Forum Discussion
NinjaKitty
Sep 09, 2020Brass Contributor
Unsecure Kerberos delegation still visible after mitigation
Hello,
Azure ATP noticed some accounts with unsecure Kerberos delegation. We deleted the affected accounts in active directory. Actually the warning should disapere after that but is still visible. I dont unterstand.
NinjaKitty
Make sure the AD account configured in the console has read access to AD's deleted items container.
7 Replies
- Or TsemahFormer Employee
Azure ATP needs to detect that these accounts are actually deleted, have you seen the "Deleted" tag added to these user account pages in AATP?
- NinjaKittyBrass Contributor
The accounts are still marked as "active" in AATP even though they are deleted in active directory.
- EliOfek
Microsoft
NinjaKitty
Make sure the AD account configured in the console has read access to AD's deleted items container.