Microsoft Sentinel/Defender Alerts on Apple iOS Connection to Exchange Online

brichardi 361 Reputation points
2025-05-27T16:04:10.89+00:00

Many alerts from Microsoft Sentinel/Defender indicate that users are being flagged as compromised. Further investigation reveals that users were accessing Exchange Online from Apple iPhone/macOS devices. The alerts show connections originating from a foreign country, while it is confirmed that the users are currently in the US.What could explain this issue?

Thanks for your help.

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud Apps
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.