Forum Discussion
Installing sensors across several data centers: Standalone vs. ATP Sensor
Sensor duplication (monitoring a DC with more than one sensor) is not supported.
For best experience, use the integrated sensor, as it provide the complete set of detections AATP offers.
Standalone sensors provide only partial detection.
- jbchrisJul 31, 2019Copper Contributor
So if I understand you correctly, ATP Sensors are installed on all DC's and send alerts to ATP Cloud service. All other non-domain controllers are set up to send traffic to the standalone sensor and then the standalone sensor sends traffic to ATP.
Is this correct?
- EliOfekJul 31, 2019
Microsoft
jbchris , pretty much, the sensor collects data we think is relative for detection and send it to Azure.
in standalone, you need to mirror traffic and forward windows events, but there are stuff you can't forward like ETW events. so the integrated sensor is far better is possible.