Azure Sign-in logs - Should I be concerned?

Mike Fairley 0 Reputation points
2023-03-27T07:48:20.9866667+00:00

We are in Australia. We have conditional access rules, including block all countries that are not Australia. We are currently getting hit hard from Uzbekistan.

It is comforting to see all access to 365 resources have failed. But one thing worries me - Why (and how) is the Windows Sign-in marked as Success. What does this mean in terms of access. Has our security been breached???

azure

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,112 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Harpreet Singh Matharoo 8,136 Reputation points Microsoft Employee
    2023-03-27T10:30:16.3233333+00:00

    Hello @Mike Fairley

    Thank you for reaching out. There is nothing to worry about. I would like to confirm that this might be due to an recent incident which was reported on Azure AD where incorrect geo-location tags were reflecting for some IP's in Asia-Pacific Region. The issue is already resolved and Root cause of the issue would be published by 2023-03-30. For more details you can refer following incident reports:

    I hope this answer helps to resolve your issue.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well

    0 comments No comments

  2. Limitless Technology 44,391 Reputation points
    2023-03-27T12:31:57.33+00:00

    Hello,

    It seems very possible that this is because of the recent issue with Azure Geolocation missplacement, but since only single-factor authentication appears as Success, I would recommend to:

    Cautelar AAD Lockout of the problematic Account(s) if the access is suspicious.

    Implement MFA (With Windows Hello, for instance) to ensure the security of access to Azure:

    https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-mfasettings

    --If the reply is helpful, please Upvote and Accept as answer--

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.