Demoted domain controller in coverage report

%3CLINGO-SUB%20id%3D%22lingo-sub-718099%22%20slang%3D%22en-US%22%3EDemoted%20domain%20controller%20in%20coverage%20report%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-718099%22%20slang%3D%22en-US%22%3E%3CP%3EQuite%20a%20while%20ago%2C%20we%20lost%20a%20domain%20controller%20(server%20died)%2C%20and%20we%20cleaned%20up%20the%20object%2Freference%20in%20Active%20Directory%20(deleted%20computer%20object%2C%20removed%20from%20sites%20and%20services).%26nbsp%3B%20Azure%20ATP%2C%20though%2C%20still%20detects%20it%20when%20generating%20the%20%22domain%20controller%20coverage%22%20report%20(in%20the%20domain%20controllers%20OU).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E1.%20How%20does%20Azure%20ATP%20discover%20the%20domain%20controllers%3F%20And%20how%20often%20does%20it%20update%3F%3C%2FP%3E%3CP%3E2.%20Any%20suggestions%20on%20where%20to%20look%20to%20find%20the%20remaining%20references%20to%20this%20old%20domain%20controller%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-718498%22%20slang%3D%22en-US%22%3ERe%3A%20Demoted%20domain%20controller%20in%20coverage%20report%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-718498%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F365773%22%20target%3D%22_blank%22%3E%40ajbravo%3C%2FA%3E%26nbsp%3B%20if%20you%20did%20not%20uninstall%20the%20sensor%20prior%20to%20server%20loss%2C%20go%20into%20the%20config%20tab%20in%20the%20console%20UI%2C%20to%20the%20sensors%20list%2C%20and%20delete%20it%20from%20the%20list.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-719803%22%20slang%3D%22en-US%22%3ERe%3A%20Demoted%20domain%20controller%20in%20coverage%20report%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-719803%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F106935%22%20target%3D%22_blank%22%3E%40Eli%20Ofek%3C%2FA%3E%26nbsp%3BI%20wasn't%20clear--the%20domain%20controller%20is%20not%20showing%20as%20an%20installed%20sensor%2C%20but%20as%20one%20which%20doesn't%20have%20the%20agent%20(in%20the%20%22domain%20controller%20coverage%20report%22).%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%2C%20at%20the%20top%20of%20the%20sensors%20list%2C%20it%20says%20%22You%20have%20installed%20Azure%20ATP%20Sensor%20on%209%20out%20of%2010%20domain%20controllers%2C%22%20when%20it%20should%20say%20%229%20out%20of%209.%22%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-727384%22%20slang%3D%22en-US%22%3ERe%3A%20Demoted%20domain%20controller%20in%20coverage%20report%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-727384%22%20slang%3D%22en-US%22%3EHi%2C%20we're%20aware%20of%20the%20issue%20(lingering%20objects%20in%20the%20DC%20Coverage%20report)%20and%20are%20working%20to%20fix%20it.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-756967%22%20slang%3D%22en-US%22%3ERe%3A%20Demoted%20domain%20controller%20in%20coverage%20report%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-756967%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F215466%22%20target%3D%22_blank%22%3E%40Or%20Tsemah%3C%2FA%3E%26nbsp%3BAny%20update%20on%20this.%20I%20just%20opened%20a%20case%20for%20this%20issue%3F%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-756979%22%20slang%3D%22en-US%22%3ERe%3A%20Demoted%20domain%20controller%20in%20coverage%20report%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-756979%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F232887%22%20target%3D%22_blank%22%3E%40Jake%20Platt%3C%2FA%3E%2C%26nbsp%3BI%20hope%20to%20share%20some%20good%20news%20soon%2C%20rest%20assure%20that%20we%20are%20on%20it%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-780402%22%20slang%3D%22en-US%22%3ERe%3A%20Demoted%20domain%20controller%20in%20coverage%20report%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-780402%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F215466%22%20target%3D%22_blank%22%3E%40Or%20Tsemah%3C%2FA%3E%26nbsp%3Bhi%2C%26nbsp%3B%20I%20am%20also%20facing%20the%20same%20issue.%20We%20have%20recently%20decommissioned%202%20DC's%20and%20we%20did%20not%20installed%20ATP%20sensor%20on%20these%20DC's%20but%20it%20is%20still%20showing%20in%20the%20report%20%22%20You%20have%20installed%20Azure%20sensor%20on%209%20out%20of%2011%20DC%22.%3C%2FP%3E%3CP%3EHow%20can%20i%20delete%20these%20from%20the%20report..%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-780963%22%20slang%3D%22en-US%22%3ERe%3A%20Demoted%20domain%20controller%20in%20coverage%20report%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-780963%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F351576%22%20target%3D%22_blank%22%3E%40roadrasher06%3C%2FA%3E%26nbsp%3BWe%20are%20actively%20working%20on%20excluding%20these%20from%20the%20list%20of%20%22Must-have%22%20domain%20controllers.%3C%2FP%3E%0A%3CP%3EQuestion%3A%20If%20excluded%2C%20would%20you%20still%20like%20to%20view%20these%20decommissioned%20DCs%20in%20the%20excel%20report%20as%20%22unreachable%22%20DCs%20(which%20will%20eventually%20be%20deleted)%20or%20they%20are%20of%20no%20interest%20to%20you%20at%20all%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-781477%22%20slang%3D%22en-US%22%3ERe%3A%20Demoted%20domain%20controller%20in%20coverage%20report%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-781477%22%20slang%3D%22en-US%22%3EA%20separate%20sheet%20in%20Excel%20might%20be%20OK%2C%20but%20generally%20I%20wouldn't%20have%20an%20interest%20in%20a%20DC%20once%20it%20has%20been%20demoted.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-910381%22%20slang%3D%22en-US%22%3ERe%3A%20Demoted%20domain%20controller%20in%20coverage%20report%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-910381%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F365773%22%20target%3D%22_blank%22%3E%40ajbravo%3C%2FA%3E%26nbsp%3Bwe%20have%20two%20DCs%20that%20are%20still%20showing%20as%20domain%20contollers%20with%20no%20sensors.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1051252%22%20slang%3D%22en-US%22%3ERe%3A%20Demoted%20domain%20controller%20in%20coverage%20report%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1051252%22%20slang%3D%22en-US%22%3E%3CP%3EI%20am%20guessing%20this%20is%20still%20not%20fixed%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%203%20long%20demoted%20domain%20controllers%20that%20still%20appear%20in%20the%20domain%20controller%20coverage%20list.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EProper%20demotion%20and%20metadata%20cleanup%20has%20been%20performed%20on%20all%20of%20them.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1051473%22%20slang%3D%22en-US%22%3ERe%3A%20Demoted%20domain%20controller%20in%20coverage%20report%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1051473%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F383902%22%20target%3D%22_blank%22%3E%40Dennis_Peabody%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EYes%2C%20we%20are%20on%20it%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1384870%22%20slang%3D%22en-US%22%3ERe%3A%20Demoted%20domain%20controller%20in%20coverage%20report%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1384870%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F215466%22%20target%3D%22_blank%22%3E%40Or%20Tsemah%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHas%20this%20been%20implemented%3F%20We%20are%20trying%20to%20increase%20our%20secure%20score%20and%20having%20all%20DCs%20with%20sensors%20is%20a%20requirement.%20We%20had%20a%20couple%20that%20were%20not%20decom%20properly%20and%20are%20showing%20in%20ATP%20still.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1385466%22%20slang%3D%22en-US%22%3ERe%3A%20Demoted%20domain%20controller%20in%20coverage%20report%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1385466%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F380284%22%20target%3D%22_blank%22%3E%40jarrydanderson%3C%2FA%3E%26nbsp%3BYes%2C%20we%20are%20now%20using%20DCs%20reported%20by%20AD%20itself%2C%20if%20you%20believe%20it%20is%20showing%20false%20results%2C%20you%20can%20ping%20us%20at%26nbsp%3BAatpFeedback%40microsoft.com%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

