You have an on-premises network.
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Identity.
From the Microsoft Defender portal, you investigate an incident on a device named Device1 of a user named User1. The incident contains the following Defender for Identity alert.
Suspected identity theft (pass-the-ticket) (external ID 2018)
You need to contain the incident without affecting users and devices. The solution must minimize administrative effort.
What should you do?
DChilds
Highly Voted 1Â year agoHawklx
9Â months, 2Â weeks agoxRiot007
3Â months, 2Â weeks agoRedZtopics
1Â year agowheeldj
12Â months agoHawklx
10Â months, 1Â week agoxRiot007
3Â months, 2Â weeks agopjn
Most Recent 3Â weeks agoHAjouz
4Â months, 2Â weeks agoTakakage
4Â months, 3Â weeks agouser636
8Â months agouser636
8Â months agog_man_rap
8Â months, 1Â week agoSyncure
8Â months, 1Â week agoLOMCLOTRMC
8Â months, 2Â weeks agoKingJ92
8Â months, 2Â weeks agoStudytime2023
9Â months, 2Â weeks agoscfitzp
9Â months, 2Â weeks agoPolomint
10Â months, 2Â weeks agoSekpluz
10Â months, 2Â weeks agoHawklx
11Â months ago