Cloud App security activity logs show Microsoft owned IPs from a foreign countries

%3CLINGO-SUB%20id%3D%22lingo-sub-2131029%22%20slang%3D%22en-US%22%3ECloud%20App%20security%20activity%20logs%20show%20Microsoft%20owned%20IPs%20from%20a%20foreign%20countries%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2131029%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20noticed%20on%20Cloud%20App%20security%20activity%20logs%20Microsoft%20own%20IP%20addreses%20generating%20activity%20logs%20and%20interacting%20with%20Sharepoint%20and%20other%20apps%2C%20these%20IPs%20are%20located%20outside%20of%20US%2C%20and%20we%20dont%20have%20any%20offices%20there.%20There%20is%20never%20a%20login%20audit%20log%20generated.%20It%20seems%20this%20is%20a%20type%20of%20background%20processing%20from%20Microsoft.%20I%20would%20like%20to%20know%20the%20reason%20behind%20Microsoft%20performing%20these%20activity%20and%20why%20it%20is%20not%20whitelisted%2Fremoved%20from%20audit%20logs%20to%20prevent%20false%20positives%20and%20confusion.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Visitor

I have noticed on Cloud App security activity logs Microsoft own IP addreses generating activity logs and interacting with Sharepoint and other apps, these IPs are located outside of US, and we dont have any offices there. There is never a login audit log generated. It seems this is a type of background processing from Microsoft. I would like to know the reason behind Microsoft performing these activity and why it is not whitelisted/removed from audit logs to prevent false positives and confusion.

0 Replies