Forum Discussion
No updates to "Stop clear text credentials exposure" after migrating our MDI sensors to v3
Since migrating our domain controllers to the v3 sensor, the "Stop clear text credentials exposure" recommendation is no longer updating. The latest "Last seen" date correlates with the date we performed the migration, and I know we have a couple entities that have not yet been remediated.
If I run a query on the IdentityQueryEvents table in Advanced Hunting, I'm still seeing LDAP queries.
Anyone else seeing this?
1 Reply
The recommendation’s “Last seen” date stopping when the domain controllers moved to sensor v3 is useful correlation, but IdentityQueryEvents rows only confirm that identity-query telemetry is arriving; ordinary LDAP searches do not prove clear-text credential exposure. Check Settings > Identities > On-premises > Sensors and confirm each migrated controller shows Up to date, Running, and healthy. Verify each server is onboarded to Defender for Endpoint, meets the supported Windows Server and cumulative-update prerequisites, and has no sensor alerts. In Advanced Hunting, inspect the affected period by controller, protocol, port, action type, and AdditionalFields, then compare it with an entity still listed by the recommendation. Allow a complete daily assessment cycle after generating a controlled test event. If telemetry is healthy but “Last seen” remains frozen, collect sensor health details, timestamps, and hunting results and open a Microsoft support case. Microsoft documents no administrator command to force-refresh this recommendation.