Azure Active Directory Identity Protections Risk Detections not all integrate into 365 Defender for indentity

Ao(Jonas) Sun 0 Reputation points
2023-08-10T01:27:42.7566667+00:00

Hi,

We have enabled "User report suspicious activities" in the Azure AD Multi-Factor Authentication settings. We do have a user report fraud via authenticator. And Azure Active Directory Identity Protections Risk Detections triggered ""User report suspicious activities" Risk detection type however it not integrate into the 365 defender for identity and also not integrate into Azure Sentinel FYI Sentinel AADIP Connector configured and related alert analytic rule setup already and we have no limitation in the analytic rule's. The other alert like "Unfamiliar Sign-ins and Atypical Travel" triggered properly only this new risk detections "User report suspicious activities" not triggered alert in 365 defender for identity and Azure Sentinel. Want to know why? (FYI 365 Defender Settings--Alert service settings--- Checked All alerts already)

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,040 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
175 questions
{count} votes