# Entra ID Unusual Cloud Device Registration

**URL:** <https://discuss.elastic.co/t/entra-id-unusual-cloud-device-registration/385717>\
**Category:** Elastic Security\
**Created:** [March 31, 2026, 2:04pm UTC](https://discuss.elastic.co/t/entra-id-unusual-cloud-device-registration/385717 "2026-03-31T14:04:57Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![lonpm2](https://avatars.discourse-cdn.com/v4/letter/l/f08c70/32.png) [@lonpm2](https://discuss.elastic.co/u/lonpm2)\
**Post date:** [March 31, 2026, 2:04pm UTC](https://discuss.elastic.co/t/entra-id-unusual-cloud-device-registration/385717/1 "2026-03-31T14:04:57Z")

</div>

Receiving a number of these alerts after a recent update to alerts, in vestigating I find that the following string is being located: User-Agent

Microsoft.OData.Client/7.12.5. However investigation of all such alerts does not give any evidence of rogue registrations or subsequent actions that are deserving of attention. I have tried device type and found Android, Windows and IOS produce these alerts. The range of users producing the alerts indicates that no one type of user is creating them. I’d like to filter these out as they are taking time and not (apparently) adding to the security of the organisation. Has anybody else come across this problem and determined why so many such alerts are being created? Thanks

---

<div class="post-metadata">

**Author:** ![dot-mike](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dot-mike/32/143339_2.png) [@dot-mike](https://discuss.elastic.co/u/dot-mike)\
**Post date:** [March 31, 2026, 5:48pm UTC](https://discuss.elastic.co/t/entra-id-unusual-cloud-device-registration/385717/2 "2026-03-31T17:48:57Z")

</div>

You can follow this: [Tune detection rules | Elastic Docs](https://www.elastic.co/docs/solutions/security/detect-and-alert/tune-detection-rules)

---

<div class="post-metadata">

**Author:** ![lonpm2](https://avatars.discourse-cdn.com/v4/letter/l/f08c70/32.png) [@lonpm2](https://discuss.elastic.co/u/lonpm2)\
**Post date:** [April 1, 2026, 8:05am UTC](https://discuss.elastic.co/t/entra-id-unusual-cloud-device-registration/385717/3 "2026-04-01T08:05:38Z")

</div>

There is a gatekeeper process in place for rule tuning to justify any additional filter I have to know why such events are being created. At the moment I am not clear why so many benign events are creating alerts when other benign registration events are not.
