1. Prerequisites
- Identity provider logs
- MFA telemetry
- Device registration logs
- User account information
- Authentication timeline
- Access to identity provider
- Access to MFA platform
- Access to SIEM
- Access to mobile device management platform
2. Step-by-Step Instructions
Common Failure Modes
- Leaving trusted devices intact
- Ignoring backup recovery methods
- Re-enrolling MFA without identity verification
-
Review Existing MFA Configuration
- Identify:
- Registered MFA methods
- Trusted devices
- Recovery methods
- Push notification approvals
- Hardware token assignments
- Identify:
-
Identify Suspicious MFA Activity
- Review:
- MFA fatigue attempts
- Unexpected approvals
- Rogue device registrations
- Suspicious enrollment events
- Bypass activity
- Review:
-
Remove Existing MFA Enrollments
- Reset:
- Push-based MFA
- TOTP applications
- SMS-based MFA
- Hardware token associations
- Backup/recovery methods
- Reset:
-
Validate Trusted Devices
- Review:
- Device ownership
- Device health
- Device compliance status
- Device registration timestamps
Remove: - Unknown devices - Non-compliant devices - Suspicious device enrollments
- Review:
-
Re-Enroll MFA Securely
- Require:
- Fresh MFA registration
- Verified user identity
- Approved authentication methods
- Device compliance validation
- Require:
-
Validate Authentication Integrity
- Confirm:
- MFA functioning correctly
- No rogue devices remain
- No persistent approvals exist
- Authentication challenges enforced
- Confirm:
3. Post-Action
- Document all containment steps taken in the incident ticket, along with the time each action was taken
Contributor
Vishal Thakur
GitHub: https://github.com/malienist
Jayden Vo GitHub: https://github.com/jayden-vo
Contributed to the Arcana Incident Response Documentation Framework.
