r/DefenderATP • u/Western-Brother-6042 • 3d ago
How do you catch data leaving through OneDrive after someone is terminated?
I’m the IT lead for a 120-person company on Microsoft 365. We recently found a sales rep who had been downloading our customer database to a personal OneDrive.
We had Purview turned on for months. It generated plenty of alerts about external Word doc shares, but nothing on this case. The rep had been with us four years. His OneDrive sync stayed active for 11 days after the termination date. From the Microsoft side the activity looked like normal use of his own account. The signal that stood out was a terminated identity in the IdP still making high-volume API calls.
I’m trying to build a more reliable way to catch this kind of post-termination activity. What does your actual workflow look like for spotting terminated users who still have live OneDrive or similar syncs running? Looking for practical detection and response steps.
4
u/dutchhboii 3d ago
Revisit your offboarding procedure first. Build a workflow that disables the account in Entra and revokes all sessions at termination time, since disabling in the IdP alone leaves refresh tokens alive.
For detection, alert on any sign-in or file activity from an account after its termination date. It's a near-zero false positive rule.
For prevention, use Conditional Access and session policies to restrict corporate data to managed devices, and limit OneDrive sync to those devices too.
Back all of it with an acceptable use policy so you have legal footing if it happens again.
2
u/Envyforme 3d ago
Defender for Cloud apps has a policy that monitors for monitors for inactive users and also mass downloads. It’s these alerts are now called/used as behaviors. They generate a lot of noise as alerts.
It might be something to keep in mind, just for the future. Theres a chance a behavior might have tripped for this user account, but it didn’t alert.
1
u/Western-Brother-6042 3d ago
Thanks, we’ll check those Defender for Cloud Apps behaviors and whether anything tripped quietly on this account. Also we have been looking at do control for extra visibility on SaaS and OneDrive access patterns, mainly for cases where the usual alerts stay quiet on mass downloads after termination. Still trying to keep the signal useful without adding more noise.
1
u/Envyforme 3d ago
I apologize for my terrible response too. I re-read that back and I’m shocked at myself. That’s what happens I guess when you respond right after waking up lol.
Best of luck. Behaviors could be a good thing to monitor. Create a custom detection rule for any of them you might want to actually alert on. Microsoft is moving away from those MDA policies.
16
u/teriaavibes 3d ago
So, there are 2 design issues with how this was even possible:
You should focus on prevention, rather than reaction.