Repeatedly having "Multiple failed user log on attempts to an app" incidents and alerts

Pavel yannara Mirochnitchenko 12,391 Reputation points MVP
2023-06-13T07:21:47.31+00:00

I have cloud-only environment without local Active Directory and after Defender for Cloud Apps was implemented, only one policy generates these "Multiple failed user log on attempts to an app" alerts and incidents all the time. Is this a known behavior? I noticed, that desktop computer without Hello for Business enabled does not generate it, but all laptops having fingerprint and face recognition do generate it.

I can't identify any problems in use, only thinking is there a conflict of having WHFB enabled together with this alert policy?

Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
118 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Pavel yannara Mirochnitchenko 12,391 Reputation points MVP
    2023-06-20T18:04:24.13+00:00

    Anyone?

    ??

    0 comments No comments

  2. Ramon Diaz 0 Reputation points
    2023-09-18T14:17:08.73+00:00

    I have the same problem, but can't find an answer either. anyone?

    0 comments No comments