Repeatedly having "Multiple failed user log on attempts to an app" incidents and alerts

Pavel yannara Mirochnitchenko 13,426 Reputation points MVP
2023-06-13T07:21:47.31+00:00

I have cloud-only environment without local Active Directory and after Defender for Cloud Apps was implemented, only one policy generates these "Multiple failed user log on attempts to an app" alerts and incidents all the time. Is this a known behavior? I noticed, that desktop computer without Hello for Business enabled does not generate it, but all laptops having fingerprint and face recognition do generate it.

I can't identify any problems in use, only thinking is there a conflict of having WHFB enabled together with this alert policy?

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud Apps
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Pavel yannara Mirochnitchenko 13,426 Reputation points MVP
    2023-06-20T18:04:24.13+00:00

    Anyone?

    ??

    0 comments No comments

  2. Ramon Diaz 0 Reputation points
    2023-09-18T14:17:08.73+00:00

    I have the same problem, but can't find an answer either. anyone?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.