Forum Discussion
Brian_Sutton
Aug 05, 2019Copper Contributor
AD Connect MSOL_ User + Suspected DCSync Attack
We use AD Connect in order to replicate our on premise AD accounts to Azure AD. The replication process is completed under the context of the 'MSOL_xxxxxxxx' user account. The AD Connect applicatio...
EliOfek
Microsoft
Aug 05, 2019Brian_Sutton Yes it is, you should exclude the account or the machine from this alert for now.
(Until we will have some news on this, we are working on a feature around this case, but it will take time to see results ...)
SSingh
Aug 13, 2024Copper Contributor
Has this been fixed or not yet?
I am seeing frequent FP alerts in my environment from a particular MSOL_**** account.
I am seeing frequent FP alerts in my environment from a particular MSOL_**** account.