Detecting Threats in Azure AD

View threats to an Azure AD instance.

Oracle CASB Cloud Service automatically detects anomalous user behavior in Azure AD as well as any behavior associated with suspicious or blacklisted IP addresses.

  1. Select Applications from the Navigation menu. If the Navigation Menu is not displayed, click the Navigation Menu icon Image of the Navigation Menu icon. to display it.
  2. On the Applications page:
    • In card view, click the icon for the instance you want to modify, and then in the Health Summary, click the non-zero number for Threats to view those threats in Risk Events.

    • In grid view, click the non-zero number in the THREATS column to view those threats in Risk Events.

  3. To view additional information related to the threat, including recommended remediation actions, drop down the Actions list and select View Incident.