Share via

Device logon user showing mismatch in Microsoft Defender for Cloud (Server)

Noyon Chandra Das 346 Reputation points
2024-11-25T05:43:26.1766667+00:00

Hello Team,

We have onboarded Exchange server in Microsoft Defender for Cloud (Server). And this server successfully showing in Microsoft Defender for Endpoint Assets lists. When we view a single asset details, we found that in logon user details there have 417 users in user lists. They all are not directly login in this Server. Then why it is showing total 417 users in user lists?

User's image

Thanks

Noyon

Community Center | Not monitored
0 comments No comments

2 answers

Sort by: Most helpful
  1. Prathista Ilango 1,065 Reputation points Microsoft Employee
    2024-12-30T07:02:44.78+00:00

    Hello Noyon Chandra Das,

    From your screenshot, this looks like an exchange server. Correct me if I am wrong.
    Is this a case with only this server or similar exchange servers? Were you able to notice this in any other server, other than exchange?
    Trying to figure out if it in case any indirect authentications like Autodiscover or activesync might cause these entries in the logs, resulting in this number. Confirming the pattern might help address here.

    0 comments No comments

  2. VarunTha 14,980 Reputation points Microsoft External Staff Moderator
    2024-11-29T15:31:30.75+00:00

    Hi Noyon Chandra Das,
    Thank you for reaching out to us on the Microsoft Q&A forum.

    This topic is currently not supported in the Q&A forums.

    I recommend initiating a new discussion through the Microsoft Defender for Endpoint Forum

    Moderators are readily available there to assist you and provide guidance.

    Please don't forget to Accept answer and close this thread.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.