Snippet
 "description": "Event contains one or more entries of known microsoft domains", "list": [ ".aadrm.com", ".afx.ms", ".akadns.net", ".aspnetcdn.com", ".azure-int.net", ".azure-mobile.net",
source: https://github.com/MISP/misp-warninglists/edit/main/lists/microsoft/list.json
Suggestion:
Either remove the leading dots, so entries are proper domain strings
Or change the type to hostname or domain to better reflect the matching intent