Inquiry about IP addresses associated with Microsoft Security Alerts

Michael Tamiru Gubay 0 Reputation points
2026-09-09T17:12:37.4533333+00:00

Dear Microsoft Support Team,

We are reaching out to inquire about the following IP addresses:

·       196.189.145.143

·       196.188.255.172

·       196.190.154.244

·       196.188.252.163

·       196.190.62.87

Could you please confirm if these IP addresses are part of Microsoft services? We have received security alerts associated with these IPs, and we need to verify their ownership to proceed with further investigation.

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud Apps
0 comments No comments

1 answer

Sort by: Most helpful
  1. Marcin Policht 106.8K Reputation points MVP Volunteer Moderator
    2026-09-09T17:24:36.62+00:00

    Nope, these IP addresses are not part of Microsoft services. Public WHOIS data and network routing information show that all five IP addresses belong to Ethio Telecom (the national telecommunications provider in Ethiopia). They are hosted under Autonomous System Number AS24757.

    A breakdown of the network ownership for each IP address indicates:

    • 196.189.145.143 – Assigned to Ethio Telecom (Network Range: 196.189.0.0/18)
    • 196.188.255.172 – Assigned to Ethio Telecom (Network Range: 196.188.0.0/14)
    • 196.190.154.244 – Assigned to Ethio Telecom (Network Range: 196.190.0.0/17)
    • 196.188.252.163 – Assigned to Ethio Telecom (Network Range: 196.188.0.0/14)
    • 196.190.62.87 – Assigned to Ethio Telecom (Network Range: 196.190.62.0/24)

    Because these are consumer/enterprise ISP addresses rather than cloud infrastructure IPs, the security alerts likely stem from individual compromised devices, local web servers, or end-users on that provider's network.

    If you are experiencing malicious activity (such as scanning, brute-force attacks, or spam), you can forward your logs directly to Ethio Telecom's abuse contacts, which can be found via the regional internet registry AFRINIC

    For future investigations, you can cross-reference suspicious IPs with official, dynamically updated Microsoft Azure IP ranges by checking the Microsoft Azure IP Ranges and Service Tags JSON file.


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.