Anonymous User Succeeded Download Limit

ShallowCopy 25 Reputation points
2025-05-02T14:46:08.9633333+00:00

My company received an alert that a user succeeded the file download limit (total was 58/min). Upon investigating the alert in Defender, the user ID is displaying as "urn:spo:anon#46b4476bd6f17a9622678ef53b2748cccfac0a30356a4a64ef9eecf9049507dd". I checked the admin portal and could not find such a user. Also, I checked the sign in logs for the IP address that was listed for the user and no such sign-ins were recorded.

Does anyone know where that user ID could be coming from? Are there any other places I should check to investigate this alert?

Thank you.

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,532 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Bandela Siri Chandana 2,645 Reputation points Microsoft External Staff Moderator
    2025-05-06T11:05:43.7033333+00:00

    Hi @ShallowCopy
    I understand that your company received an alert that a user succeeded the file download limit (total was 58/min). Upon investigating the alert in Defender, the user ID is displaying as "urn:spo:anon#46b4476bd6f17a9622678ef53b2748cccfac0a30356a4a64ef9eecf9049507dd".

    You checked the admin portal and could not find such a user. Also, you checked the sign in logs for the IP address that was listed for the user and no such sign-ins were recorded.

    The risk reports are found in the Microsoft Entra admin center under ID Protection. You can navigate directly to the reports or view a summary of important insights in the dashboard view and navigate to the corresponding reports from there. To view and investigate risky users, navigate to the Risky users report and use the filters to manage the results. There's an option at the top of the page to add other columns such as risk level, status, and risk detail.

    Screenshot showing the summary of risk provided by Copilot in the Risky User Details flyout.

    With the information provided by the Risky user's report, administrators can view:

    • User risk that was remediated, dismissed, or is still currently at risk and needs investigation
    • Details about detections
    • Risky sign-ins associated to a given user
    • Risk history

    Follow the document for more information: https://learn.microsoft.com/en-us/entra/id-protection/howto-identity-protection-investigate-risk#how-to-investigate-risky-users

    Hope this helps. Do let us know if you have any further queries.

    If this answers your query, do click `Accept Answer` and `Yes`.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.