Can legitimate activity look suspicious to a cloud provider?¶
Yes. Risk systems compare activity with expected patterns and known threats, so authorised travel, new equipment, VPN routes, synchronisation, automation or unusually large work can trigger the same signals associated with compromise. A legitimate explanation becomes persuasive when records support the person, purpose, device and resulting activity.
Dave's planned migration produces an anomaly¶
Northstar issues Dave a new Surface Laptop. An approved migration starts at 18:00 through the company's Amsterdam security gateway and synchronises 940 OneDrive files. The provider sees a new device, unfamiliar network exit and unusual file volume.
A plausible story is not enough¶
Compare the precise provider events with device enrollment, change or travel records, job logs, communications and the expected object range. Ask whether the explanation accounts for the authentication method, application, timing, volume and security changes - not merely one convenient feature.
The same discipline prevents both errors: treating a red dashboard symbol as proof of an attack, or accepting “normal business” without corroboration. Several records that independently describe the same authorised event can positively establish a legitimate route while leaving unrelated events open.
Current Microsoft Entra example - checked 2 September 2026
Microsoft Entra currently describes risk detections based on signals including unfamiliar sign-in properties, atypical travel, anomalous tokens and uncommon mass access to sensitive SharePoint or OneDrive files. Microsoft notes that models suppress some familiar VPN patterns and that some detections can still produce false positives.
Detection logic, learning periods, licences and labels change. Preserve the provider's risk detail and raw activity, then test it against independent organisational and device records.
The point to remember
Legitimate activity can trigger a genuine risk alert. Establish the authorised person, purpose, device and event scope with records rather than accepting or dismissing the alert on appearance.