Microsoft Defender portal
  • Disabling compromised user accounts to prevent lateral movement during investigation

Best practices

  • Assign to Tier 2/3 SOC analysts and incident response personnel requiring containment capabilities
  • Enforce Just-in-Time (JIT) activation via Microsoft Entra Privileged Identity Management (PIM)
  • Require phishing-resistant Multi-Factor Authentication (MFA) and ticket justification for activation
  • Coordinate with identity administration teams when accounts are ready to be re-enabled or offboarded
  • Monitor audit logs for invalidateAllRefreshTokens and password reset operations

Security considerations

  • Privileged role with capability to reset passwords and revoke active sessions for any user
  • Incorrect containment actions can disrupt legitimate user productivity during incident investigation
  • Requires rigorous auditing and alert monitoring on password reset and session revocation actions

Common questions

When should I assign the Entra SOC Identity Responder role?

Assign Entra SOC Identity Responder when you need to: SOC analyst performing immediate containment on compromised user accounts during an active incident; Revoking active sign-in sessions across devices for compromised identities; Resetting passwords for compromised users directly from the Microsoft Defender portal; and Disabling compromised user accounts to prevent lateral movement during investigation. It is part of Microsoft Entra ID and should be granted as a least-privilege alternative to broader roles like Global Administrator.

What can someone with the Entra SOC Identity Responder role do?

The Entra SOC Identity Responder role grants permissions including: User Management - Disable and enable user accounts during active security incidents; Session Management - Force sign-out by invalidating user refresh tokens; Credential Management - Reset passwords for all users (privileged); Incident Containment - Execute targeted identity containment from the Microsoft Defender portal; and Limitation - Scoped to incident containment; cannot modify user profile attributes or security policies. See the Permissions section above for the full list.

What are the security risks of the Entra SOC Identity Responder role?

Key considerations when assigning Entra SOC Identity Responder: Privileged role with capability to reset passwords and revoke active sessions for any user; Incorrect containment actions can disrupt legitimate user productivity during incident investigation; and Requires rigorous auditing and alert monitoring on password reset and session revocation actions. Review the Security considerations section before assignment, and pair with Privileged Identity Management (PIM) for just-in-time access where possible.

Official Microsoft Learn documentation →

Open the interactive RBACMap →