Forum Discussion
ThomasFriisPoulsen
Jul 03, 2019Iron Contributor
ATA showing a user as an member of Domain Admin who has been deleted for 40 days?
Hi all, ATA shows a member of "Domain Admins" who has been deleted for 40 days? I have verified that the user doesn’t exist in AD. When I look at the user in ATA, the last event is: “Account's passw...
EliOfek
Microsoft
ThomasFriisPoulsen , see
https://docs.microsoft.com/en-us/advanced-threat-analytics/ata-prerequisites#before-you-start
"Recommended: User should have read-only permissions on the Deleted Objects container. This allows ATA to detect bulk deletion of objects in the domain. For information about configuring read-only permissions on the Deleted Objects container, see the Changing permissions on a deleted object container section in the View or Set Permissions on a Directory Objectarticle."
Besides detection, this can help us know an account was deleted, try this and see if it resolves the issue.
ThomasFriisPoulsen
Jul 03, 2019Iron Contributor
Thanks. :)
We will look into it. I'll keep you updated.EliOfek