Forum Discussion

redherring's avatar
redherring
Copper Contributor
Jan 17, 2025

AIR (Automated Investigation and Response) disables user in Active Directory, suspends in Entra ID

My organization saw an incident yesterday with a new-to-us behavior: Defender disabled the user access in Active Directory and suspended the user in Entra ID. It was an AitM (Attacker in the Middle)...

Resources