You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: ATPDocs/deploy/activate-capabilities.md
+41-24Lines changed: 41 additions & 24 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -37,12 +37,6 @@ Direct Defender for Identity capabilities are supported on domain controllers on
37
37
>
38
38
> This issue is addressed in the out-of-band update [KB5037422](https://support.microsoft.com/en-gb/topic/march-22-2024-kb5037422-os-build-20348-2342-out-of-band-e8f5bf56-c7cb-4051-bd5c-cc35963b18f3).
39
39
40
-
### Defender for Endpoint onboarding
41
-
42
-
Your domain controller must be onboarded to Microsoft Defender for Endpoint.
43
-
44
-
For more information, see [Onboard a Windows server](/microsoft-365/security/defender-endpoint/onboard-windows-server).
45
-
46
40
### Permissions requirements
47
41
48
42
To access the Defender for Identity **Activation** page, you must either be a [Security Administrator](/entra/identity/role-based-access-control/permissions-reference), or have the following Unified RBAC permissions:
@@ -55,12 +49,6 @@ For more information, see:
55
49
-[Unified role-based access control RBAC](../role-groups.md#unified-role-based-access-control-rbac)
56
50
-[Create a role to access and manage roles and permissions](/microsoft-365/security/defender/create-custom-rbac-roles#create-a-role-to-access-and-manage-roles-and-permissions)
57
51
58
-
### Connectivity requirements
59
-
60
-
Defender for Identity capabilities directly on domain controllers use Defender for Endpoint URL endpoints for communication, including simplified URLs.
61
-
62
-
For more information, see [Configure your network environment to ensure connectivity with Defender for Endpoint](/microsoft-365/security/defender-endpoint/configure-environment##enable-access-to-microsoft-defender-for-endpoint-service-urls-in-the-proxy-server).
63
-
64
52
## Configure Windows auditing
65
53
66
54
Defender for Identity detections rely on specific Windows Event Log entries to enhance detections and provide extra information about the users performing specific actions, such as NTLM sign-ins and security group modifications.
@@ -78,42 +66,58 @@ For example, the following command defines all settings for the domain, creates
78
66
Set-MDIConfiguration -Mode Domain -Configuration All
79
67
```
80
68
81
-
## Activate Defender for Identity capabilities
69
+
## Onboarding steps
70
+
71
+
### Customers with domain controllers already onboarded to Defender for Endpoint
82
72
83
-
After ensuring that your environment is completely configured, activate the Microsoft Defender for Identity capabilities on your domain controller.
73
+
### Activate Defender for Identity capabilities
84
74
85
75
Activate the Defender for Identity from the [Microsoft Defender portal](https://security.microsoft.com).
86
76
87
77
1. Navigate to **System** > **Settings** > **Identities** > **Activation**.
88
78
89
-
The Activation page lists servers discovered in Device Inventory and identified as eligible domain controllers.
79
+
The Activation Page now displays all servers from your device inventory, including those not currently eligible for the activation of the new Defender for Identity sensor. For each server you can find its activation state.
90
80
91
-
1. Select the domain controller where you want to activate the Defender for Identity capabilities and then select **Activate**. Confirm your selection when prompted.
81
+
2. Select the domain controller where you want to activate the Defender for Identity capabilities and then select **Activate**. Confirm your selection when prompted.
92
82
93
83
:::image type="content" source="media/activate-capabilities/1.jpg" lightbox="media/activate-capabilities/1.jpg" alt-text="Screenshot that shows how to activate the new sensor.":::
94
84
95
85
> [!NOTE]
96
86
> You can choose to activate eligible domain controllers either automatically, where Defender for Identity activates them as soon as they're discovered, or manually, where you select specific domain controllers from the list of eligible servers.
97
87
98
-
1. When the activation is complete, a green success banner shows. In the banner, select **Click here to see the onboarded servers** to jump to the **Settings > Identities > Sensors** page, where you can check your sensor health.
88
+
3. When the activation is complete, a green success banner shows. In the banner, select **Click here to see the onboarded servers** to jump to the **Settings > Identities > Sensors** page, where you can check your sensor health.
