ATA showing a user as an member of Domain Admin who has been deleted for 40 days?

%3CLINGO-SUB%20id%3D%22lingo-sub-735851%22%20slang%3D%22en-US%22%3EATA%20showing%20a%20user%20as%20an%20member%20of%20Domain%20Admin%20who%20has%20been%20deleted%20for%2040%20days%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-735851%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20all%2C%3C%2FP%3E%3CP%3EATA%20shows%20a%20member%20of%20%22Domain%20Admins%22%20who%20has%20been%20deleted%20for%2040%20days%3F%20I%20have%20verified%26nbsp%3Bthat%20the%20user%20doesn%E2%80%99t%20exist%20in%20AD.%20When%20I%20look%20at%20the%20user%20in%20ATA%2C%20the%20last%20event%20is%3A%20%E2%80%9CAccount's%20password%20was%20set%20to%20never%20expire%E2%80%9D.%3C%2FP%3E%3CUL%3E%3CLI%3EIs%20it%20me%20that%20don%E2%80%99t%20understand%20how%20ATA%20is%20working%3F%20So%2C%20by%20design.%20%3Asmiling_face_with_smiling_eyes%3A%3C%2Fimg%3E%3C%2FLI%3E%3CLI%3ECould%20it%20be%20a%20communication%20error%20(drop%20out)%20between%20the%20ATA%20and%20one%20of%20the%20Domain%20Controllers%3F%20I%20have%20no%20reason%20to%20believe%20that%2C%20but%20anyway.%3CUL%3E%3CLI%3EIf%20that%20is%20the%20case%2C%20is%20there%20a%20way%20that%20I%20can%20get%20the%20correct%20information%20in%20to%20ATA%3F%3C%2FLI%3E%3CLI%3EHow%20do%20I%20verify%20the%20communication%20error%2C%20and%20how%20do%20I%20correct%20it%3F%3C%2FLI%3E%3C%2FUL%3E%3C%2FLI%3E%3C%2FUL%3E%3CP%3EThe%20setup%20is%201%20ATA%20on%20the%20same%20subnet%20as%204%20domain%20controllers.%20And%20everything%20else%20seems%20to%20be%20working%20as%20expected.%3CBR%20%2F%3EBest%20regards%3CBR%20%2F%3EThomas%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-735851%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAdvanced%20Threat%20Analytics%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-735874%22%20slang%3D%22en-US%22%3ERe%3A%20ATA%20showing%20a%20user%20as%20an%20member%20of%20Domain%20Admin%20who%20has%20been%20deleted%20for%2040%20days%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-735874%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F3985%22%20target%3D%22_blank%22%3E%40Thomas%20Friis%20Poulsen%3C%2FA%3E%26nbsp%3B%2C%20see%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fadvanced-threat-analytics%2Fata-prerequisites%23before-you-start%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fadvanced-threat-analytics%2Fata-prerequisites%23before-you-start%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%22%3CSPAN%3ERecommended%3A%20User%20should%20have%20read-only%20permissions%20on%20the%20Deleted%20Objects%20container.%20This%20allows%20ATA%20to%20detect%20bulk%20deletion%20of%20objects%20in%20the%20domain.%20For%20information%20about%20configuring%20read-only%20permissions%20on%20the%20Deleted%20Objects%20container%2C%20see%20the%26nbsp%3B%3C%2FSPAN%3E%3CSTRONG%3EChanging%20permissions%20on%20a%20deleted%20object%20container%3C%2FSTRONG%3E%3CSPAN%3E%26nbsp%3Bsection%20in%20the%26nbsp%3B%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Ftechnet.microsoft.com%2Flibrary%2Fcc816824%2528v%3Dws.10%2529.aspx%22%20data-linktype%3D%22external%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3EView%20or%20Set%20Permissions%20on%20a%20Directory%20Object%3C%2FA%3E%3CSPAN%3Earticle.%22%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EBesides%3CSPAN%3E%26nbsp%3Bdetection%2C%20this%20can%20help%20us%20know%20an%20account%20was%20deleted%2C%20try%20this%20and%20see%20if%20it%20resolves%20the%20issue.%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-736085%22%20slang%3D%22en-US%22%3ERe%3A%20ATA%20showing%20a%20user%20as%20an%20member%20of%20Domain%20Admin%20who%20has%20been%20deleted%20for%2040%20days%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-736085%22%20slang%3D%22en-US%22%3E%3CP%3EThanks.%20%3A)%3C%2Fimg%3E%3CBR%20%2F%3EWe%20will%20look%20into%20it.%20I'll%20keep%20you%20updated.