Microsoft Defender not reacting on suspisious URL
Hello,
I have encountered a rather unpleasant situation with Microsoft Defender.
We have received an incident regarding Connection to adversary-in-the-middle (AiTM) phishing site on one endpoint. The User involved has confirmed, that he had accidentally clicked on a phishing link. The problem is that this was not prevented by Defender. The Evidence and Response tab does not show anything under Remediation status. The URL in questino has a Suspicious verdict.
In comparison, when I look at our last A potentially malicious URL click was detected involving one user incident, In the Evidence and Response tab I can clearly see that both Malicious and Suspisious entities (mail cluster and URL) have a green Prevented Remediation status.
We were lucky that our other security means kicked in and the User was unharmed. I would however like to understand why Defender took no action against a suspicious URL.
Kind regards,
Wojciech