Skip to content

Commit c42920e

Browse files
authored
Update remote-calls-sam.md
1 parent e22e78a commit c42920e

File tree

1 file changed

+0
-7
lines changed

1 file changed

+0
-7
lines changed

ATPDocs/deploy/remote-calls-sam.md

Lines changed: 0 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -13,13 +13,6 @@ ms.topic: how-to
1313
1414
Microsoft Defender for Identity mapping for [potential lateral movement paths](/defender-for-identity/understand-lateral-movement-paths) relies on queries that identify local admins on specific machines. These queries are performed with the SAM-R protocol, using the Defender for Identity [Directory Service account](directory-service-accounts.md) you configured.
1515

16-
> [!NOTE]
17-
> This feature can potentially be exploited by an adversary to obtain the NTLM hash of the DSA account due to a Windows limitation in the SAM-R calls that allows downgrading from Kerberos to NTLM.
18-
> The new Defender for Identity sensor (version 3.x) is not affected by this issue as it uses different detection methods.
19-
>
20-
> It is recommended to use a [low privileged DSA account](directory-service-accounts.md#grant-required-dsa-permissions). You can also [contact support](../support.md) to open a case and request to completely disable the [Lateral Movement Paths](../security-assessment-riskiest-lmp.md) data collection capability.
21-
> Please note that this will result in reduced data available for the [attack path feature in Exposure Management](/security-exposure-management/review-attack-paths).
22-
2316
This article describes the configuration changes required to allow the Defender for Identity Directory Services Account (DSA) to perform the SAM-R queries.
2417

2518
> [!TIP]

0 commit comments

Comments
 (0)