May 16 2022 08:52 AM
We have sentinel ingesting incidents from Identity protection Risky users, sign-ins and detections from Azure portal > Azure Active Directory > Security. However, Sentinel is getting inundates with alerts: atypical travel, unfamiliar sign-ins which already have a correlated rule ('Correlate Unfamiliar sign-in properties and atypical travel alerts) which is great. However, I have marked the user in the Identity protect in the Azure portal as 'Confirmed Safe' and 'Dismissed' but still a few hours later still getting the same alerts for the user. Is there something I am missing to mark this user activity as safe so it stops alerting?
Thanks
Nov 09 2022 03:56 PM
@BcyberS So before like...last week, I could suppress the alerts in Defender so they never made it to Sentinel - however with the new Azure Identity Management that came out just recently - there's no way to suppress atypical travel alerts. As soon as I figure it out, I'll update you.
Nov 18 2022 07:24 PM
Mar 04 2023 11:14 PM