Hi Team, We would like to raise a support case for clarification and guidance on the following Microsoft Defender XDR alerts: Alert ID 2845536 – Unfamiliar sign-in properties involving one user Alert ID 2825455 – Possibly compromised service principal acc

2026-08-14T10:25:52.2+00:00

Hi Team,

We would like to raise a support case for clarification and guidance on the following Microsoft Defender XDR alerts:

  1. Alert ID 2845536 – Unfamiliar sign-in properties involving one user
  2. Alert ID 2825455 – Possibly compromised service principal account signed in involving one user
  3. Alert ID 2840861 – Increase in app activity on Exchange

We would appreciate your assistance in understanding the following:

  1. Alert/Activity Status: All three alerts are currently showing as Active, while the activity details indicate:
    • Performed by: MicrosoftDefenderXDR
      • Trigger: Automated
        • Activity status: Completed
        1. Actions Taken by Defender: Since these alerts involve potentially compromised identities/applications and are classified as High/Medium severity, please confirm what automated actions, if any, have already been taken by Microsoft Defender XDR, such as account blocking, token revocation, application restriction, or other containment measures.
  2. Recommended Remediation/Blocking Actions: Please advise on the recommended next steps to contain or block the activity associated with these alerts. Specifically, we would like to understand whether any action should be taken. Please review the above alerts and provide your recommendations for further investigation and remediation.Hi Team, We would like to raise a support case for clarification and guidance on the following Microsoft Defender XDR alerts:
    1. Alert ID 2845536 – Unfamiliar sign-in properties involving one user
    2. Alert ID 2825455 – Possibly compromised service principal account signed in involving one user
    3. Alert ID 2840861 – Increase in app activity on Exchange
    We would appreciate your assistance in understanding the following:
    1. Alert/Activity Status:
      All three alerts are currently showing as Active, while the activity details indicate:
      • Performed by: MicrosoftDefenderXDR
      • Trigger: Automated
      • Activity status: Completed
    2. Actions Taken by Defender:
      Since these alerts involve potentially compromised identities/applications and are classified as High/Medium severity, please confirm what automated actions, if any, have already been taken by Microsoft Defender XDR, such as account blocking, token revocation, application restriction, or other containment measures.
    3. Recommended Remediation/Blocking Actions:
      Please advise on the recommended next steps to contain or block the activity associated with these alerts. Specifically, we would like to understand whether any action should be taken. Please review the above alerts and provide your recommendations for further investigation and remediation.
Microsoft Security | Microsoft Defender | Microsoft Defender for Identity
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.