Compromised Users
The Compromised Users are the users detected as compromised with high probability. It shows the number of Anomaly events with Critical severity.
For Microsoft SaaS applications, these tags appear at the top of the widget based on the configured anomaly detection workflow:
-
No prevention - Appears if the anomaly detection workflow is configured not to block the user automatically when an account is detected as compromised.
-
Full prevention - Appears if the anomaly detection workflow is configured to block the user automatically when an account is detected as compromised.
For more information, see Configuring Anomaly Detection Workflows.
In rare cases, this widget might be replaced with the Anomalies widget that shows information about the compromised users.