Microsoft Defender not reacting on suspisious URL

Wojciech Rozanski 75 Reputation points
2024-10-09T15:18:05.7766667+00:00

Hello,

I have encountered a rather unpleasant situation with Microsoft Defender.

We have received an incident regarding Connection to adversary-in-the-middle (AiTM) phishing site on one endpoint. The User involved has confirmed, that he had accidentally clicked on a phishing link. The problem is that this was not prevented by Defender. The Evidence and Response tab does not show anything under Remediation status. The URL in questino has a Suspicious verdict.

In comparison, when I look at our last A potentially malicious URL click was detected involving one user incident, In the Evidence and Response tab I can clearly see that both Malicious and Suspisious entities (mail cluster and URL) have a green Prevented Remediation status.

We were lucky that our other security means kicked in and the User was unharmed. I would however like to understand why Defender took no action against a suspicious URL.

Kind regards,

Wojciech

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
250 questions
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.