Forum Discussion

Arian_van_der_Pijl's avatar
Arian_van_der_Pijl
Iron Contributor
Feb 29, 2024

Exclude account from secure score 'Remove non-admin accounts with DCSync permissions'

I do (i think :)) have a legit MSOL_522f75393cfe account which needs the DCSync permissions (Entra Connect) so how can I exclude this account from being detected to this rule?


I can find some 'exceptions';
Microsoft Defender | Settings | Identities | Actions and exclusions | Global excluded entities
https://security.microsoft.com/settings/identities?tabid=globalExclude&tid=e681ca77-e7ac-448f-b649-6c82feadfe8e 

I put the account there so it has the 'Exclude entities from all detection rules' option.

Is this the only way (i prefer not to exlude the account but only an exception of the detection) to exclude an account?

5 Replies

  • Hi Arian_van_der_Pijl,

     

    Have you tried to exclude entities based on specific detection rules? This will allow you to exclude users/devices/IPs for a particular detection rule or alert type in MDI.

     

    Please navigate to security.microsoft.com > Settings > Identities > Exclusions by detection rule.

     

     

    • Arian_van_der_Pijl's avatar
      Arian_van_der_Pijl
      Iron Contributor

      Hi esatyaman thanks for the reply. I failed earlier to match the 'Remove non-admin accounts with DCSync permissions' with 'Suspected DCSync attack (replication of directory services)' as you pointed out. I did enable the exclusion and will wait (and report) if this is the exclusion that works. (and removed the user from 'Global excluded entities')
      Thanks!

Resources