%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F106935%22%20target%3D%22_blank%22%3E%40Eli%20Ofek%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-737669%22%20slang%3D%22en-US%22%3ERe%3A%20ATA%20showing%20a%20user%20as%20an%20member%20of%20Domain%20Admin%20who%20has%20been%20deleted%20for%2040%20days%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-737669%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F106935%22%20target%3D%22_blank%22%3E%40Eli%20Ofek%3C%2FA%3E%26nbsp%3B%3CBR%20%2F%3EThanks%20again.%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3CP%3EOK%2C%20we%20done%20that%20wrong%20and%20have%20now%20change%20it%20so%20ATA%20has%20readonly%20access%20to%20Deleted%20Objects.%3CBR%20%2F%3ENext%20question%20is%2C%20how%20do%20we%20get%20ATA%20back%20in%20sync%3F%20Should%20we%20just%20sit%20back%20and%20wait%3F%20%3B)%3C%2Fimg%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-737853%22%20slang%3D%22en-US%22%3ERe%3A%20ATA%20showing%20a%20user%20as%20an%20member%20of%20Domain%20Admin%20who%20has%20been%20deleted%20for%2040%20days%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-737853%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F3985%22%20target%3D%22_blank%22%3E%40Thomas%20Friis%20Poulsen%3C%2FA%3E%26nbsp%3B%2C%20I%20think%20this%20will%20fix%20the%20issue%20only%20going%20forward%2C%20as%20we%20already%20%22missed%22%20the%20update.%3C%2FP%3E%0A%3CP%3EWhich%20ATA%20version%20are%20you%20running%3F%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-738704%22%20slang%3D%22en-US%22%3ERe%3A%20ATA%20showing%20a%20user%20as%20an%20member%20of%20Domain%20Admin%20who%20has%20been%20deleted%20for%2040%20days%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-738704%22%20slang%3D%22en-US%22%3E%3CP%3E1.9.7412.9649%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F106935%22%20target%3D%22_blank%22%3E%40Eli%20Ofek%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-741915%22%20slang%3D%22en-US%22%3ERe%3A%20ATA%20showing%20a%20user%20as%20an%20member%20of%20Domain%20Admin%20who%20has%20been%20deleted%20for%2040%20days%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-741915%22%20slang%3D%22en-US%22%3E%3CP%3EJust%20upgraded%2C%20waiting...%20...%20...%20...%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F106935%22%20target%3D%22_blank%22%3E%40Eli%20Ofek%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-741332%22%20slang%3D%22en-US%22%3ERe%3A%20ATA%20showing%20a%20user%20as%20an%20member%20of%20Domain%20Admin%20who%20has%20been%20deleted%20for%2040%20days%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-741332%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F3985%22%20target%3D%22_blank%22%3E%40Thomas%20Friis%20Poulsen%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ETry%20to%20upgrade%20to%201.9%20Update%202%20(1.9.7478.57683).%3C%2FP%3E%0A%3CP%3EIf%20the%20issue%20is%20still%20not%20resolved%2C%20on%20top%20of%20this%20version%2C%20you%20can%20induce%20a%20forced%20resync%20of%20AD%20to%20ATA.%3C%2FP%3E%0A%3CP%3EGiving%20that%20now%20we%20have%20read%20access%20on%20deleted%20items%2C%20the%20resync%20should%20resolve%20the%20issue.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EYou%20can%20do%20this%20by%20opening%20an%26nbsp%3B%20elevated%20command%20prompt%20on%20the%20Center%20machine%2C%20navigating%20to%20the%20mongo%20bin%20folder%2C%20and%20from%20there%20issuing%20the%20commands%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%3Enet%20stop%20ATACenter%0Amongo.exe%20ATA%20--eval%20%22db.SystemProfile.remove(%7B_t%3A'DirectoryServicesSystemProfile'%7D)%22%0Anet%20start%20ATACenter%3C%2FPRE%3E%0A%3CP%3EThis%20will%20force%20a%20resync%2C%20which%20can%20take%20from%20a%20few%20hours%20to%20a%20few%20days%2C%20depending%20on%20your%20AD%20size...%20for%20most%20customers%20it%20will%20complete%20within%20a%20few%20hours.%3C%2FP%3E%0A%3CP%3EThere%20is%20no%20UI%20indication%20on%20completion%20because%20it%20is%20actually%20an%20ongoing%20process%2C%20we%20just%20tell%20it%20here%20to%20start%20from%20scratch.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

