New Defender for Identity health issue for missing Windows events from a domain controller

🚨 The Signal: Defender for Identity now alerts when domain controllers fail to send Windows events. This improves visibility into potential event collection gaps, crucial for detecting identity-based threats and maintaining a robust security posture.

The Impact

Security teams are affected by improved visibility into critical event logging, reducing the risk of undetected identity attacks.

  • Security Teams: Reduced risk of undetected identity-based attacks due to improved event collection monitoring.
  • Identity Administrators: Enhanced ability to troubleshoot and ensure complete event data for domain controllers.
  • Compliance Officers: Better assurance of meeting logging and monitoring requirements for critical infrastructure.

The Action

  1. Monitor the 'Sensors health issues' tab in Microsoft Defender XDR for new 'No Windows events received from domain controller' alerts.
  2. If an alert appears, review the affected domain controller's event forwarding and collection configuration.
  3. Verify that required Windows events (e.g., Security, System, Directory Service) are being generated and forwarded.
  4. Consult Microsoft Defender for Identity documentation for specific event collection requirements and troubleshooting.
  5. If issues persist, contact Microsoft Support for further assistance.

Domain: Defender · Impact: medium · Workload: Microsoft Defender