You have an on-premises network.
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Identity.
From the Microsoft Defender portal, you investigate an incident on a device named Device1 of a user named User1. The incident contains the following Defender for Identity alert.
Suspected identity theft (pass-the-ticket) (external ID 2018)
You need to contain the incident without affecting users and devices. The solution must minimize administrative effort.
What should you do?
DChilds
Highly Voted 1Â year agoHawklx
9Â months, 2Â weeks agoxRiot007
3Â months, 2Â weeks agoRedZtopics
1Â year agowheeldj
1Â year agoHawklx
10Â months, 2Â weeks agoxRiot007
3Â months, 2Â weeks agopjn
Most Recent 3Â weeks, 4Â days agoHAjouz
4Â months, 2Â weeks agoTakakage
5Â months agouser636
8Â months, 1Â week agouser636
8Â months, 1Â week agog_man_rap
8Â months, 2Â weeks agoSyncure
8Â months, 2Â weeks agoLOMCLOTRMC
8Â months, 3Â weeks agoKingJ92
8Â months, 3Â weeks agoStudytime2023
9Â months, 2Â weeks agoscfitzp
9Â months, 3Â weeks agoPolomint
10Â months, 2Â weeks agoSekpluz
10Â months, 2Â weeks agoHawklx
11Â months, 1Â week ago