Hi Chris, I sincerely feel for your concerns.
Your point is excellent education for both newcomers and existing organizations that use any 3rd party services which have public access.
I can suggest to anyone reading this article to take very seriously the monitoring of all resources under your own responsibility.
Some good tips that have worked for me:
- Set alerts for cost caps which will email you the moment they're exceeded.
- Use Resource Locks to restrict the enablement of new resources.
- Limit the number of users with admin access.
- Use PIM to minimize the hours any user has access to privileged use.
- Configure Sentinel to monitor, alert and even automatically lock out unauthorized use.
- Configure Conditional access and 2FA to restrict user entry.