Entra ID Unusual Cloud Device Registration

Receiving a number of these alerts after a recent update to alerts, in vestigating I find that the following string is being located: User-Agent

Microsoft.OData.Client/7.12.5. However investigation of all such alerts does not give any evidence of rogue registrations or subsequent actions that are deserving of attention. I have tried device type and found Android, Windows and IOS produce these alerts. The range of users producing the alerts indicates that no one type of user is creating them. I’d like to filter these out as they are taking time and not (apparently) adding to the security of the organisation. Has anybody else come across this problem and determined why so many such alerts are being created? Thanks

You can follow this: Tune detection rules | Elastic Docs

There is a gatekeeper process in place for rule tuning to justify any additional filter I have to know why such events are being created. At the moment I am not clear why so many benign events are creating alerts when other benign registration events are not.