Skip to content

Commit 6638621

Browse files
authored
Merge pull request #4251 from rlitinsky/patch-32
Update remote-calls-sam.md
2 parents 93e04b3 + f3de4d5 commit 6638621

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

ATPDocs/deploy/remote-calls-sam.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,8 +9,8 @@ ms.reviewer: rlitinsky
99
# Configure SAM-R to enable lateral movement path detection in Microsoft Defender for Identity
1010

1111
> [!IMPORTANT]
12-
> The remote collection of local administrators group members from endpoints using SAM-R queries in Microsoft Defender for Identity will be disabled by mid-May 2025. This data is currently used to build potential lateral movement path maps, which will no longer be updated after this change. The change will occur automatically by the specified date, and no administrative action is required.
13-
>
12+
> As of mid-May 2025, Microsoft Defender for Identity no longer collects local administrators group members from endpoints using SAM-R queries. This data is used to build potential lateral movement path maps, which are no longer being updated. The change was applied automaticallyno administrative action or configuration changes were required.
13+
>
1414
1515
Microsoft Defender for Identity mapping for [potential lateral movement paths](/defender-for-identity/understand-lateral-movement-paths) relies on queries that identify local admins on specific machines. These queries are performed with the SAM-R protocol, using the Defender for Identity [Directory Service account](directory-service-accounts.md) you configured.
1616

0 commit comments

Comments
 (0)