Forum Discussion

Anonymous's avatar
Anonymous
Jan 23, 2023

failed to log on to unknown using a wrong password

Hello

I am trying to identify the source of multiple bad password attempts and I am seeing this in MDI: "failed to log on to unknown using a wrong password." I understand that it may be from a device that name resolution is failing, but cant we at least see an IP address? Is there a way we can leverage MDE to achieve this? Any ideas or pointers will be greatly appreciated.

 

Thank you

 

1 Reply

  • Yes, it's possible that the "unknown" device could be one with a failed name resolution or one that's not properly registered on the network. To identify the source of multiple bad password attempts, you can try the following steps: 1- Check the logs: Look for any logs on the server or the authentication system you are using that contain IP addresses associated with failed login attempts. These logs might be in the form of event logs, security logs, or even application logs, depending on your environment. 2- Leverage MDE (Microsoft Defender for Endpoint): MDE can provide you with valuable information about devices on your network. If you have it configured in your environment, you can use it to identify devices with multiple failed login attempts. You can either search for events related to failed logins or create custom queries to filter devices based on failed login attempts.

Resources