You have an on-premises network.
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Identity.
From the Microsoft Defender portal, you investigate an incident on a device named Device1 of a user named User1. The incident contains the following Defender for Identity alert.
Suspected identity theft (pass-the-ticket) (external ID 2018)
You need to contain the incident without affecting users and devices. The solution must minimize administrative effort.
What should you do?
DChilds
Highly Voted 1Â year, 1Â month agoHawklx
11Â months agoxRiot007
5Â months agoRedZtopics
1Â year, 1Â month agowheeldj
1Â year, 1Â month agoHawklx
12Â months agoxRiot007
5Â months agopjn
Most Recent 2Â months, 1Â week agoHAjouz
6Â months agoTakakage
6Â months, 2Â weeks agouser636
9Â months, 3Â weeks agouser636
9Â months, 3Â weeks agog_man_rap
10Â months agoSyncure
10Â months agoLOMCLOTRMC
10Â months, 1Â week agoKingJ92
10Â months, 1Â week agoStudytime2023
11Â months agoscfitzp
11Â months, 1Â week agoPolomint
1Â year agoSekpluz
1Â year agoKrayzr
2Â weeks, 6Â days agoKrayzr
2Â weeks, 6Â days agoHawklx
1Â year ago