Action 'Get-LabelPolicy' and 'Get-AutoSensitivityLabelPolicy' by User '<SNIP-PII>'

Anonymous
2024-10-06T03:08:53.4833333+00:00

We have been receiving detections related to User Access Sensitivity Label Policy with actions stating these commands have been executed 'Get-LabelPolicy' and 'Get-AutoSensitivityLabelPolicy'. The user.id associated with it is named '<SNIP-PII>'

As what I've understand it appears to be that the user's information that initiated this has been redacted. Am I understanding this correctly? I want some insights would be glad to know about it.

Thank you!

Windows for business | Windows Server | User experience | PowerShell
Microsoft Security | Intune | Compliance
{count} vote

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.