Skip to content

Commit 8a79664

Browse files
authored
Merge pull request #3766 from MicrosoftDocs/main
[AutoPublish] main to live - 05/14 04:29 PDT | 05/14 16:59 IST
2 parents b98de20 + 74d68e7 commit 8a79664

File tree

3 files changed

+2
-3
lines changed

3 files changed

+2
-3
lines changed

ATPDocs/deploy/remote-calls-sam.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ ms.topic: how-to
88
# Configure SAM-R to enable lateral movement path detection in Microsoft Defender for Identity
99

1010
> [!IMPORTANT]
11-
> Remote collection of local administrators' group members on endpoints (using SAM-R queries) feature in Microsoft Defender for Identity will be disabled by mid-May 2025.
11+
> Remote collection of local administrators' group members on endpoints (using SAM-R queries) feature in Microsoft Defender for Identity will be disabled by mid-May 2025. This change will happen automatically by the specified dates. No admin action is required.
1212
>
1313
1414
Microsoft Defender for Identity mapping for [potential lateral movement paths](/defender-for-identity/understand-lateral-movement-paths) relies on queries that identify local admins on specific machines. These queries are performed with the SAM-R protocol, using the Defender for Identity [Directory Service account](directory-service-accounts.md) you configured.

ATPDocs/whats-new.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ For updates about versions and features released six months ago or earlier, see
2525
## May 2025
2626

2727
### Local administrators collection (using SAM-R queries) feature will be disabled
28-
Remote collection of local administrators' group members on endpoints (using SAM-R queries) feature in Microsoft Defender for Identity will be disabled by mid-May 2025. The details collected are used to build the potential lateral movement paths map. Alternative methods are currently being explored.
28+
Remote collection of local administrators' group members on endpoints (using SAM-R queries) feature in Microsoft Defender for Identity will be disabled by mid-May 2025. The details collected are used to build the potential lateral movement paths map. Alternative methods are currently being explored. This change will happen automatically by the specified dates. No admin action is required.
2929

3030
### New Health Issue
3131

CloudAppSecurityDocs/session-policy-aad.md

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -97,7 +97,6 @@ This procedure describes how to create a new session policy in Defender for Clou
9797

9898
1. <a name="inspection"></a>In the **Apply to** area (Preview):
9999

100-
- Select whether to apply the policy to all files, or files in specified folders only
101100
- Select an inspection method to use, such as data classification services, or malware. For more information, see [Microsoft Data Classification Services integration](dcs-inspection.md).
102101
- Configure more detailed options for your policy, such as scenarios based on elements like fingerprints or trainable classifiers.
103102

0 commit comments

Comments
 (0)