Forum Discussion
SAM-R
- Jun 26, 2022
Hello skipster311-175,
1. It is required. "a modification to Group Policy must be made to add the Defender for Identity service account"
2. The default value for 2016 and later is Administrators: Remote Access: Allow. It means that remote SAM won't be allowed for the MDfI account but it must be allowed for it in order to work correctly.
"The default security descriptor on computers beginning with Windows 10 version 1607 and Windows Server 2016 allows only the local (built-in) Administrators group remote access to SAM on non-domain controllers"
Hello skipster311-175,
1. It is required. "a modification to Group Policy must be made to add the Defender for Identity service account"
2. The default value for 2016 and later is Administrators: Remote Access: Allow. It means that remote SAM won't be allowed for the MDfI account but it must be allowed for it in order to work correctly.
"The default security descriptor on computers beginning with Windows 10 version 1607 and Windows Server 2016 allows only the local (built-in) Administrators group remote access to SAM on non-domain controllers"