Forum Discussion
PeterJoInobits
Jul 18, 2022Brass Contributor
Defender for Endpoint on Domain Controllers and restricting control
Hi Community I've got a customer who's busy deploying Windows Defender and has purchased several thousand Defender for Endpoint on Server licenses. The AD team has raised some concerns on wh...
yongrheemsft
Microsoft
Jul 20, 2022PeterJoInobits, the first question is, are there more than 2 Global Admin's? If so, probably needs to be looked into, but that is not a topic that we will go into this forum. Yes, PIM + MFA should be used by Global Admin account, but also for other Identity accounts managing your infrastructure. You then would tag the Domain Controllers (DC's), and assign it to a "Device Group", which then you would assign a MDE RBAC "Security Group" for the SOC/IR folks that would be able to see, and/or investigate and/or remediate. Hope this helps, Yong