Oct 15 2020
- last edited on
Jan 14 2022
Apologies if this is posted in the wrong hub.
Looking at the Sign-ins monitor in Azure AD, I noticed one of my users gets a Successful sign-in every half hour. The application is "OfficeShredderWacClient". Anyone knows what that application is and what it does? This happens day and night and I know the user is not working at night. Did a google (ahem, I mean Bing) search and I can't find a concrete answer.
Any help will be much appreciated.
Oct 16 2020 12:20 AM
That's hardly the only cryptic name you'll find in the logs, Microsoft continues to do a very poor job in naming and documenting all the first-party apps...
I would suggest you get the appID and check against the list of enterprise apps/service principals for your tenant, the corresponding object might reveal some more info.
Oct 16 2020 06:24 AM
Thanks Vasil, unfortunately I couldn't find a corresponding enterprise app using the appID.
I agree that some of these entries are cryptic but so far, I have been able to find some info on just about everything but that one (knock on wood).
I'll keep digging.
Jan 11 2022 11:36 AM
In the organization I work for, I noticed OfficeShredderWacClient had successfully logged into my account a handful of times in one day. That correlated with a spam email being reported by several people in the office, and part of the solution was for administration to reach into everybody's email and delete it. My assumption is that OfficeShredderWacClient is the service they used to do that. I don't have access to Azure, but stumbled on this post as I was trying to research it myself.