Forum Discussion
Incorrect Identification of Local Admin in Defender for Endpoint
Hi italicize_valiant , can you confirm Group is "Administrator" or Administratorer ? It looks like getting a different object class, what you can do is, go to computer management console and check the administrator group as per this screenshot and confirm or share the screenshot.
Hi,
Yes, I can confirm that “Administratorer” is the same as your image. Also, the same users and groups are present.
That why I don't understand how and why MDE is getting this information.
- duliprbMar 14, 2025MCT
It looks like your filtering options are different, As I told "Administratorer" has a spelling issue. Appreciate if you could share a screenshot. :)
- duliprbMar 19, 2025MCT
oh :), in that case it could pose security risk, check windows sign in logs to see any recent logins especially 4624, could be privilege escalation activity, has MDE detected anything. ?
- italicize_valiantMar 19, 2025Copper Contributor
"Administratorer" is just Administrator in Danish :)