Forum Discussion
SergioT1228
Sep 22, 2020Brass Contributor
Failed Logins with Cloud App Security - Locked account
I have created a policy that alerts when Activity Type equals "Failed log on" AND App equals "Active Directory". What I would like to be able to also find is a policy/report in CASB to show when an account is "LOCKED".
Cheers,
4 Replies
- Caroline_Lee
Microsoft
SergioT1228 Hi, one way you'd be able to see this is under the investigate blade > users and accounts > filter on the status=Suspended. Does that help?
- Sarahzin_Shane
Microsoft
In addition to Caroline’s response, wanted to confirm that when you’re using Active Directory, that’s showing the alerts coming through Azure ATP as Azure ATP alerts are filtered using the application filter to Active Directory. You’re trying to find Azure ATP detected logins?
- SergioT1228Brass Contributor