It would be a good idea to deactivate any devices that were added in Entra during the attack, or at least include this step in the remediation plan, as these devices could provide persistence mechanisms for an attacker after the incident.