Anomalous Token & activity from Microsoft

%3CLINGO-SUB%20id%3D%22lingo-sub-3256034%22%20slang%3D%22en-US%22%3EAnomalous%20Token%20%26amp%3B%20activity%20from%20Microsoft%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3256034%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20am%20trying%20to%20understand%20the%20following%20activity.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20had%20a%20few%20users%20in%20my%20organization%20flagged%20as%20a%20%22Risky%20User%22%20due%20to%20an%20anomalous%20token.%20This%20is%20normally%20supposed%20to%20flag%20if%20a%20users%20session%20token%20is%20stolen%20and%20replayed.%3C%2FP%3E%3CP%3EUpon%20investigating%20the%20flagged%20sign%20ins%2C%20the%20IP%20addresses%20used%20for%20these%20are%20within%20Microsoft's%20Exchange%20Online%20IP%20range.%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmicrosoft-365%2Fenterprise%2Furls-and-ip-address-ranges%3Fview%3Do365-worldwide%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EOffice%20365%20URLs%20and%20IP%20address%20ranges%20-%20Microsoft%20365%20Enterprise%20%7C%20Microsoft%20Docs%3C%2FA%3E%3C%2FP%3E%3CP%3E52.96.172.x%3C%2FP%3E%3CP%3EIt%20is%20also%20common%20to%20see%20these%20as%20non-interactive%20sign%20ins.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20am%20trying%20to%20understand%20why%20there%20would%20be%20a%20sign%20in%20from%20a%20Microsoft%20Exchange%20Online%20IP%20address%20to%20one%20of%20our%20accounts%20that%20would%20be%20attempting%20to%20use%20a%20token%20from%20a%20users%20client%20as%20per%20the%20error%20message%20reported%3F%3C%2FP%3E%3CP%3EIs%20there%20a%20service%20running%20in%20Exchange%20Online%20I%20am%20not%20aware%20of%20that%20signs%20in%20on%20the%20users%20behalf%3F%20Why%20would%20it%20be%20using%20a%20token%20granted%20to%20a%20users%20device%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20also%20noticed%20consistent%20activity%20from%20these%20IP%20addresses%20in%20Cloud%20App%20Security.%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22cloudApp.png%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F355433i65ADA6F1095265D4%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22cloudApp.png%22%20alt%3D%22cloudApp.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20help%20or%20clarification%20would%20be%20greatly%20appreciated!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EKind%20Regards%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EJacques%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CBR%20%2F%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-3256034%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20Active%20Directory%20(AAD)%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIdentity%20Protection%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Occasional Visitor

Hi,

 

I am trying to understand the following activity.

 

I have had a few users in my organization flagged as a "Risky User" due to an anomalous token. This is normally supposed to flag if a users session token is stolen and replayed.

Upon investigating the flagged sign ins, the IP addresses used for these are within Microsoft's Exchange Online IP range. Office 365 URLs and IP address ranges - Microsoft 365 Enterprise | Microsoft Docs

52.96.172.x

It is also common to see these as non-interactive sign ins.

 

I am trying to understand why there would be a sign in from a Microsoft Exchange Online IP address to one of our accounts that would be attempting to use a token from a users client as per the error message reported?

Is there a service running in Exchange Online I am not aware of that signs in on the users behalf? Why would it be using a token granted to a users device?

 

I have also noticed consistent activity from these IP addresses in Cloud App Security.

cloudApp.png

 

Any help or clarification would be greatly appreciated!

 

Kind Regards,

 

Jacques

 

 

 


 

0 Replies