Incidents in Microsoft Sentinel Auto-Closing Without Automation Rules

Anonymous
2024-10-17T14:15:27.48+00:00

I'm currently using Microsoft Sentinel and noticing that some incidents are automatically closing themselves, sometimes with the reason "resolved at source" or no comment at all. I've checked for any automation rules or playbooks that might be responsible, but I haven't found any. I suspect something in the Security portal might be causing this, but I'm not sure where to look.

User's image

Does anyone know the reason for this? There are several incidents like this, most of them related to "unfamiliar sign-in properties."

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Microsoft Sentinel
0 comments No comments
{count} votes

Accepted answer
  1. Raja Pothuraju 23,790 Reputation points Microsoft External Staff Moderator
    2024-10-28T18:59:02.4033333+00:00

    Hello @Hyago Santana Mariano,

    Thank you for posting your query on Microsoft Q&A.

    Based on your description, it appears that incidents in Microsoft Sentinel are being automatically closed with the “Reason for closing” set to “Benign positive – suspicious but expected. Resolved at source.” This behavior occurs when user risks are dismissed due to actions taken by the user, such as completing Multi-Factor Authentication (MFA) or resetting their password. When users are allowed to self-remediate using Microsoft Entra Multi-Factor Authentication (MFA) or Self-Service Password Reset (SSPR) within risk policies, they can unblock themselves when risk is detected.

    Reference: Self-Remediation with Risk Policy

    Identity Protection risks can often be detected and remediated automatically, without the need for intervention by an admin or security analyst. This self-remediation is a designed feature of Identity Protection. For more details on the self-remediation actions, please check the "Risky sign-ins" blade under Identity Protection in Entra ID, where you’ll find that, in most cases, MFA has remediated the risks.

    As these risks are being automatically remediated in Entra Identity Protection, the related incidents triggered in Microsoft Sentinel are being closed automatically with the reason “Benign positive – suspicious but expected. Resolved at source.”

    I hope this information is helpful. Please feel free to reach out if you have any further questions.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Thanks,
    Raja Pothuraju.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.