Microsoft Defender for identity auto disable user account.

brichardi 336 Reputation points
2025-02-06T20:10:58.3766667+00:00

Hello,

Recently, we are experiencing a lot of user accounts being automatically disable by Microsoft Defender for Identity when they authenticated by Exchange Online. Somehow, Defender think the user's accounts being attacked, and just disabled users account. We are not able to pinpoint the policy which cause this issue.

Any suggestion on how to fix this issue is greatly appreciated.

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
251 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Catherine Kyalo 750 Reputation points Microsoft Employee
    2025-03-19T10:04:09.16+00:00

    Hi @brichardi ,

    During my research, I came across a scenario that seems similar to yours here

    Here is what I would recommend to further analyze what is causing the use lockouts in AD:

    1. sign-in logs to see if there are any related entries that might indicate why these accounts are being disabled.
    2. Audit logs in Compliance Center. these contain entries for various administrative changes in your environment.
    3. Review your Conditional Access policies and any other security configurations that could impact user accounts.
    4. Look out for any cached passwords - especially if there was a recent password change.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.