A security solution that detects identity-based threats and suspicious activities in on-premises Active Directory environments
The "CONTAINED" flag did vanish, apparently by its own, half a day later. When Microsoft support finally got around to answering my request four days later there was nothing left to see. So the issue is resolved but the cause remains a mystery.