99
89
100
90
:::image type="content" source="media/activate-capabilities/2.jpg" lightbox="media/activate-capabilities/2.jpg" alt-text="Screenshot that shows how to seethe onboarded servers.":::
101
91
92
+
### Customers without domain controllers onboarded to Defender for Endpoint
93
+
94
+
### Connectivity requirements
95
+
96
+
Defender for Identity capabilities directly on domain controllers use Defender for Endpoint URL endpoints for communication, including simplified URLs.
97
+
98
+
For more information, see [Configure your network environment to ensure connectivity with Defender for Endpoint](/microsoft-365/security/defender-endpoint/configure-environment##enable-access-to-microsoft-defender-for-endpoint-service-urls-in-the-proxy-server).
99
+
100
+
### Onboard Defender for Identity capabilities
101
+
Download the Defender for Identity onboarding package from the [Microsoft Defender portal] (https://security.microsoft.com)
102
+
103
+
1. Navigate to **System** > **Settings** > **Identities** > **Activation**
104
+
2. Select Download onboarding package and save the file in a location you can access from your domain controller.
105
+
3. From the domain controller, extract the zip file you downloaded from the Microsoft Defender portal, and run the `DefenderForIdentityOnlyOnboardingScript.cmd` script as an Administrator.
106
+
102
107
## Onboarding Confirmation
103
108
104
109
To confirm the sensor has been onboarded:
105
110
106
-
1. Navigate to **System** > **Settings** > **Identities** > **Sensors**.
111
+
1. Navigate to **System** > **Settings** > **Identities** > **Sensors**.
107
112
108
113
2. Check that the onboarded domain controller is listed.
109
114
110
115
> [!NOTE]
111
-
> The activation doesn't require a restart/reboot. The first time you activate Defender for Identity capabilities on your domain controller, it may take up to an hour for the first sensor to show as **Running** on the **Sensors** page. Subsequent activations are shown within five minutes.
116
+
> The onboarding doesn't require a restart/reboot. The first time you activate Defender for Identity capabilities on your domain controller, it may take up to an hour for the first sensor to show as **Running** on the **Sensors** page. Subsequent activations are shown within five minutes.
117
+
> To check the onboarding on the local server you can also review the event log under **Applications and Services Logs** > **Microsoft** > **Windows** > **Sense** > **Operational**. You should receive an onboarding event:
112
118
113
119
## Test activated capabilities
114
120
115
-
The first time you activate Defender for Identity capabilities on your domain controller, it may take up to an hour for the first sensor to show as **Running** on the **Sensors** page. Subsequent activations show within five minutes.
116
-
117
121
Defender for Identity capabilities on domain controllers currently support the following Defender for Identity functionality:
118
122
119
123
- Investigation features on the [ITDR dashboard](#check-the-itdr-dashboard), [identity inventory](#confirm-entity-page-details), and [identity advanced hunting data](#test-advanced-hunting-tables)
@@ -163,7 +167,6 @@ IdentityQueryEvents
163
167
164
168
For more information, see [Advanced hunting in the Microsoft Defender portal](/microsoft-365/security/defender/advanced-hunting-microsoft-defender).
165
169
166
-
167
170
## Test Identity Security Posture Management (ISPM) recommendations
168
171
169
172
We recommend simulating risky behavior in a test environment to trigger supported assessments and verify that they appear as expected. For example:
@@ -214,17 +217,31 @@ Test remediation actions on a test user. For example:
214
217
215
218
For more information, see [Remediation actions in Microsoft Defender for Identity](../remediation-actions.md).
216
219
217
-
## Deactivate Defender for Identity capabilities on your domain controller
220
+
## Offboarding steps
221
+
222
+
### Customers with domain controllers already onboarded to Defender for Endpoint
223
+
224
+
### Deactivate Defender for Identity capabilities on your domain controller
218
225
219
226
If you want to deactivate Defender for Identity capabilities on your domain controller, delete it from the **Sensors** page:
220
227
221
-
1. In the Defender portal, select **Settings** > **Identities** > **Sensors**.
228
+
1. Navigate to **Settings** > **Identities** > **Sensors**
222
229
2. Select the domain controller where you want to deactivate Defender for Identity capabilities, select **Delete**, and confirm your selection.
