Decrease False Positive "new IP address" alerts from Microsoft addresses and internal APIs
The IP alerts we receive are almost always false positives, and after opening support tickets with your team, they have been tracked as being internal to Microsoft systems or REST APIs.
This creates confusion and wasted time chasing these for admins and users.
This needs to be better tracked and filtered so the alerts are believable.
Right now it's crying wolf too many times and not useful.
2
votes
Ed Sparks
shared this idea
-
Adminalfilteau (Admin, SherWeb) commented
A feature that dynamically detects Microsoft IP has been launched this week and has significantly reduced the false positive for IP sensitive events!