Forum Discussion
Yossi Basha
Microsoft
Jun 20, 2019Investigating identity threats in hybrid on prem and cloud environments
We are very happy to announce the new identity threat investigation experiance. Which is the integraiton of Azure ATP, Azure AD identity protection and MCAS - you can now get the security value of t...
David Caddick
Jun 27, 2019Iron Contributor
jlouden Aha - ATA, not Azure ATP? That makes sense, I'm suspecting that there is something going on here that is causing the 10.x.x.x to be flagged as external somehow. Have you also got Sentinel up and compared that to the MD ATP Advanced Threat hunting - I can't understand how two similar tools have such different UI's...
jlouden
Jun 27, 2019Brass Contributor
David Caddick Sorry minor typo...it is Azure ATP...to many TLA's!!
Haven't got sentinel up yet...that is next week. I'll let you know what I find.
I also had a look our internal's are 172.16.x.x and they are being labelled correctly, as are the IPv6's (which was a surprise).