Forum Discussion
JasonNeasham
May 21, 2019Copper Contributor
New Failed Sign in MACS Policy
Hi Guys,
I am trying to get a new policy corrected so that it does not show so much noise. What I have done is created a policy that looks for failed sign in's. In the Activity section of the policy I have selected "Failed Log on". However what I would really like to see is just "(Failure message: Strong Authentication (second factor) is required)" messages. The idea is that we have all users in MFA so seeing an alert with 5 failed MFA attempts in 5 min should mean that either the user is having problem or someone else might be trying to access that account. We have the policy but it creates quite a few alerts as I cannot find the activity linked to Failed MFA attempts.
Any help would be appreciated.
- Valon_KolicaMicrosoft
- paristerCopper ContributorI never get failed log in attempts, is there something more to configure?
- Valon_KolicaMicrosoft
Looping Andrew Harris (AZURE SEC)