SOLVED

Using Azure ATP with AWS Directory Service

%3CLINGO-SUB%20id%3D%22lingo-sub-759461%22%20slang%3D%22en-US%22%3EUsing%20Azure%20ATP%20with%20AWS%20Directory%20Service%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-759461%22%20slang%3D%22en-US%22%3E%3CP%3EIs%20there%20any%20guidance%20on%20using%20Azure%20ATP%20when%20using%20AWS%20Directory%20Service%20(%3CA%20href%3D%22https%3A%2F%2Faws.amazon.com%2Fdirectoryservice%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Faws.amazon.com%2Fdirectoryservice%2F%3C%2FA%3E)%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFrom%20my%20understanding%2C%20Domain%20Controllers%20are%20managed%20for%20you%2C%20so%20no%20host%20access.%20Can%20a%20stand%20alone%20sensor%20be%20used%20with%20some%20other%20AWS%20or%20VPC%20configurations%20(for%20port%20mirroring)%3F%20Has%20this%20been%20looked%20at%20or%20attempted%20yet%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EJust%20curious%20as%20we%20may%20be%20investigating%20the%20ability%20to%20use%20Azure%20ATP%20with%20this%20type%20of%20environment.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-760262%22%20slang%3D%22en-US%22%3ERe%3A%20Using%20Azure%20ATP%20with%20AWS%20Directory%20Service%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-760262%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F344092%22%20target%3D%22_blank%22%3E%40archedmeerkat%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ECurrently%20no%2C%20but%20if%20this%20a%20service%20that%20you%20are%20currently%20using%20(or%20anyone%20else)%20and%20you%20believe%20it%20should%20integrate%20with%20Azure%20ATP%2C%20i%20would%20be%20happy%20to%20discuss%20it.%3C%2FP%3E%0A%3CP%3Eyou%20can%20contact%20me%20at%20ort%40microsoft.com%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-768046%22%20slang%3D%22en-US%22%3ERe%3A%20Using%20Azure%20ATP%20with%20AWS%20Directory%20Service%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-768046%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F215466%22%20target%3D%22_blank%22%3E%40Or%20Tsemah%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20for%20the%20information%2C%20Or.%20Just%20more%20looking%20for%20information%20as%20a%20certain%20portion%20of%20the%20environment%20I%20am%20in%20is%20looking%20to%20use%20this%20functionality%20and%20wanted%20to%20be%20out%20ahead%20of%20it%2C%20if%20possible.%3CBR%20%2F%3E%3CBR%20%2F%3EI%20haven't%20looked%20too%20much%20into%20the%20AWS%20Directory%20Service%20functionality%20yet%2C%20but%20I%20think%20there%20may%20be%20the%20ability%20to%20use%20a%20recently%20released%20port%20mirroring%20feature%20from%20AWS%20(%3CA%20href%3D%22https%3A%2F%2Faws.amazon.com%2Fblogs%2Faws%2Fnew-vpc-traffic-mirroring%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Faws.amazon.com%2Fblogs%2Faws%2Fnew-vpc-traffic-mirroring%2F%3C%2FA%3E)%2C%20which%20may%20allow%20for%20use%20of%20a%20standalone%20sensor%20to%20collect%20the%20traffic.%20Not%20sure%20about%20event%20forwarding%20though.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-769058%22%20slang%3D%22en-US%22%3ERe%3A%20Using%20Azure%20ATP%20with%20AWS%20Directory%20Service%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-769058%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F344092%22%20target%3D%22_blank%22%3E%40archedmeerkat%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EGreat%2C%20would%20be%20glad%20to%20hear%20how%20we%20can%20extend%20our%20solution%20coverage%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

Is there any guidance on using Azure ATP when using AWS Directory Service (https://aws.amazon.com/directoryservice/)?

 

From my understanding, Domain Controllers are managed for you, so no host access. Can a stand alone sensor be used with some other AWS or VPC configurations (for port mirroring)? Has this been looked at or attempted yet?

 

Just curious as we may be investigating the ability to use Azure ATP with this type of environment.

3 Replies
Highlighted
Best Response confirmed by archedmeerkat (Occasional Contributor)
Solution

@archedmeerkat 

Currently no, but if this a service that you are currently using (or anyone else) and you believe it should integrate with Azure ATP, i would be happy to discuss it.

you can contact me at ort@microsoft.com

 

Highlighted

@Or Tsemah 

 

Thanks for the information, Or. Just more looking for information as a certain portion of the environment I am in is looking to use this functionality and wanted to be out ahead of it, if possible.

I haven't looked too much into the AWS Directory Service functionality yet, but I think there may be the ability to use a recently released port mirroring feature from AWS (https://aws.amazon.com/blogs/aws/new-vpc-traffic-mirroring/), which may allow for use of a standalone sensor to collect the traffic. Not sure about event forwarding though.

Highlighted

@archedmeerkat 

Great, would be glad to hear how we can extend our solution coverage