Microsoft Entra ID Protection Malicious IP Address Risk
Detects Microsoft Entra ID Protection risk telemetry where authentication activity is associated with an IP address Microsoft has classified as malicious. The signal can indicate hostile infrastructure, but the event can represent either successful or failed authentication and therefore should not be statically mapped to a specific access technique.
Cortex XDR

