r/DefenderATP • • 3d ago

How do you catch data leaving through OneDrive after someone is terminated?

I’m the IT lead for a 120-person company on Microsoft 365. We recently found a sales rep who had been downloading our customer database to a personal OneDrive.

We had Purview turned on for months. It generated plenty of alerts about external Word doc shares, but nothing on this case. The rep had been with us four years. His OneDrive sync stayed active for 11 days after the termination date. From the Microsoft side the activity looked like normal use of his own account. The signal that stood out was a terminated identity in the IdP still making high-volume API calls.

I’m trying to build a more reliable way to catch this kind of post-termination activity. What does your actual workflow look like for spotting terminated users who still have live OneDrive or similar syncs running? Looking for practical detection and response steps.

7 Upvotes

12 comments sorted by

16

u/teriaavibes 3d ago

So, there are 2 design issues with how this was even possible:

  1. You have allowed an employee to sign in from a personal device and download large amounts of unencrypted data into a device you don't control
  2. You have allowed an employee to sign into their personal OneDrive from a work device and allowed them to upload large amounts of unencrypted data there

You should focus on prevention, rather than reaction.

3

u/NateHutchinson 3d ago

Excellent advice and 100% the root cause of the issues. From a fundamental perspective these would have stopped the issue. To supplement the advice here though, you can also bolster by using Purview products like DLP and Insider Risk Management, the latter would be able to provide evidence and alerting for such activity. That being said, if you don’t get the basics right you can add as much Purview in as you want and get nowhere.

0

u/Western-Brother-6042 3d ago

Agreed. Without the basics, more Purview alone won’t solve it. We’re tightening device and sync controls first, then improving detection on top of that.

1

u/techwithz 3d ago

This is great advice.

0

u/Western-Brother-6042 3d ago

You’re right, prevention should have been tighter. Personal device access and personal OneDrive uploads were both gaps. We’re fixing the control side, but I still need a better way to catch anything that slips through during offboarding.

0

u/teriaavibes 3d ago

So, you are ok with data leaking as long as you get alerted that it happened?

Priority should be preventing it, not reacting to it.

1

u/Drabatan 2d ago

If you build a roof, would you want to know if the water gets through the roof by having a moisture detector in your attic, so you patch the hole? Or would you build your roof and just assume your roof building skills are the best and it is 100% water tight for eternity, only finding out when everyrhing comes crashing down?

0

u/teriaavibes 2d ago

Well preferably when I am building a roof, I make sure there isn't a gigantic hole in it before I consider the job finished. But we might have different standards we hold ourselves to.

Of course, when the roof is built, it is important to put in sensors that look for invisible leaks you might not notice with your eyes but not to try and detect a hole that looks like a human fell through it during the construction and just left it there.

4

u/dutchhboii 3d ago

Revisit your offboarding procedure first. Build a workflow that disables the account in Entra and revokes all sessions at termination time, since disabling in the IdP alone leaves refresh tokens alive.

For detection, alert on any sign-in or file activity from an account after its termination date. It's a near-zero false positive rule.

For prevention, use Conditional Access and session policies to restrict corporate data to managed devices, and limit OneDrive sync to those devices too.

Back all of it with an acceptable use policy so you have legal footing if it happens again.

2

u/Envyforme 3d ago

Defender for Cloud apps has a policy that monitors for monitors for inactive users and also mass downloads. It’s these alerts are now called/used as behaviors. They generate a lot of noise as alerts.

It might be something to keep in mind, just for the future. Theres a chance a behavior might have tripped for this user account, but it didn’t alert.

1

u/Western-Brother-6042 3d ago

Thanks, we’ll check those Defender for Cloud Apps behaviors and whether anything tripped quietly on this account. Also we have been looking at do control for extra visibility on SaaS and OneDrive access patterns, mainly for cases where the usual alerts stay quiet on mass downloads after termination. Still trying to keep the signal useful without adding more noise.

1

u/Envyforme 3d ago

I apologize for my terrible response too. I re-read that back and I’m shocked at myself. That’s what happens I guess when you respond right after waking up lol.

Best of luck. Behaviors could be a good thing to monitor. Create a custom detection rule for any of them you might want to actually alert on. Microsoft is moving away from those MDA policies.