You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: ATPDocs/deploy/configure-windows-event-collection.md
+6-6Lines changed: 6 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -58,7 +58,7 @@ Use the following procedures to configure auditing on the domain controllers tha
58
58
59
59
This procedure describes how to modify your domain controller's Advanced Audit Policy settings as needed for Defender for Identity via the UI.
60
60
61
-
**Related health issue:**[Directory Services Advanced Auditing is not enabled as required](../health-alerts.md#directory-services-advanced-auditing-is-not-enabled-as-required)
61
+
**Related health issue:**[Directory Services Advanced Auditing is not enabled as required](../health-alerts.md#directory-services-advanced-auditing-isn't-enabled-as-required)
62
62
63
63
To configure your Advanced Audit Policy settings:
64
64
@@ -113,7 +113,7 @@ For more information, see the [auditpol reference documentation](/windows-server
113
113
114
114
The following actions describe how to modify your domain controller's Advanced Audit Policy settings as needed for Defender for Identity by using PowerShell.
115
115
116
-
**Related health issue:**[Directory Services Advanced Auditing is not enabled as required](../health-alerts.md#directory-services-advanced-auditing-is-not-enabled-as-required)
116
+
**Related health issue:**[Directory Services Advanced Auditing is not enabled as required](../health-alerts.md#directory-services-advanced-auditing-isn't-enabled-as-required)
117
117
118
118
To configure your settings, run:
119
119
@@ -166,7 +166,7 @@ This section describes the extra configuration steps that you need for auditing
166
166
> - Domain group policies to collect Windows event 8004 should be applied *only* to domain controllers.
167
167
> - When a Defender for Identity sensor parses Windows event 8004, Defender for Identity NTLM authentication activities are enriched with the server-accessed data.
168
168
169
-
**Related health issue:**[NTLM Auditing is not enabled](../health-alerts.md#ntlm-auditing-is-not-enabled)
169
+
**Related health issue:**[NTLM Auditing is not enabled](../health-alerts.md#ntlm-auditing-isn't-enabled)
170
170
171
171
To configure NTLM auditing:
172
172
@@ -191,7 +191,7 @@ To collect events for object changes, such as for event 4662, you must also conf
191
191
> [!IMPORTANT]
192
192
> Review and audit your policies (via the [UI](#configure-advanced-audit-policy-settings-from-the-ui) or [PowerShell](#configure-advanced-audit-policy-settings-by-using-powershell)) before you enable event collection, to ensure that the domain controllers are properly configured to record the necessary events. If this auditing is configured properly, it should have a minimal effect on server performance.
193
193
194
-
**Related health issue:**[Directory Services Object Auditing is not enabled as required](../health-alerts.md#directory-services-object-auditing-is-not-enabled-as-required)
194
+
**Related health issue:**[Directory Services Object Auditing is not enabled as required](../health-alerts.md#directory-services-object-auditing-isn't-enabled-as-required)
195
195
196
196
To configure domain object auditing:
197
197
@@ -245,7 +245,7 @@ To configure domain object auditing:
245
245
246
246
## Configure auditing on AD FS
247
247
248
-
**Related health issue:**[Auditing on the AD FS container is not enabled as required](../health-alerts.md#auditing-on-the-adfs-container-is-not-enabled-as-required)
248
+
**Related health issue:**[Auditing on the AD FS container is not enabled as required](../health-alerts.md#auditing-on-the-adfs-container-isn't-enabled-as-required)
249
249
250
250
To configure auditing on Active Directory Federation Services (AD FS):
251
251
@@ -330,7 +330,7 @@ To configure auditing on Microsoft Entra Connect servers:
330
330
>[!NOTE]
331
331
> The configuration container audit is required only for environments that currently have or previously had Microsoft Exchange, as these environments have an Exchange container located within the domain's Configuration section.
332
332
333
-
**Related health issue:** [Auditing on the Configuration container is not enabled as required](../health-alerts.md#auditing-on-the-configuration-container-is-not-enabled-as-required)
333
+
**Related health issue:** [Auditing on the Configuration container is not enabled as required](../health-alerts.md#auditing-on-the-configuration-container-isn't-enabled-as-required)
334
334
335
335
1. Open the ADSI Edit tool. Select **Start** > **Run**, enter `ADSIEdit.msc`, and then select **OK**.
Copy file name to clipboardExpand all lines: ATPDocs/whats-new-archive.md
+7-7Lines changed: 7 additions & 7 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -129,7 +129,7 @@ Released May 29, 2023
129
129
130
130
Released May 15, 2023
131
131
132
-
- New health alert for verifying that ADFS Container Auditing is configured correctly. For more information, see [Microsoft Defender for Identity sensor health alerts](health-alerts.md#auditing-on-the-adfs-container-is-not-enabled-as-required).
132
+
- New health alert for verifying that ADFS Container Auditing is configured correctly. For more information, see [Microsoft Defender for Identity sensor health alerts](health-alerts.md#auditing-on-the-adfs-container-isn't-enabled-as-required).
