Attack Simulation Training False Flagging

Sheila 21 Reputation points
2024-10-11T18:24:01.37+00:00

Hello,

I created an attack simulation with a drive-by URL for my end users and it somehow falsely flagged over half of the users as compromised when I can confirm that they did not click on the URL. I can confirm this because I was one of the users that was falsely flagged.

I was able to cancel the simulation and exclude it from reporting, but users who were flagged as compromised are still receiving the training notifications. We have SEVERAL users who have expressed their frustration to us over this and we have not found a way to cancel the training assigned to them.

Any help is welcomed.

Thank you.

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,420 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.