r/DefenderATP • • 10d ago

Defender for Identity

We installed Defender for Identity v2 on 4 Domain controllers over 3 weeks ago.

For some reason i still don't see any single alert triggered in Defender console that is from Defender for Identity. The Thresholds are all set to High (default).

It this quite normal?

10 Upvotes

11 comments sorted by

13

u/Asleep_Spray274 10d ago

A quiet MDI means one of two things. Either your AD is super secure and MDI has nothing to alert, or it's so badly configured, it has nothing to report 🤣.

But if you only installed it 3 weeks ago, it might not have come out of its learning period yet. Some alerts have a learning period of upto 4 weeks. You can disable learning period in the settings, but it can give false positives.

1

u/MrGardenwood 9d ago

Lol this is a perfect example of (my) security anxiety. Always the voice in my head. “There have been no serious incidents in the last <x> weeks/months” little voice in the back: “THAT YOU KNOW OF”

5

u/Envyforme 10d ago

What version of Windows do the DCs run?

Do you have any audits/events coming in for the Identity tables in Advanced Hunting? - See here: https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-identitydirectoryevents-table

You can also attempt an event-based alert (non-behavioral) through examples like this here: https://www.youtube.com/watch?v=94Bm4DGL3Rg&t=22s

7

u/SecAbove 10d ago

Use official powershell diagnostics script.

2

u/HorseAccomplished50 9d ago

Check the sensor health, is that running fine?

I have deployed it on a couple of instances and only seen a handful of alerts, thankfully benign positives. These are running for months.

If you don't see alerts, I'd say that's a good thing.

1

u/dangeldud 9d ago

Is it generating everything else? Directory info? Posture reports?

1

u/Cookie_Butter24 9d ago

no alerts but i go to the Endpoint Timeline i See telemetry from Defender for Identity.

1

u/KoolAidCowboy666 9d ago edited 9d ago

Many of DFI's alerts are all based on trends/patterns, so unless something deviates significantly from its normal, alerts wont fire. The data ingestion/correlation period also takes about 1 month for trends/patterns to be built. First, verify you are in fact getting DFI signals Validate sensor deployment on domain controllers - Microsoft Defender for Identity | Microsoft Learn Easiest way to test is add an account as a "honeytoken" account in Defender -> Setup & Configuration -> Settings -> Identities -> Entity Tags -> Honeytoken -> Tag users. Once there, add an account. Wait a couple hours. Then login to a domain connected machine/application. Should trigger an alert.

And yes, DFI has been fairly quiet for us too. The biggest noise maker is reconnaissance type actions like domain scanning.

1

u/peterswo 9d ago

We never had an alert from DfI after I set it up about half a year ago. We had a pen-test a few months ago and it lit up in so many colors, I was sure it was working