Quite a while ago, we lost a domain controller (server died), and we cleaned up the object/reference in Active Directory (deleted computer object, removed from sites and services).  Azure ATP, though, still detects it when generating the "domain controller coverage" report (in the domain controllers OU).

 

1. How does Azure ATP discover the domain controllers? And how often does it update?

2. Any suggestions on where to look to find the remaining references to this old domain controller?

 

Thank you!

12 Replies
Highlighted

@ajbravo  if you did not uninstall the sensor prior to server loss, go into the config tab in the console UI, to the sensors list, and delete it from the list.

Highlighted

@Eli Ofek I wasn't clear--the domain controller is not showing as an installed sensor, but as one which doesn't have the agent (in the "domain controller coverage report"). 

 

So, at the top of the sensors list, it says "You have installed Azure ATP Sensor on 9 out of 10 domain controllers," when it should say "9 out of 9."

Highlighted
Hi, we're aware of the issue (lingering objects in the DC Coverage report) and are working to fix it.
Highlighted

@Or Tsemah Any update on this? I just opened a case for this issue.

Highlighted

@Jake Platt, I hope to share some good news soon, rest assure that we are on it

Highlighted

@Or Tsemah hi,  I am also facing the same issue. We have recently decommissioned 2 DC's and we did not installed ATP sensor on these DC's but it is still showing in the report " You have installed Azure sensor on 9 out of 11 DC".

How can i delete these from the report..

Highlighted

@roadrasher06 We are actively working on excluding these from the list of "Must-have" domain controllers.

Question: If excluded, would you still like to view these decommissioned DCs in the excel report as "unreachable" DCs (which will eventually be deleted) or they are of no interest to you at all?

Highlighted
A separate sheet in Excel might be OK, but generally I wouldn't have an interest in a DC once it has been demoted.
Highlighted

I am guessing this is still not fixed?

 

I have 3 long demoted domain controllers that still appear in the domain controller coverage list.

 

Proper demotion and metadata cleanup has been performed on all of them.

Highlighted

@Dennis_Peabody 

Yes, we are on it

Highlighted

@Or Tsemah 

 

Has this been implemented? We are trying to increase our secure score and having all DCs with sensors is a requirement. We had a couple that were not decom properly and are showing in ATP still. 

Highlighted

@jarrydanderson Yes, we are now using DCs reported by AD itself, if you believe it is showing false results, you can ping us at AatpFeedback@microsoft.com