It would be a good idea to deactivate any devices that were added in Entra during the attack, or at least include this step in the remediation plan, as these devices could provide persistence mechanisms for an attacker after the incident.
J
Jacob Adams
Seconded, nine times out of ten in BEC incidents there are rogue devices that get registered to the compromised user's account.