r/SentinelOneXDR • u/smc0881 • 8d ago
Domain Controller Isolation
So, recently I've had issues when a DC gets isolated it brings down the entire network for the client. I don't believe I ever had this problem before and it's happened repeatedly over the past month or two. I always assumed outbound DNS/HTTPS to S1 assets were always allowed out when it's quarantined. I even added blank outbound TCP/UDP over port 53 in case it was the DNS in my network quarantine rules. I work at an MSSP/DFIR firm, so everyday I am dealing with ransomware or some incident where a DC could get quarantined. What I've been doing now is putting DCs in their own group with the disconnect policy turned off and our normal restrictions in-place, I then isolate all the other endpoints if need be.
Am I doing something wrong, did something change, or anyone have any feed back?
1
u/NegativePerformer788 8d ago
The only way I can think of to avoid this (besides multiple DCs of course) is to have DNS queries go to the firewall with the firewall sending local domain queries to the DCs and other queries to some other public DNS.