An integrated threat protection solution designed to detect, investigate, and respond to cyber threats across Microsoft 365 services.
Hello Koakd,
Thanks for reaching out here regarding this query.
The 365 Defender generates that alert when an unusually large number of activities are performed on files in SharePoint or OneDrive by users outside of your organization. This includes activities such as accessing files, downloading files, and deleting files.
Essentially, the alert will keep existing as long as the Defender doesn't recognize your outside vendor as one within your organization.
For more details, check out:
Sorry for the inconvenience caused.
Warm regards, Albert