Forum Discussion
Exclude account from secure score 'Remove non-admin accounts with DCSync permissions'
I do (i think :)) have a legit MSOL_522f75393cfe account which needs the DCSync permissions (Entra Connect) so how can I exclude this account from being detected to this rule?
I can find some 'exceptions';
Microsoft Defender | Settings | Identities | Actions and exclusions | Global excluded entities
https://security.microsoft.com/settings/identities?tabid=globalExclude&tid=e681ca77-e7ac-448f-b649-6c82feadfe8e
I put the account there so it has the 'Exclude entities from all detection rules' option.
Is this the only way (i prefer not to exlude the account but only an exception of the detection) to exclude an account?
5 Replies
- esatyaman
Microsoft
Have you tried to exclude entities based on specific detection rules? This will allow you to exclude users/devices/IPs for a particular detection rule or alert type in MDI.
Please navigate to security.microsoft.com > Settings > Identities > Exclusions by detection rule.
- Arian_van_der_PijlIron Contributor
Hi esatyaman thanks for the reply. I failed earlier to match the 'Remove non-admin accounts with DCSync permissions' with 'Suspected DCSync attack (replication of directory services)' as you pointed out. I did enable the exclusion and will wait (and report) if this is the exclusion that works. (and removed the user from 'Global excluded entities')
Thanks!- AeuwhaCopper Contributor
Did this work for your for the secure score metric? It's annoying me as well. Arian_van_der_Pijl