We identified that the alerts were triggered when our monitor followed an authentication redirect to an external authentication service, which intermittently failed to respond. The core application remained healthy.
The monitor now uses a dedicated health endpoint. We are investigating the authentication issue with the service provider and will add separate monitoring for this dependency.