Are Others Experiencing the MS Entra ‘Leaked Credentials’ Alert?

0
1
Asked By CuriousCactus42 On

Hey everyone, I'm trying to figure out what's going on with Microsoft Entra. I received a few alerts today about valid credentials that supposedly leaked on the dark web. According to Microsoft's documentation, these alerts happen when they detect valid user credentials in compromised databases. However, these accounts don't share common services, and there are no other indications of risky sign-ins. All users have MFA enabled. I checked Have I Been Pwned, and there's nothing on those accounts. I'm wondering if this could be a Microsoft error or if anyone else has received similar alerts around 1:10 AM UTC on Saturday, the 19th? Aside from resetting passwords for now, what steps should I be taking?

5 Answers

Answered By DataProtector101 On

We also had a surge of alerts. It's either a new Microsoft feature or a major screw-up on their end. I suspect misconfiguration leading to unnecessary false positives given that no other risk detections appeared.

JustTryingToHelp -

That does make sense! I wonder if they launched a new patch or something similar that triggered this.

Answered By TechSavvyNerd On

I can confirm similar alerts hit our system too. I even opened a P1 support case with Microsoft about it. After eight hours, I was told it's just an automated flagging, and they can't provide further details about why it happened. They suggested we either trust this system blindly or go ahead with password resets without knowing if it's necessary. I also heard others received the same alerts, so it seems widespread.

HelpMeTech2023 -

Any updates from your case? I'm still waiting for a response on mine.

LostInTechLand -

I got a call from support, and they hung up right away—super unhelpful.

Answered By MSP_Life On

We experienced massive lockouts too, about a third of our accounts got flagged as high risk. I think it might be affecting clients similarly but I've been scrambling to manage it all this morning.

EffectiveAdmins -

How are you all tracking these flags? You must have a strategy in place for such a large workload.

TriagingTech -

Definitely wild over here too, seems like a chaotic Monday is ahead.

Answered By OldSchoolSysadmin On

I appreciate this community of sysadmins! Back in the day, we had no real way to connect and share these issues, so having a place to discuss this is invaluable. Just interesting to see how these alerts are rolling out so widely.

SysAdminTimeTraveler -

Absolutely! Connection and sharing knowledge is key in our field.

Answered By InquisitiveAdmin On

Just chiming in—some accounts flagged in our tenant showed that a new Enterprise App was created coinciding with the alerts. Anyone else seeing a strange new addition like the 'MACE Credential Revocation' app?

ReassuredRookie -

Same! It raised a red flag for sure in our logs.

ConfirmingAdmin -

Yeah, we saw that too! It’s concerning how this all correlates.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.