suspicious log in defender for endpoint

Loïc 85 Reputation points
2024-02-14T08:51:02.35+00:00

User's image

User's image

Hi everyone, I stumbled upon these logs from a machine, they seem very suspicious and not normal, should I be worried? Thanks.

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
175 questions
{count} votes

Accepted answer
  1. Oleksandr Romaniuk 465 Reputation points
    2024-03-07T20:50:53.6966667+00:00

    Hello!

    It looks like the user (maybe as an administrator) just wants to turn off this feature (SpynetReporting is part of Microsoft MAPS). I think this is not critical, but I would suggest you enable the Tamper protection functionality so that nobody can turn off the Defender.

    And go to https://security.microsoft.com => Incidents & alerts =>Alerts, if you don't see anything there, then all is good.


    If the above response was helpful, please feel free to "Accept as Answer" and click "Yes" so it can be beneficial to the community.

    2 people found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful