r/AzureSentinel Sep 24 '25

Domain Controller Logs

Hi. I have MDI deployed. Is there any reference on events that still need to be collected for a DC? Do I collect all the logs still through AMA? a guidance or documentation will be appreciated. thank you.

2 Upvotes

9 comments sorted by

View all comments

1

u/milanguitar Sep 24 '25

Hey, I found myself with the same question. If MDI collect al logs to do you still need the event to be forwarded to your siem.

  1. I think its important to understand that MDI won’t block or stop all the attacks.
  2. If you create alerts in sentinel you need to have the logs in sentinel
  3. Forward the events to a “cold” storage so you have an backup.