Forum Discussion

SergioT1228's avatar
SergioT1228
Brass Contributor
Sep 22, 2020

Failed Logins with Cloud App Security - Locked account

I have created a policy that alerts when Activity Type equals "Failed log on" AND App equals "Active Directory".  What I would like to be able to also find is a policy/report in CASB to show when an account is "LOCKED".  

 

Cheers,

4 Replies

  • SergioT1228 Hi, one way you'd be able to see this is under the investigate blade > users and accounts > filter on the status=Suspended. Does that help?

    • Sarahzin_Shane's avatar
      Sarahzin_Shane
      Icon for Microsoft rankMicrosoft

      In addition to Caroline’s response, wanted to confirm that when you’re using Active Directory, that’s showing the alerts coming through Azure ATP as Azure ATP alerts are filtered using the application filter to Active Directory. You’re trying to find Azure ATP detected logins?

      SergioT1228 

Resources