Azure AD Join SSO to on prem resources

%3CLINGO-SUB%20id%3D%22lingo-sub-1311571%22%20slang%3D%22en-US%22%3EAzure%20AD%20Join%20SSO%20to%20on%20prem%20resources%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1311571%22%20slang%3D%22en-US%22%3E%3CP%3EIs%20anyone%20using%20this%2C%20and%20have%20Microsoft%20ATA%20setup%20as%20well%3F%3CBR%20%2F%3EIs%20it%20expected%20that%20it'll%20generate%20overpass-the-hash%20alerts%20in%20ATA%3F%3C%2FP%3E%3CDIV%20class%3D%22mceNonEditable%20lia-copypaste-placeholder%22%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%20class%3D%22mceNonEditable%20lia-copypaste-placeholder%22%3E%26nbsp%3B%3C%2FDIV%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%222020-04-16%2011_58_54-Microsoft%20Advanced%20Threat%20Analytics%20_%20Encryption%20downgrade%20activity%20and%2024%20more%20.png%22%20style%3D%22width%3A%20927px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F184705i9C7EFAECE8575BCD%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%222020-04-16%2011_58_54-Microsoft%20Advanced%20Threat%20Analytics%20_%20Encryption%20downgrade%20activity%20and%2024%20more%20.png%22%20alt%3D%222020-04-16%2011_58_54-Microsoft%20Advanced%20Threat%20Analytics%20_%20Encryption%20downgrade%20activity%20and%2024%20more%20.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1311571%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMicrosoft%20ATA%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Senior Member

Is anyone using this, and have Microsoft ATA setup as well?
Is it expected that it'll generate overpass-the-hash alerts in ATA?

 
 

2020-04-16 11_58_54-Microsoft Advanced Threat Analytics _ Encryption downgrade activity and 24 more .png

0 Replies