223
230
224
231
:::image type="content" source="media/activate-capabilities/3.jpg" lightbox="media/activate-capabilities/3.jpg" alt-text="Screenshot that shows how to deactivate a server.":::
225
232
226
233
Deactivating Defender for Identity capabilities from your domain controller doesn't remove the domain controller from Defender for Endpoint. For more information, see [Defender for Endpoint documentation](/microsoft-365/security/defender-endpoint/).
227
234
235
+
### Customers without domain controllers onboarded to Defender for Endpoint
236
+
237
+
### Offboard Defender for Identity capabilities on your domain controller
238
+
Download the Defender for Identity offboarding package from the [Microsoft Defender portal] (https://security.microsoft.com).
239
+
240
+
1. Navigate to **Settings** > **Identities** > **Activation**
241
+
2. Select Download offboarding package and save the file in a location you can access from your domain controller.
242
+
3. From the domain controller, extract the zip file you downloaded from the Microsoft Defender portal, and run the `DefenderForIdentityOnlyOffboardingScript_valid_until_YYYY-MM-DD.cmd` script as an Administrator.
243
+
4. To fully remove the sensor, navigate to **Settings** > **Identities** > **Sensors**, select the server and click Delete.
244
+
228
245
## Next steps
229
246
230
247
For more information, see [Manage and update Microsoft Defender for Identity sensors](../sensor-settings.md).
Copy file name to clipboardExpand all lines: ATPDocs/deploy/remote-calls-sam.md
+1-8Lines changed: 1 addition & 8 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -8,18 +8,11 @@ ms.topic: how-to
8
8
# Configure SAM-R to enable lateral movement path detection in Microsoft Defender for Identity
9
9
10
10
> [!IMPORTANT]
11
-
> Remote collection of local administrators' group members on endpoints (using SAM-R queries) feature in Microsoft Defender for Identity will be disabled by mid-May 2025. This changewill happen automatically by the specified dates. No admin action is required.
11
+
> The remote collection of local administrators group members from endpoints using SAM-R queriesin Microsoft Defender for Identity will be disabled by mid-May 2025. This data is currently used to build potential lateral movement path maps, which will no longer be updated after this change. The change will occur automatically by the specified date, and no administrative action is required.
12
12
>
13
13
14
14
Microsoft Defender for Identity mapping for [potential lateral movement paths](/defender-for-identity/understand-lateral-movement-paths) relies on queries that identify local admins on specific machines. These queries are performed with the SAM-R protocol, using the Defender for Identity [Directory Service account](directory-service-accounts.md) you configured.
15
15
16
-
> [!NOTE]
17
-
> This feature can potentially be exploited by an adversary to obtain the NTLM hash of the DSA account due to a Windows limitation in the SAM-R calls that allows downgrading from Kerberos to NTLM.
18
-
> The new Defender for Identity sensor (version 3.x) is not affected by this issue as it uses different detection methods.
19
-
>
20
-
> It is recommended to use a [low privileged DSA account](directory-service-accounts.md#grant-required-dsa-permissions). You can also [contact support](../support.md) to open a case and request to completely disable the [Lateral Movement Paths](../security-assessment-riskiest-lmp.md) data collection capability.
21
-
> Please note that this will result in reduced data available for the [attack path feature in Exposure Management](/security-exposure-management/review-attack-paths).
22
-
23
16
This article describes the configuration changes required to allow the Defender for Identity Directory Services Account (DSA) to perform the SAM-R queries.
Copy file name to clipboardExpand all lines: ATPDocs/understand-lateral-movement-paths.md
+5-1Lines changed: 5 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,9 +7,13 @@ ms.topic: conceptual
7
7
8
8
# Understand and investigate Lateral Movement Paths (LMPs) with Microsoft Defender for Identity
9
9
10
+
> [!IMPORTANT]
11
+
> The remote collection of local administrators group members from endpoints using SAM-R queries in Microsoft Defender for Identity will be disabled by mid-May 2025. This data is currently used to build potential lateral movement path maps, which will no longer be updated after this change. The change will occur automatically by the specified date, and no administrative action is required.
