Forum Discussion
jonghwamun
Microsoft
Jul 07, 2022Inquiries related to maximum lifetime for user ticket.
Good afternoon, my Cx was curious about some questions that came along with Golden Ticket Alert.
I tried to figure it out, but was not able to locate sources for the questions. Here are the questions.
Also, I attached the snapshot for better understanding. Thank you in advance!
What exactly does "Due to insufficient source data, default maximum lifetime for user tickets" mean?
> About this I assume there is no existing policy set up yet for the particular case, so it applied default settings. Can anybody elaborate what this means?
What source data is it looking for and how can there be a insufficient amount of it?
> I am not sure, any insights will be appreciated.
An additional question, What does this alert think the default life of a golden ticket is?
> I was not sure on this either. Please provide any insights.
V/r,
- gurulee73Copper ContributorWere you able to resolve this and determine if the MDI sensor was unable to ready the policy value?
- gurulee73Copper ContributorI checked the MDI sensors and I am not seeing any open health issues being reported. If the sensor is unable to read the domain policy, would it be smart enough to consider this a health issue?
- EliOfek
Microsoft
This comment means that MDI failed to read the default Kerberos policy for the domain (you can probably find error in the Sensor logs).
Since we failed to read it , we assume the default in AD which is 10 hours.
This is important , as if the customer knows the default policy is set to something else, larger, that most chances are this is a false positive, and you need to find out why weren't we able to read the policy so it won't happen again.- gurulee73Copper ContributorWe are getting flooded with MDI alerts 'Suspected Golden Ticket usage (time anomaly) on one endpoint' and we verified the default domain policy is set to 10 hours for 'maximum lifetime for a user ticket'.
Is there something we should be looking for on the MDI sensor logs that would point to the sensor not being able to read the policy?