Forum Discussion
Users flagged for risk
I have just enabled the Azure AD premium trial and looked at the users on the list most of them don't have any suspecious activity in the last month, the ones that do are all Sign-in from unfamiliar location.
I think for the free and basic versions of this Users flagged for risk tool, each warning should have a risk level rating, as resetting a user password just becouse they signed in from a different location is not a reason to reset their password and review their whole mailbox.
This makes the current information a waste of time, and will make Office 365 admins just ignore report which is not good.
- Jonathan FrericksJul 24, 2017Copper Contributor
I agree. It feels like an upsell attempt.
I got a list of 100+ at-risk users. The first one I investigated had a mere 4 connections from a single application, from a single source IP. The only thing suspicious was how infrequently the user checked their email from their phone.
The main problem now is that the managers are starting to panic.
- Daniel WesterdaleJul 25, 2017Iron Contributor
Hi
I have enabled AD Premium 30 day trial on half of a client via the AD Admin Classic Portal. I have 20 or so users flagged for risk to step through. I wondered if there isn't a bit of PowerShell to create a CSV file listing each user and risk notification.