@Fahad Noaman
Thank you for your post!
Looking at your issue, you should be able to investigate this issue further by following the Reconnaissance using Directory Services queries documentation. Additionally, you can troubleshoot the issues using the ATA audit logs which can be found under the "Windows Event Logs" -> Applications and Services, Microsoft ATA.
If you'd like to reach out to our Azure Advanced Thread Protection Team.
Please let me know if you have any other questions.
Thank you for your time and patience.
Additional Links:
Advanced Threat Analytics suspicious activity guidesuspicious-activity-guide
User and Group membership reconnaissance (SAMR) (external ID 2021)