Hi Team,
We would like to raise a support case for clarification and guidance on the following Microsoft Defender XDR alerts:
- Alert ID 2845536 – Unfamiliar sign-in properties involving one user
- Alert ID 2825455 – Possibly compromised service principal account signed in involving one user
- Alert ID 2840861 – Increase in app activity on Exchange
We would appreciate your assistance in understanding the following:
- Alert/Activity Status: All three alerts are currently showing as Active, while the activity details indicate:
- Performed by: MicrosoftDefenderXDR
- Trigger: Automated
- Activity status: Completed
- Actions Taken by Defender: Since these alerts involve potentially compromised identities/applications and are classified as High/Medium severity, please confirm what automated actions, if any, have already been taken by Microsoft Defender XDR, such as account blocking, token revocation, application restriction, or other containment measures.
- Recommended Remediation/Blocking Actions: Please advise on the recommended next steps to contain or block the activity associated with these alerts. Specifically, we would like to understand whether any action should be taken. Please review the above alerts and provide your recommendations for further investigation and remediation.Hi Team, We would like to raise a support case for clarification and guidance on the following Microsoft Defender XDR alerts:
- Alert ID 2845536 – Unfamiliar sign-in properties involving one user
- Alert ID 2825455 – Possibly compromised service principal account signed in involving one user
- Alert ID 2840861 – Increase in app activity on Exchange
We would appreciate your assistance in understanding the following:
- Alert/Activity Status:
All three alerts are currently showing as Active, while the activity details indicate:
- Performed by: MicrosoftDefenderXDR
- Trigger: Automated
- Activity status: Completed
- Actions Taken by Defender:
Since these alerts involve potentially compromised identities/applications and are classified as High/Medium severity, please confirm what automated actions, if any, have already been taken by Microsoft Defender XDR, such as account blocking, token revocation, application restriction, or other containment measures.
- Recommended Remediation/Blocking Actions:
Please advise on the recommended next steps to contain or block the activity associated with these alerts. Specifically, we would like to understand whether any action should be taken. Please review the above alerts and provide your recommendations for further investigation and remediation.