Aug. 10, 2022, 12:13 p.m. | /u/thaihoangcfc

cybersecurity www.reddit.com

Recently we have had an alert popping up on Microsoft 365 Defender, classifying our AAD Sync server (on Azure VM) as "Potential ADSync tampering". Not quite sure if the below is a false positive.

[Screenshot of the alerts](https://imgur.com/J0xMdz8)

[Alert details](https://imgur.com/f9E71Pr)

I'm not very advanced at cybersecurity, but is it possible to modify a complied executables as shown in the first screenshot? These executables belong to Microsoft AAD Connect as far as I know.

alert cybersecurity defender tampering

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

IT Security Manager

@ Teltonika | Vilnius/Kaunas, VL, LT

Security Officer - Part Time - Harrah's Gulf Coast

@ Caesars Entertainment | Biloxi, MS, United States

DevSecOps Full-stack Developer

@ Peraton | Fort Gordon, GA, United States

Cybersecurity Cooperation Lead

@ Peraton | Stuttgart, AE, United States

Cybersecurity Engineer - Malware & Forensics

@ ManTech | 201DU - Customer Site,Herndon, VA