Risky sign-in event: Anomalous Token

Copper Contributor

Hello,
Could someone tell me what the Risky sign-in event refers to: Anomalous Token that is related to the Address 52.97.13.101? this IP corresponds to Microsoft exchange online but for some reason it is taken as an abnormal event, according to the validated events it is only communication to sharepoint, is there any type of new configuration generated that involves this IP? And how could I delete this IP so that it does not generate events again?

0 Replies