Microsoft public IP scanning my app services IP

AzureGladiator 0 Reputation points
2025-02-06T07:34:03.2566667+00:00

We recevied an alert on defender for cloud stating vulnerability scanner detected. while checking the owner of the IP, it's MICROSOFT-CORP-MSN-AS-BLOCK and it is scanning for world press related stuffs on my azure app services.

Is it some sort of intenal scanning or do we have to report abuse on it?

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,487 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,219 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Sakshi Devkante 655 Reputation points Microsoft Vendor
    2025-02-06T11:48:46.7+00:00

    Hello @AzureGladiator

    Thank you for posting your query on Microsoft Q&A.

    It is most likely an internal scan, either as part of Microsoft's security assessments, vulnerability scanning, or proactive measures like the Azure Security Center or associated services performing their checks, since it originates from an IP range owned by Microsoft.

    To improve client security, Microsoft frequently performs internal security scans on all of its cloud infrastructure, including Azure-hosted apps, to find vulnerabilities. This scan might be a valid way to look for possible WordPress vulnerabilities, like out-of-date plugins or customizations.

    If the scan seems unusual or doesn't appear to be related to any of your Microsoft services, or if you suspect malicious activity, you can consider reporting it through Microsoft's Abuse Reporting channels. They take abuse reports seriously and will investigate any suspicious behavior: https://learn.microsoft.com/en-us/defender-office-365/submissions-report-messages-files-to-microsoft

    Although it's likely an internal Microsoft security scan, it's recommended to double-check and keep an eye out for any unusual activities. You can report the scan if it doesn't match your configured services or if it worries you, but given the IP range, it most likely is a part of Microsoft's routine checks.

    Ref: https://learn.microsoft.com/en-us/azure/defender-for-cloud/alerts-overview
    https://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-vulnerability-assessment

    I hope this clarifies things. Please contact us if you have any additional questions.

    If this answers your query, do click Accept Answer and Yes for "Was this answer helpful". And, if you have any further query do let us know.

    Best regards,

    Sakshi Devkante


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.