Description

Invalidate current password based credentials without disabling a user account. Sometimes known as ‘forced password change’. Helpful in situations when an account could be compromised, but does not have any identifiable information that it has been utilized maliciously.

Techniques

Examples

Invalidate user's password in Azure Active Directory | Story library | Tines

Reset a user's password in Okta | Library | Tines

Reset Azure Entra ID passwords seen in SpyCloud breachces | Library | Tines

References

Account compromise (Part 1): Breaches are inevitable and early detection is crucial | Tines

FROM TECH TALK TO BUSINESS IMPACT: Leveraging “Have I Been Pwned” to Strengthen Password Integrity

Response Actions in Microsoft Defender for Identity