Can we exclude Remediated Risk state alerts in Identity Protection

Pallavi Kattepura Laxminarayan 0 Reputation points
2023-04-28T13:05:41.72+00:00

We have Risk state as Remediated in the Sign in log tables.
Can those alerts be excluded or should we monitor and investigate them under certain conditions with Authorization details etc.

Microsoft Security | Microsoft Defender | Microsoft Defender for Identity
Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

1 answer

Sort by: Most helpful
  1. Akshay-MSFT 18,006 Reputation points Microsoft Employee Moderator
    2023-05-02T13:57:38.49+00:00

    @Pallavi Kattepura Laxminarayan

    Thank you for posting your query on Microsoft Q&A. From the above description I could understand that you are looking for clarity on if you could ignore risk alerts with status Remediated (risk detection).

    My answer to that would be "Yes". A risk detection status set automatically by Identity Protection, indicating that the risk detection was remediated using the standard remediation action for this type of risk detection. For example, when the user password is reset, many risk detections that indicate that the previous password was compromised are automatically remediated.

    Please do let me know if you have any further queries.

    Thanks,

    Akshay Kaushik

    Please "Accept the answer" (Yes), and share your feedback if the suggestion answers you’re your query. This will help us and others in the community as well.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.