Forum Discussion
AndrewX
Oct 28, 2018Iron Contributor
Account compromise false positives
In its default state, the constant stream of AzureAD firing “risk events” is overwhelming.. I regularly see a logon in a valid country with other mailbox activity from another country, without a co...
VasilMichev
Oct 29, 2018MVP
It depends, I do tend to see some "Microsoft" IPs reported there, but overall they're getting better in filtering those out. In any case I would suggest you properly investigate those, and if you have any suspicions, contact support and have them confirm whether those are "known" IPs.