Hi Team, We would like to raise a support case for clarification and guidance on the following Microsoft Defender XDR alerts: Alert ID 2845536 – Unfamiliar sign-in properties involving one user Alert ID 2825455 – Possibly compromised service principal acc

2026-08-14T10:25:52.2+00:00

Hi Team,

We would like to raise a support case for clarification and guidance on the following Microsoft Defender XDR alerts:

  1. Alert ID 2845536 – Unfamiliar sign-in properties involving one user
  2. Alert ID 2825455 – Possibly compromised service principal account signed in involving one user
  3. Alert ID 2840861 – Increase in app activity on Exchange

We would appreciate your assistance in understanding the following:

  1. Alert/Activity Status: All three alerts are currently showing as Active, while the activity details indicate:
    • Performed by: MicrosoftDefenderXDR
      • Trigger: Automated
        • Activity status: Completed
        1. Actions Taken by Defender: Since these alerts involve potentially compromised identities/applications and are classified as High/Medium severity, please confirm what automated actions, if any, have already been taken by Microsoft Defender XDR, such as account blocking, token revocation, application restriction, or other containment measures.
  2. Recommended Remediation/Blocking Actions: Please advise on the recommended next steps to contain or block the activity associated with these alerts. Specifically, we would like to understand whether any action should be taken. Please review the above alerts and provide your recommendations for further investigation and remediation.Hi Team, We would like to raise a support case for clarification and guidance on the following Microsoft Defender XDR alerts:
    1. Alert ID 2845536 – Unfamiliar sign-in properties involving one user
    2. Alert ID 2825455 – Possibly compromised service principal account signed in involving one user
    3. Alert ID 2840861 – Increase in app activity on Exchange
    We would appreciate your assistance in understanding the following:
    1. Alert/Activity Status:
      All three alerts are currently showing as Active, while the activity details indicate:
      • Performed by: MicrosoftDefenderXDR
      • Trigger: Automated
      • Activity status: Completed
    2. Actions Taken by Defender:
      Since these alerts involve potentially compromised identities/applications and are classified as High/Medium severity, please confirm what automated actions, if any, have already been taken by Microsoft Defender XDR, such as account blocking, token revocation, application restriction, or other containment measures.
    3. Recommended Remediation/Blocking Actions:
      Please advise on the recommended next steps to contain or block the activity associated with these alerts. Specifically, we would like to understand whether any action should be taken. Please review the above alerts and provide your recommendations for further investigation and remediation.
Microsoft Security | Microsoft Defender | Microsoft Defender for Identity
0 comments No comments

1 answer

Sort by: Most helpful
  1. Derek Morgan II 85 Reputation points
    2026-09-21T14:27:41.72+00:00

    @Mukherjee Ayantika (Accenture)

    Good news, nothing's broken here. Identity Protection only scores risk and raises the alert; it doesn't block or disable anything on its own. Automatic remediation needs a sign-in/user risk Conditional Access policy for the first alert, and a separate Conditional Access for Workload Identities policy, assigned directly to that service principal, for the second. Worth confirming both exist and are enabled. Also check your incident queue: Defender XDR's alert correlation logic often groups alerts sharing the same user automatically, though it's not guaranteed.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.