New Defender for Identity health issue for missing Windows events from a domain controller
🚨 The Signal: Defender for Identity now alerts when domain controllers fail to send Windows events. This improves visibility into potential event collection gaps, crucial for detecting identity-based threats and maintaining a robust security posture.
The Impact
Security teams are affected by improved visibility into critical event logging, reducing the risk of undetected identity attacks.
- Security Teams: Reduced risk of undetected identity-based attacks due to improved event collection monitoring.
- Identity Administrators: Enhanced ability to troubleshoot and ensure complete event data for domain controllers.
- Compliance Officers: Better assurance of meeting logging and monitoring requirements for critical infrastructure.
The Action
- Monitor the 'Sensors health issues' tab in Microsoft Defender XDR for new 'No Windows events received from domain controller' alerts.
- If an alert appears, review the affected domain controller's event forwarding and collection configuration.
- Verify that required Windows events (e.g., Security, System, Directory Service) are being generated and forwarded.
- Consult Microsoft Defender for Identity documentation for specific event collection requirements and troubleshooting.
- If issues persist, contact Microsoft Support for further assistance.
Domain: Defender · Impact: medium · Workload: Microsoft Defender