Azure virtual desktop session alerts triggered by hostname changes

Heath Smart Dylan 0 Reputation points
2024-07-16T04:55:47.8+00:00

Our Azure virtual desktop keeps raising "pass the ticket" attack alerts when the hostname of our computers changes from <hostname> to <hostname>-<random number>. However, our security logs remain the same inside the SIEM, showing no change in hostname or client IP. As Azure virtual desktop might swap instances, create sessions, or perform backups, I'm assuming this is the reason. Can anyone provide official documentation or a statement to confirm this before we automate a solution?

Azure Virtual Desktop
Azure Virtual Desktop
A Microsoft desktop and app virtualization service that runs on Azure. Previously known as Windows Virtual Desktop.
1,445 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,051 questions
0 comments No comments
{count} votes