Microsoft Corporation
Suspicious credential change detection and mitigation

Last updated:

Abstract:

Suspicious credential changes are automatically detected and mitigated. A comparison of data surrounding user-account credential changes with suspicious change patterns forms a basis for detecting suspicious credential changes. More particularly, if a credential change substantially matches a known suspicious change pattern, the credential change can be flagged as suspicious. After a credential change is determined to be suspicious, one or more mitigation activities can be triggered to allay adverse effects associated with a suspicious credential change.

Status:
Grant
Type:

Utility

Filling date:

21 Aug 2018

Issue date:

1 Mar 2022