Forum Discussion

Larssen92's avatar
Larssen92
Copper Contributor
Jan 14, 2022

AAD Identity Protection queries

Hi,

The "Create incidents based on all alerts generated in Azure Active Directory Identity Protection" rule is generating alot of false-positive incidents in our environment.

 

Is it possible to find and edit the queries used to trigger these alerts, to get rid of the false-positive alerts? Or is it not possible to modify the query triggering the alerts generated by AAD Identity Protection?

 

4 Replies

  • GaryBushey's avatar
    GaryBushey
    Bronze Contributor
    These alerts are generated in the AAD IP program, so you can go there and see about adjusting the parameters to help alleviate the false positives.
    • Larssen92's avatar
      Larssen92
      Copper Contributor
      Thank you for answering.
      I don't seem to find what I search for though. I hoped to find a customizable query, in the style of the ones used for custom made Scheduled Analytics rules.

      Are you refering to the Policies in the AADIP? Or can you give more details about where i can go and adjust parameters?
      Thank you in advance.

Resources