Forum Widgets
Latest Discussions
No updates to "Stop clear text credentials exposure" after migrating our MDI sensors to v3
Since migrating our domain controllers to the v3 sensor, the "Stop clear text credentials exposure" recommendation is no longer updating. The latest "Last seen" date correlates with the date we performed the migration, and I know we have a couple entities that have not yet been remediated. If I run a query on the IdentityQueryEvents table in Advanced Hunting, I'm still seeing LDAP queries. Anyone else seeing this?RyanSteele-CoVAug 17, 2026Steel Contributor91Views1like1CommentDomain controller showing "Not ready for migration"
I want to get the MDI sensor upgraded to v3 on our domain controllers. When I go into Settings > Sensors, two of our DCs are listed as "Ready for migration", but the third says "Not ready for migration". As far as I can tell, this DC meets all the prerequisites listed at Migrate from sensor v2.x to sensor v3.x - Microsoft Defender for Identity | Microsoft Learn. In the Troubleshooting section of that article, it says "hover over the status on the Sensors page to see a tooltip that lists the reasons the server doesn't meet the migration prerequisites", but I see no such tooltip, no matter where I hover. I tried opening a support request with Microsoft 365 Support, only to be told that I have to contact Azure support. We don't currently have an Azure support plan, so I guess we don't qualify for support. Anyone got any suggestions for things I can try?SolvedRyanSteele-CoVAug 05, 2026Steel Contributor91Views0likes2CommentsPermission required to see the Exposed Entities in Secure Score's MDI items
The documentation here suggests to see the full details of Microsoft Defender for Identity items in Secure Score, I would need the following permission: Security operations/Security data /Security data basics (Read) However, when even with those permissions, I don't have access to the Exposed Entities tab. What permission would I need to be able to have read access to those?AndrewPiskaiJun 24, 2026Microsoft1.2KViews0likes1CommentKQL Query Pass Hash Sync Status
Hi Community, Are there any KQL queries to find the status of Pass Hash Sync status on all users, I was able to find some queries through co-pilot but none of them are valid since the Table name doesn't exists. Thanks VishwaWishwahvijayaJun 02, 2026Copper Contributor200Views0likes2CommentsVPN Integration not persistent
Hello, We tried to configure https://learn.microsoft.com/en-us/defender-for-identity/vpn-integration from supported Cisco VPN GW. We established the RADIUS Accounting logs to be sent to DC with MDI sensors installed. Yet when we enabled this in Defender Portal (Settings > Identities > VPN) by checking the box and inserting the shared secret, the configuration is not persistent. We hit save, and we are presented with the success green message, but once we refresh the page or go elsewhere in the portal, the checkbox is not checked. Has anyone encountered the same issue? Thanks, SimonschimpanzeApr 16, 2026Copper Contributor120Views1like1CommentClarification over "dormant" account status
I was looking today at our list of "Remove dormant accounts from sensitive groups" within Microsoft Defender for Identity, and one service account has caused a bit of discussion. The account would only be used on-premise and would never be carrying out authentications out of our estate. In this case would Defender for Identity still see the account as being "dormant", or is the reason because it's not carried out any of those off-estate authentications? Apologies if this is a simple question, but it would be very helpful to know the answer.jasonbourne5379Apr 15, 2026Copper Contributor253Views0likes1CommentIdentityLogonEvents - IsNtlmV1
Hi, I cannot find documentation on how the IdentityLogonEvents table's AdditionalFields.IsNtlmV1 populated. In a demo environment, I intentionally "enforced" NTLMv1 and made an NTLMv1 connection to a domain controller. On the DC's Security log, event ID 4624 shows correct info: Detailed Authentication Information: Logon Process: NtLmSsp Authentication Package: NTLM Transited Services: - Package Name (NTLM only): NTLM V1 Key Length: 128 On MDI side however it looks like this: (using the following KQL to display relevant info here: IdentityLogonEvents | where ReportId == @"f70dbd37-af8e-4e4e-a77d-b4250f9e0d0b" | extend todynamic(AdditionalFields) | project TimeGenerated, ActionType, Application, LogonType, Protocol,IsNtlmV1 = AdditionalFields.IsNtlmV1 ) TimeGenerated ActionType Application LogonType Protocol IsNtlmV1 Nov 28, 2025 10:43:05 PM LogonSuccess Active Directory Credentials validation Ntlm false Can someone please explain, under which circumstances will the IsNtlmV1 property become "true"? Thank you in advancekuglidaniFeb 27, 2026Tin Contributor648Views0likes8CommentsDefender for Identity health issues - Not Closing
We have old issues and they're not being "Closed" as reported. Are we missing something or is this "Microsoft Defender for Identity" Health Issues process broken? Thanks! Closed: A health issue is automatically marked as Closed when Microsoft Defender for Identity detects that the underlying issue is resolved. If you have the Azure ATP (workspace name) Administrator role, you can also manually close a health issue.MPH2Feb 06, 2026Copper Contributor567Views0likes2CommentsChange password for krbtgt account
What is the criteria that MDI uses to determine whether the https://learn.microsoft.com/en-us/defender-for-identity/security-posture-assessments/accounts#change-password-for-krbtgt-account recommendation has been completed? I'm working with an org where the passwordLastSet attribute on the krbtgt account says "never", yet this recommendation is showing "Completed".SolvedrgsteeleJan 23, 2026Tin Contributor401Views1like6Comments
Tags
- Sensor53 Topics
- microsoft 365 defender45 Topics
- identity protection36 Topics
- alerts17 Topics
- security posture17 Topics
- logging15 Topics
- azure active directory11 Topics
- updates10 Topics
- requirements8 Topics
- Investigations8 Topics