Forum Discussion

manojviduranga's avatar
manojviduranga
Iron Contributor
Mar 14, 2023

Question on configuring SAM-R to enable lateral movement path detection

Hey Defender Peeps,
 
Referring to this KB from MS -Configure SAM-R to enable lateral movement path detection - Microsoft Defender for Identity | Microsoft Learn Seeking some advice on "configuring SAM-R to enable lateral movement path detection in Microsoft Defender for Identity". Customer don't currently have the "Network access - Restrict clients allowed to make remote calls to SAM" policy defined within their environment, and unsure of the implication of doing so – assume by enabling the policy across their domain (excluding Domain Controllers) and adding the Directory Service account with Remote Access, any other accounts currently making remote calls to SAM will start failing?.
 
The MS documentation around the policy setting itself mentions the ability to configure audit-only mode for the change, but applying that across the PROD environment means we'd be needing to look for 8 different event IDs across every server/workstation in every domain in order to figure out what other accounts are making remote calls to SAM and what (i.e. it will take a significant amount of time).
 
Can someone advise what Best Practice would be followed for enabling the policy/what accounts should be added in addition to the Directory Service account? 
 
Any thoughts/advises are highly appreciated 
 
Thank you !!
  • thalpius's avatar
    thalpius
    Brass Contributor
    By default, the SAM can be accessed remotely via SAMR by any authenticated user. So, to be honest, I don't see why you need to set it in the first place. Since you need to set a Directory Service Account, it is always authenticated and should use the SAM-R protocol anyway.

    And the "Access this computer from the network setting" is not needed if you didn't set it:
    "The setting is not enabled by default. If you have not enabled it previously, you don't need to modify it to allow Defender for Identity to make remote calls to SAM."

    I can confirm at the program team and come back on this one.

Resources