Anomalous Token involving from Microsoft IPs

Anonymous
2024-03-29T15:57:49+00:00

Hi,

Last day, many of my Microsoft applications (Azure admin portal, my sign-ins, O365 portal, etc.) were logged in by IP 51.140.177.153 and showing. And found that the IP is from Microsoft Corporation.

I am trying to understand why these IPs are accessed by the actual username and got triggered as an anonymous token involving.

And that IP also signed in on SSO. I see this as suspicious.

IP involved: 51.140.177.153, 52.171.132.174.

Can someone explain why this is happening?

For reference, see below screenshot.

Sign-in details:

Ip details:

Windows Server Networking Network connectivity and file sharing

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question. To protect privacy, user profiles for migrated questions are anonymized.

0 comments No comments
{count} votes
Accepted answer
  1. Anonymous
    2024-04-02T07:29:37+00:00

    Hello,

    The IP addresses you mentioned, 51.140.177.153 and 52.171.132.174, are associated with Microsoft Corporation . It is not uncommon for Microsoft services and applications to use IP addresses from their own infrastructure when accessing various resources.

    In some cases, these IP addresses may appear as anonymous tokens or involve SSO (Single Sign-On) . This behavior is typically part of the authentication and authorization process used by Microsoft services to ensure secure access to user accounts and resources.

    If you have concerns about the activity or suspect any unauthorized access, it is recommended to review the activities and logs associated with these IP addresses. You can investigate the activities originating from these IP addresses, check for any suspicious behavior, and correlate them with other relevant alerts or incidents .

    It's important to note that Microsoft continuously monitors and maintains the security of their services, and the use of IP addresses from their infrastructure is a normal part of their operations.

    Best regards

    Zunhui

    0 comments No comments

0 additional answers

Sort by: Most helpful