Hi all,

ATA shows a member of "Domain Admins" who has been deleted for 40 days? I have verified that the user doesn’t exist in AD. When I look at the user in ATA, the last event is: “Account's password was set to never expire”.

  • Is it me that don’t understand how ATA is working? So, by design. :smiling_face_with_smiling_eyes:
  • Could it be a communication error (drop out) between the ATA and one of the Domain Controllers? I have no reason to believe that, but anyway.
    • If that is the case, is there a way that I can get the correct information in to ATA?
    • How do I verify the communication error, and how do I correct it?

The setup is 1 ATA on the same subnet as 4 domain controllers. And everything else seems to be working as expected.
Best regards
Thomas

7 Replies
Highlighted

@Thomas Friis Poulsen , see

https://docs.microsoft.com/en-us/advanced-threat-analytics/ata-prerequisites#before-you-start

"Recommended: User should have read-only permissions on the Deleted Objects container. This allows ATA to detect bulk deletion of objects in the domain. For information about configuring read-only permissions on the Deleted Objects container, see the Changing permissions on a deleted object container section in the View or Set Permissions on a Directory Objectarticle."

 

Besides detection, this can help us know an account was deleted, try this and see if it resolves the issue. 

Highlighted

Thanks. :)
We will look into it. I'll keep you updated.@Eli Ofek 

Highlighted

@Eli Ofek 
Thanks again. :)

OK, we done that wrong and have now change it so ATA has readonly access to Deleted Objects.
Next question is, how do we get ATA back in sync? Should we just sit back and wait? ;)

 

Highlighted

@Thomas Friis Poulsen , I think this will fix the issue only going forward, as we already "missed" the update.

Which ATA version are you running? 

Highlighted
Highlighted

@Thomas Friis Poulsen 

Try to upgrade to 1.9 Update 2 (1.9.7478.57683).

If the issue is still not resolved, on top of this version, you can induce a forced resync of AD to ATA.

Giving that now we have read access on deleted items, the resync should resolve the issue.

 

You can do this by opening an  elevated command prompt on the Center machine, navigating to the mongo bin folder, and from there issuing the commands:

 

net stop ATACenter
mongo.exe ATA --eval "db.SystemProfile.remove({_t:'DirectoryServicesSystemProfile'})"
net start ATACenter

This will force a resync, which can take from a few hours to a few days, depending on your AD size... for most customers it will complete within a few hours.

There is no UI indication on completion because it is actually an ongoing process, we just tell it here to start from scratch.

Highlighted

Just upgraded, waiting... ... ... ... :)

@Eli Ofek