You have an on-premises network.
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Identity.
From the Microsoft Defender portal, you investigate an incident on a device named Device1 of a user named User1. The incident contains the following Defender for Identity alert.
Suspected identity theft (pass-the-ticket) (external ID 2018)
You need to contain the incident without affecting users and devices. The solution must minimize administrative effort.
What should you do?
DChilds
Highly Voted 1Â year, 3Â months agoHawklx
1Â year agoxRiot007
6Â months, 3Â weeks agoRedZtopics
1Â year, 3Â months agowheeldj
1Â year, 3Â months agoHawklx
1Â year, 1Â month agoxRiot007
6Â months, 3Â weeks agopjn
Most Recent 3Â months, 4Â weeks agoHAjouz
7Â months, 3Â weeks agoTakakage
8Â months agouser636
11Â months, 1Â week agouser636
11Â months, 1Â week agog_man_rap
11Â months, 2Â weeks agoSyncure
11Â months, 2Â weeks agoLOMCLOTRMC
11Â months, 3Â weeks agoKingJ92
11Â months, 3Â weeks agoStudytime2023
1Â year agoscfitzp
1Â year agoPolomint
1Â year, 1Â month agoSekpluz
1Â year, 1Â month agoKrayzr
2Â months, 1Â week agoKrayzr
2Â months, 1Â week agoHawklx
1Â year, 2Â months ago