SOLVED

AADConnect false alert

Copper Contributor

I've found out that Azure ATP has some problems recognizing aadconnect activities.

azure atp dirsync.PNG

Is it happening to you, too?

 

1 Reply
best response confirmed by Paolo Heuer (Copper Contributor)
Solution

This is a known false positive for this detection. You can find more information about all the alerts (including what night generate a false positive) in the Suspicious Activity Guide (this is the ATA version but it's relevant for Azure ATP alerts too): https://aka.ms/atasaguide 

 

For known AAD Connect servers, you can use the "Close and Exclude" option to stop further alerts.

1 best response

Accepted Solutions
best response confirmed by Paolo Heuer (Copper Contributor)
Solution

This is a known false positive for this detection. You can find more information about all the alerts (including what night generate a false positive) in the Suspicious Activity Guide (this is the ATA version but it's relevant for Azure ATP alerts too): https://aka.ms/atasaguide 

 

For known AAD Connect servers, you can use the "Close and Exclude" option to stop further alerts.

View solution in original post