Suspicious login alerts are designed to identify logins to mailboxes in your organisation that are out of the ordinary. They are normally prompted when a login is made from outside the country.
If you receive a suspicious login alert email then you should follow this procedure:
- Speak to the user in person or on the phone to ask if it was genuinely them logging in.
- If it wasn't then log into the Email Admin Console and reset the password of the mailbox. Pass the new password onto the user either in person or over the phone (to avoid sending new credentials to a potentially compromised account).
There may be false positives from these notifications. One common example is if a councillor is using a VPN. VPNs can make your computer/phone appear to be in a different country than where it actually is. This will prompt a login alert. It's worth speaking to the councillor to see if that's something they use on a regular basis so you can take that into account.