12
+
>
13
+
10
14
Lateral movement is when an attacker uses non-sensitive accounts to gain access to sensitive accounts throughout your network. Lateral movement is used by attackers to identify and gain access to the sensitive accounts and machines in your network that share stored sign-in credentials in accounts, groups and machines. Once an attacker makes successful lateral moves towards your key targets, the attacker can also take advantage and gain access to your domain controllers. Lateral movement attacks are carried out using many of the methods described in [Microsoft Defender for Identity Security Alerts](alerts-overview.md).
11
15
12
-
A key component of Microsoft Defender for Identity's security insights are Lateral Movement Paths or LMPs. Defender for Identity LMPs are visual guides that help you quickly understand and identify exactly how attackers can move laterally inside your network. The purpose of lateral movements within the cyber-attack kill chain are for attackers to gain and compromise your sensitive accounts using non-sensitive accounts. Compromising your sensitive accounts gets them another step closer to their ultimate goal, domain dominance. To stop these attacks from being successful, Defender for Identity LMPs give you easy to interpret, direct visual guidance on your most vulnerable, sensitive accounts. LMPs help you mitigate and prevent those risks in the future, and close attacker access before they achieve domain dominance.
16
+
A key component of Microsoft Defender for Identity's security insights is Lateral Movement Paths or LMPs. Defender for Identity LMPs are visual guides that help you quickly understand and identify exactly how attackers can move laterally inside your network. The purpose of lateral movements within the cyber-attack kill chain are for attackers to gain and compromise your sensitive accounts using non-sensitive accounts. Compromising your sensitive accounts gets them another step closer to their ultimate goal, domain dominance. To stop these attacks from being successful, Defender for Identity LMPs give you easy to interpret, direct visual guidance on your most vulnerable, sensitive accounts. LMPs help you mitigate and prevent those risks in the future, and close attacker access before they achieve domain dominance.
We've extended the device information we send to Defender for Cloud Apps including device names, IP addresses, account UPNs and used port. For more information about our integration with Defender for Cloud Apps, see [Using Azure ATP with Defender for Cloud Apps](/defender-for-identity/deploy-defender-identity).
909
909
910
910
- Version includes improvements and bug fixes for internal sensor infrastructure.
Copy file name to clipboardExpand all lines: ATPDocs/whats-new.md
+9-1Lines changed: 9 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -24,8 +24,16 @@ For updates about versions and features released six months ago or earlier, see
24
24
25
25
## May 2025
26
26
27
+
### Expanded New Sensor Deployment Support for Domain Controllers (Preview)
28
+
Defender for Identity now supports deploying its new sensor on Domain Controllers without requiring Defender for Endpoint onboarding. This simplifies sensor activation and expands deployment flexibility. [Learn more](deploy/activate-capabilities.md).
29
+
30
+
31
+
### Improved Visibility into Defender for Identity New Sensor Eligibility in the Activation page
32
+
The Activation Page now displays all servers from your device inventory, including those not currently eligible for the new Defender for Identity sensor. This enhancement increases transparency into sensor eligibility, helping you identify non-eligible servers and take action to update and onboard them for enhanced identity protection.
33
+
34
+
27
35
### Local administrators collection (using SAM-R queries) feature will be disabled
28
-
Remote collection of local administrators' group members on endpoints (using SAM-R queries) feature in Microsoft Defender for Identity will be disabled by mid-May 2025. The details collected are used to build the potential lateral movement paths map. Alternative methods are currently being explored. This change will happen automatically by the specified dates. No admin action is required.
36
+
The remote collection of local administrators group members from endpoints using SAM-R queriesin Microsoft Defender for Identity will be disabled by mid-May 2025. This data is currently used to build potential lateral movement path maps, which will no longer be updated after this change. An alternative method is being explored. The change will occur automatically by the specified date, and no administrative action is required.
Copy file name to clipboardExpand all lines: CloudAppSecurityDocs/app-activity-threat-hunting.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,6 @@
1
1
---
2
2
title: Hunt for threats in app activities | Microsoft Defender for Cloud Apps
3
-
ms.date: 05/28/2023
3
+
ms.date: 05/23/2025
4
4
ms.topic: how-to
5
5
description: Learn how app governance in Microsoft Defender for Cloud Apps helps you hunt for resources accessed and activities carried out by apps in your environment.
0 commit comments