MicrosoftDocs / CloudAppSecurityDocs

Public repo for CloudAppSecurityDocs-pr
Creative Commons Attribution 4.0 International
107 stars 153 forks source link

Alerts generated from *Microsoft IPs* ("Administrative activity from a non-corporate IP address involving one user") #739

Closed ContreBombarde closed 4 months ago

ContreBombarde commented 4 months ago

Hello! We have a recurring frustration with alerting whenever a new user is set up for OneDrive or whenever dismissing certain alerts. It reports that this action is coming from a non-corporate IP address. However, the IP is not the one related to the device or network from which the action was taken, but rather a Microsoft datacenter. Dismissing the alert then generates yet another alert stating the same thing, so it starts an alert loop that can't be stopped.

It seems like the only solution would be to add all of Microsoft's datacenter IPs (not even sure which ones are relevant) to the company's corporate IP address range, but surely that's not the right solution. Is there a better way to address this?

Thank you!

batamig commented 4 months ago

Hi @ContreBombarde, thanks for writing into docs! This sounds like a product question, so I'm going to redirect you to our Tech Community, where there are product experts on hand for questions like this.

If the discussions there show that we need an update in docs, please make sure to request that in the discussion, and the team will open an item for our backlog.

I'm going to close this issue for now. If you have specific feedback on the docs, please feel free to send further comments via our new "thumbs" feedback system.

please-close