Risky User Dismissals Generating Defender Alerts

Martin Shaw 0 Reputation points
2025-12-18T13:28:33.7866667+00:00

Bit of a odd one we've just noticed as we put our Defender into a Third party SIEM.

When a user gets marked as a risky user (regardless of level - low, medium. etc.) when we dismiss the user risk in Entra it subsequently generates an 'Unfamiliar sign-in properties involving one user' alert in Defender for the user. This alert is automatically resolved as soon as it's generated.

Can anyone shed some light on why this happens? And if there is a way to disable these alerts or the link that generates them?

Microsoft Security | Microsoft Defender | Microsoft Defender for Office 365
0 comments No comments
{count} votes

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.