Decision RecordActivePublished without chair review
CRT-2026-026609 Sep 2026AFTERNOON EDITIONDaily Roundtable
Targeted containment for Microsoft 365 session exposure
Preserve sign-in and audit evidence, confirm affected identities through correlation, revoke linked user and application sessions, disable confirmed accounts, and review account and OAuth changes rather than relying on authentication resets alone or assuming tenant-wide compromise.
Current public guidance · the full record
What to do now
At a glanceThe edition's authoritative action board carries no action for this record's subjects — no What to do now guidance.
Why now
Partially supportedThe identity architect analysis observed on September 8, 2026 relays 5,137 BigBear 2.0 records associated with 461 organizations, including 4,148 cookies and 474 completed-login records.
That reporting creates an immediate need to preserve evidence and distinguish possible targeting from authenticated-session capture.
Because the analysis describes stolen bearer sessions being accepted after authentication, an MFA or password reset alone may not address the reported exposure; the precise revocation mechanics still require authoritative Microsoft corroboration.
Who is affected
WeakMicrosoft 365 and Entra security and identity operators at the 461 organizations associated with reported BigBear 2.0 records face a validation task, not proof of compromise.
Users whose organization-linked completed-login records show authenticated-session capture face targeted account disablement and session revocation.
Owners of linked applications, OAuth grants, and federated sessions require review when identity and activity correlation connects those assets to a confirmed account. Accounts supported only by a domain or username match should not be disabled or revoked indiscriminately.
The packet identifies no affected Microsoft 365 or Entra version, tenant configuration, or deployment model.
What supports this
Partially supportedIdentity architect analysis — support: it identifies acceptance of a stolen bearer session after authentication, rather than cryptographic defeat of MFA, as the control failure.
Report classification — support: the analysis relays 5,137 BigBear 2.0 records associated with 461 organizations, including 4,148 cookies and 474 completed-login records, and explains why those record types require different conclusions.
Containment assessment — support: the evidence audit says the cited analysis directly recommends preserving sign-in and audit logs, disabling confirmed accounts, revoking identity and application sessions, reviewing OAuth and account changes, and avoiding assumptions of tenant-wide compromise.
Revocation-mechanics assessment — evidence gap: the audit says the packet describes why authentication resets and session revocation differ but lacks Microsoft documentation corroborating the details.
How the Roundtable reached this
WeakThe initial analysis proposed preserving evidence, correlating identities and activity, and containing only confirmed Microsoft 365 and Entra exposure.
The identity architect distinguished a domain or username match, which shows possible targeting or exposure, from a completed-login record, which shows authenticated-session capture; confirmed tenant compromise still requires Entra log correlation.
The evidence audit found direct support for the containment sequence but identified missing Microsoft documentation for session-revocation behavior. The boundary review accepted the narrowed position because it does not treat every named tenant as compromised or claim that MFA was defeated.
A record-linking check found no existing decision covering this question, and the arbiter selected a new record because the containment position was supported despite the peripheral vendor-documentation gap.
Positions are generated by AI specialist personas and chaired by Halil Öztürkci.
Panel composition
- Scout (AI panel role)Scout identified 9 candidate signals.
- Linker (AI panel role)Linker evaluated 9 relation judgments.
- Evidence Auditor (AI panel role)Evidence Auditor recorded 20 evidence signals; 11 gaps.
- Prediction Steward (AI panel role)Prediction Steward accepted 1 prediction and rejected 1 claim.
- Boundary Reviewer (AI panel role)Boundary Reviewer recorded 13 public/private findings.
- Arbiter (AI panel role)Arbiter produced 9 decision envelopes.
Key disagreement
Scout (AI panel role)
Reported records and organization matches indicate possible exposure or session capture, but do not prove compromise across every named organization or account.
Arbiter outcome
Arbiter outcome: new decision record. The operational containment position is directly supported, no existing record was found, and the remaining vendor-corroboration gap is peripheral.
Candidates considered
Considered 9 candidates · opened 1 · 8 not opened (8 other)
Considered, not opened
Sign in to preview Considered-Not-Opened entries (moves to Pro at launch).
Sign in to preview practitioner entries.
What is uncertain
ConflictingIt remains unknown which of the 461 organizations or associated accounts were compromised.
A domain or username match establishes possible targeting or exposure, while a completed-login record tied to an organization establishes authenticated-session capture; neither alone proves tenant-wide compromise.
The packet also does not establish the exact limits of Microsoft 365 and Entra session revocation across applications and federated sessions because authoritative Microsoft documentation is absent.
What evidence is missing
ConflictingThe packet lacks authoritative Microsoft documentation confirming how session revocation affects refresh-token-backed access, captured session cookies, individual applications, and federated sessions.
It also lacks direct Entra interactive and non-interactive sign-in records, audit logs, device records, and activity records needed to validate compromise for any named organization or account.
The underlying CloudSEK material and authoritative incident evidence supporting the reported BigBear 2.0 record counts are not included. No affected Microsoft 365 or Entra versions, tenant configurations, or deployment models are identified.
What would change this
WeakDirect Entra correlation showing additional compromised identities, applications, or federated sessions would broaden containment beyond the initially confirmed accounts.
Authoritative incident evidence demonstrating tenant-wide compromise would justify tenant-wide response rather than targeted revocation.
Microsoft documentation showing that particular applications or federated sessions survive the stated revocation steps would require additional application-specific or federation controls.
Conversely, correlation that finds no suspicious sign-ins or activity would leave a reported domain or username match classified as possible exposure rather than confirmed compromise.
What to watch next
WeakMonitor Entra interactive and non-interactive sign-ins, audit events, device records, and activity records for additional identities linked to the reported exposure.
If correlation identifies another compromised identity, application, OAuth change, or federation session, preserve its evidence and extend the same disablement and revocation sequence to that scope.
After revocation, treat renewed access or further account and OAuth changes as a trigger to expand containment.
Evidence basis
The control failure was acceptance of a stolen bearer session after authentication—not a cryptographic defeat of MFA. CloudSEK reports 5,137 records associated with 461 organizations, including 4,148 cookies and 474 completed-login records.…
Public value history
- 09 Sep 2026Initial public guidanceCurrent guidance
Created the first public value version for this Decision Record.
Source RoundtableAfternoon roundtableConvened 08 Sep 2026Methodology
How the panel reaches a Public Decision Record.