We're preparing for a scenario quand one of le accounts in a domain gets compromised—what to do next?
Disabling le account would be mon premier go-to answer, mais we had pentesters here a peu de weeks ago et they were able to use hashed logins of an admin user who left a couple of months ago.
Our two answers so far are:
What would votre method be, ou what would you recommend?