Educause Security Discussion mailing list archives
Re: Spike in O365 risky "unfamiliar" sign-ins?
From: "Huang, Maria" <MHUANG () BENTLEY EDU>
Date: Fri, 13 Sep 2019 14:28:15 +0000
We are experiencing the same thing. Last night, it was very busy in Cloud App Security. I am still investigating on them as well. We have around 10 alerts about students signed in from risky IPs. Maria Huang Cyber Security Engineer Bentley University 175 Forest Street , LIN 14G Waltham, MA 02452 Office 781-891-2759 [escription: Bentley_Master_EMAILSIG] From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> On Behalf Of Jim A. Bole Sent: Friday, September 13, 2019 10:25 AM To: SECURITY () LISTSERV EDUCAUSE EDU Subject: [SECURITY] Spike in O365 risky "unfamiliar" sign-ins? In the past 24 hours we saw a spike in "unfamiliar" sign-in alerts on our O365 tenant. We are still investigating, but we have some indications in might be due to Microsoft's recent change in their algorithm: https://techcommunity.microsoft.com/t5/Azure-Active-Directory-Identity/Presenting-the-new-Unfamiliar-Sign-in-Properties/ba-p/779978<https://nam03.safelinks.protection.outlook.com/?url=https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FAzure-Active-Directory-Identity%2FPresenting-the-new-Unfamiliar-Sign-in-Properties%2Fba-p%2F779978&data=02%7C01%7CMHUANG%40BENTLEY.EDU%7C4e7caeea34a84ee0c92e08d738563090%7C9030beae3cfc4788a9e2130204ff1f10%7C0%7C0%7C637039815180784697&sdata=OnLt1NvpXarAdfb6oFNg55aIp%2BX2L3MzBdFNK1Gx68M%3D&reserved=0> Is anyone else seeing this? Jim Bole Director of Information Security Stevenson University 1525 Greenspring Valley Road Stevenson, MD, 21153-0641 jbole () stevenson edu<mailto:jbole () stevenson edu> | O: 443-334-2696 ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community
Current thread:
- Spike in O365 risky "unfamiliar" sign-ins? Jim A. Bole (Sep 13)
- Re: Spike in O365 risky "unfamiliar" sign-ins? Huang, Maria (Sep 13)
- Re: Spike in O365 risky "unfamiliar" sign-ins? Hart, Michael (Sep 13)
- Re: Spike in O365 risky "unfamiliar" sign-ins? Jim A. Bole (Sep 13)
- Re: Spike in O365 risky "unfamiliar" sign-ins? Turnbull, Colin (Sep 13)
- Re: Spike in O365 risky "unfamiliar" sign-ins? Sonder, Henk E. (Sep 13)
- Re: Spike in O365 risky "unfamiliar" sign-ins? Frank Barton (Sep 20)
- Re: Spike in O365 risky "unfamiliar" sign-ins? Brandon Hume (Sep 20)
- Re: Spike in O365 risky "unfamiliar" sign-ins? Jim A. Bole (Sep 13)
- <Possible follow-ups>
- Re: Spike in O365 risky "unfamiliar" sign-ins? Theodore J. August (Sep 14)
- Re: Spike in O365 risky "unfamiliar" sign-ins? Jim A. Bole (Sep 16)