133
133
134
134
- The Microsoft Defender 365 **Identity** page includes UI updates for the lateral movement path experience. No functionality was changed. For more information, see [Understand and investigate Lateral Movement Paths (LMPs) with Microsoft Defender for Identity](understand-lateral-movement-paths.md).
135
135
@@ -151,7 +151,7 @@ In Microsoft Defender XDR, create rule conditions based on evidence types, and t
151
151
152
152
Released April 23, 2023
153
153
154
-
- New health alert for verifying that Directory Services Configuration Container Auditing is configured correctly, as described in the [health alerts page](health-alerts.md#auditing-on-the-configuration-container-is-not-enabled-as-required).
154
+
- New health alert for verifying that Directory Services Configuration Container Auditing is configured correctly, as described in the [health alerts page](health-alerts.md#auditing-on-the-configuration-container-isn't-enabled-as-required).
155
155
- New workspaces for AD tenants mapped to New Zealand are created in the Australia East region. For the most current list of regional deployment, see [Defender for Identity components](architecture.md#defender-for-identity-components).
156
156
- Version includes improvements and bug fixes for internal sensor infrastructure.
157
157
@@ -163,7 +163,7 @@ Released March 27, 2023
163
163
164
164
- We're in the process of disabling the SAM-R honeytoken alert. While these types of accounts should never be accessed or queried, certain legacy systems might use these accounts as part of their regular operations. If this functionality is necessary for you, you can always create an advanced hunting query and use it as a custom detection. We're also reviewing the LDAP honeytoken alert over the coming weeks, but remains functional for now.
165
165
166
-
- We fixed detection logic issues in the [Directory Services Object Auditing health alert](health-alerts.md#directory-services-object-auditing-is-not-enabled-as-required) for non-English operating systems, and for Windows 2012 with Directory Services schemas earlier than version 87.
166
+
- We fixed detection logic issues in the [Directory Services Object Auditing health alert](health-alerts.md#directory-services-object-auditing-isn't-enabled-as-required) for non-English operating systems, and for Windows 2012 with Directory Services schemas earlier than version 87.
167
167
168
168
- We removed the prerequisite of configuring a Directory Services account for the sensors to start. For more information, see [Microsoft Defender for Identity Directory Service account recommendations](directory-service-accounts.md).
169
169
@@ -232,9 +232,9 @@ Released January 22, 2023
232
232
233
233
Released January 10, 2023
234
234
235
-
- New health alert for verifying that Directory Services Object Auditing is configured correctly, as described in the [health alerts page](health-alerts.md#directory-services-object-auditing-is-not-enabled-as-required).
235
+
- New health alert for verifying that Directory Services Object Auditing is configured correctly, as described in the [health alerts page](health-alerts.md#directory-services-object-auditing-isn't-enabled-as-required).
236
236
237
-
- New health alert for verifying that the sensor’s power settings are configured for optimal performance, as described in the [health alerts page](health-alerts.md#power-mode-is-not-configured-for-optimal-processor-performance).
237
+
- New health alert for verifying that the sensor’s power settings are configured for optimal performance, as described in the [health alerts page](health-alerts.md#power-mode-isn't-configured-for-optimal-processor-performance).
238
238
239
239
- We've added [MITRE ATT&CK](https://attack.mitre.org/) information to the IdentityLogonEvents, IdentityDirectoryEvents and IdentityQueryEvents tables in Microsoft Defender XDR Advanced Hunting. In the **AdditionalFields** column, you can find details about the Attack Techniques and the Tactic (Category) associated with some of our logical activities.
240
240
@@ -256,7 +256,7 @@ Released December 7, 2022
256
256
257
257
Released November 10, 2022
258
258
259
-
- New health alert for verifying that Directory Services Advanced Auditing is configured correctly, as described in the [health alerts page](health-alerts.md#directory-services-advanced-auditing-is-not-enabled-as-required).
259
+
- New health alert for verifying that Directory Services Advanced Auditing is configured correctly, as described in the [health alerts page](health-alerts.md#directory-services-advanced-auditing-isn't-enabled-as-required).
260
260
261
261
- Some of the changes introduced in [Defender for Identity release 2.191](#defender-for-identity-release-2191) regarding honeytoken alerts were not enabled properly. Those issues have been resolved now.
262
262
@@ -282,7 +282,7 @@ To learn more about this attack, read [this blog post](https://techcommunity.mic
282
282
283
283
Released October 23, 2022
284
284
285
-
- New health alert for verifying that the NTLM Auditing is enabled, as described in the [health alerts page](health-alerts.md#ntlm-auditing-is-not-enabled).
285
+
- New health alert for verifying that the NTLM Auditing is enabled, as described in the [health alerts page](health-alerts.md#ntlm-auditing-isn't-enabled).
286
286
287
287
- Version includes improvements and bug fixes for internal sensor infrastructure.
0 commit comments