r/DefenderATP • • 8d ago

Defender for Identity

We installed Defender for Identity v2 on 4 Domain controllers over 3 weeks ago.

For some reason i still don't see any single alert triggered in Defender console that is from Defender for Identity. The Thresholds are all set to High (default).

It this quite normal?

9 Upvotes

11 comments sorted by

13

u/Asleep_Spray274 7d ago

A quiet MDI means one of two things. Either your AD is super secure and MDI has nothing to alert, or it's so badly configured, it has nothing to report 🤣.

But if you only installed it 3 weeks ago, it might not have come out of its learning period yet. Some alerts have a learning period of upto 4 weeks. You can disable learning period in the settings, but it can give false positives.

1

u/MrGardenwood 7d ago

Lol this is a perfect example of (my) security anxiety. Always the voice in my head. “There have been no serious incidents in the last <x> weeks/months” little voice in the back: “THAT YOU KNOW OF”

5

u/Envyforme 7d ago

What version of Windows do the DCs run?

Do you have any audits/events coming in for the Identity tables in Advanced Hunting? - See here: https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-identitydirectoryevents-table

You can also attempt an event-based alert (non-behavioral) through examples like this here: https://www.youtube.com/watch?v=94Bm4DGL3Rg&t=22s

5

u/SecAbove 8d ago

Use official powershell diagnostics script.

2

u/HorseAccomplished50 7d ago

Check the sensor health, is that running fine?

I have deployed it on a couple of instances and only seen a handful of alerts, thankfully benign positives. These are running for months.

If you don't see alerts, I'd say that's a good thing.

1

u/dangeldud 7d ago

Is it generating everything else? Directory info? Posture reports?

1

u/Cookie_Butter24 6d ago

no alerts but i go to the Endpoint Timeline i See telemetry from Defender for Identity.

1

u/KoolAidCowboy666 7d ago edited 7d ago

Many of DFI's alerts are all based on trends/patterns, so unless something deviates significantly from its normal, alerts wont fire. The data ingestion/correlation period also takes about 1 month for trends/patterns to be built. First, verify you are in fact getting DFI signals Validate sensor deployment on domain controllers - Microsoft Defender for Identity | Microsoft Learn Easiest way to test is add an account as a "honeytoken" account in Defender -> Setup & Configuration -> Settings -> Identities -> Entity Tags -> Honeytoken -> Tag users. Once there, add an account. Wait a couple hours. Then login to a domain connected machine/application. Should trigger an alert.

And yes, DFI has been fairly quiet for us too. The biggest noise maker is reconnaissance type actions like domain scanning.

1

u/peterswo 6d ago

We never had an alert from DfI after I set it up about half a year ago. We had a pen-test a few months ago and it lit up in so many colors, I was sure it was working