Forum Discussion
Monitoring AAD Connect
Does MDI have any special functionality for monitoring AAD Connect servers?
Should MDI be installed on AAD Connect Servers? if not, why not?
- Joe StockerBronze ContributorNo, MDI is not supported for AAD Connect Servers. Only Domain Controllers and AD FS Servers. https://docs.microsoft.com/en-us/defender-for-identity/architecture#defender-for-identity-components
- Dean_GrossSilver ContributorThanks for the confirmation. Given that it’s a Tier 0 resource, I wonder why not. Do you think that it should be?
- SebastianRogersCopper Contributor
Dean_Gross if its like the older on premise ATA then they use some of the same components so would cause a conflict in operation in certain configs and cause an issue with both products, I would see no main value, from the identities as you are getting the info from on prem AD servers and the Azure AAD logs. so it would just be duplication of events if AAD connect servers had the MDI agent installed. and the HIDS part would have no value. as the no workstations directly talk to the AAD connect server its more of a pull the info for on prem and push to 365 service.
if it just to monitor if there is an issue with the server then there is a base monitor that show in the office 365 portal that show the last sync but you can always uses log analytics/ sentinel with an MMA agent to monitor the server and trigger an alert when there an issue with AAD connect server