A cloud-based identity and access management service for securing user authentication and resource access
A failed sign-in does not mean the user actually travelled to those countries or accessed AMC Prod. The location is inferred from the source IP and can be distorted by VPNs, mobile networks, cloud-hosted proxies, or automated password-spray attempts. A risky sign-in is a signal to investigate, not proof of compromise.
Open several of the events and compare the failure code/reason, IP address, client app and device, Conditional Access result, risk detection, and the application/resource IDs. Confirm what “AMC Prod” represents from its service principal rather than relying on the display name. Record the request and correlation IDs for escalation.
If every attempt failed and there are no unexpected successful sign-ins or token activity, the app was not accessed by those attempts. Still, check for password-spray patterns and ensure MFA is enforced and legacy authentication is blocked where possible. If you find an unexpected success, high user risk, or unfamiliar active session, reset the password, revoke sessions, and investigate the source IPs immediately.