Installing sensors across several data centers: Standalone vs. ATP Sensor

%3CLINGO-SUB%20id%3D%22lingo-sub-781726%22%20slang%3D%22en-US%22%3EInstalling%20sensors%20across%20several%20data%20centers%3A%20Standalone%20vs.%20ATP%20Sensor%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-781726%22%20slang%3D%22en-US%22%3E%3CP%3EIn%20order%20to%20get%20full%20coverage%20of%20a%20large%20enterprise%2C%20besides%20installing%20on%20all%20DC's%2C%20should%20we%20install%20standalone%20sensors%20also%3F%20My%20thinking%20is%20that%20it%20is%20a%20good%20idea%20to%20have%20both%20types%20of%20sensors%20installed.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EJust%20got%20out%20of%20a%20design%20meeting%20where%20it%20was%20discussed%20that%20its%20either%20one%20or%20the%20other%2C%20not%20both.%20Any%20clarity%20on%20the%20subject%20would%20be%20helpful%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-781742%22%20slang%3D%22en-US%22%3ERe%3A%20Installing%20sensors%20across%20several%20data%20centers%3A%20Standalone%20vs.%20ATP%20Sensor%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-781742%22%20slang%3D%22en-US%22%3E%3CP%3ESensor%20duplication%20(monitoring%20a%20DC%20with%20more%20than%20one%20sensor)%20is%20not%20supported.%3C%2FP%3E%0A%3CP%3EFor%20best%20experience%2C%20use%20the%20integrated%20sensor%2C%20as%20it%20provide%20the%20complete%20set%20of%20detections%20AATP%20offers.%3C%2FP%3E%0A%3CP%3EStandalone%20sensors%20provide%20only%20partial%20detection.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-781776%22%20slang%3D%22en-US%22%3ERe%3A%20Installing%20sensors%20across%20several%20data%20centers%3A%20Standalone%20vs.%20ATP%20Sensor%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-781776%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F106935%22%20target%3D%22_blank%22%3E%40Eli%20Ofek%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20if%20I%20understand%20you%20correctly%2C%20ATP%20Sensors%20are%20installed%20on%20all%20DC's%20and%20send%20alerts%20to%20ATP%20Cloud%20service.%20All%20other%20non-domain%20controllers%20are%20set%20up%20to%20send%20traffic%20to%20the%20standalone%20sensor%20and%20then%20the%20standalone%20sensor%20sends%20traffic%20to%20ATP.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20this%20correct%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-782445%22%20slang%3D%22en-US%22%3ERe%3A%20Installing%20sensors%20across%20several%20data%20centers%3A%20Standalone%20vs.%20ATP%20Sensor%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-782445%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F363955%22%20target%3D%22_blank%22%3E%40jbchris%3C%2FA%3E%26nbsp%3B%2C%20pretty%20much%2C%20the%20sensor%20collects%20data%20we%20think%20is%20relative%20for%20detection%20and%20send%20it%20to%20Azure.%3C%2FP%3E%0A%3CP%3Ein%20standalone%2C%20you%20need%20to%20mirror%20traffic%20and%20forward%20windows%20events%2C%20but%20there%20are%20stuff%20you%20can't%20forward%20like%20ETW%20events.%20so%20the%20integrated%20sensor%20is%20far%20better%20is%20possible.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1458305%22%20slang%3D%22en-US%22%3ERe%3A%20Installing%20sensors%20across%20several%20data%20centers%3A%20Standalone%20vs.%20ATP%20Sensor%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1458305%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F106935%22%20target%3D%22_blank%22%3E%40Eli%20Ofek%3C%2FA%3E%26nbsp%3BIs%20there%20an%20overview%20of%20what%20kind%20of%20use%20cases%20cannot%20be%20covered%20when%20using%20the%20Standalone%20Sensor%3F%20As%20of%20security%20related%20issues%2C%20we%20tend%20to%20proceed%20with%20the%20standalone%20sensors%2C%20thus%20the%20question.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1459786%22%20slang%3D%22en-US%22%3ERe%3A%20Installing%20sensors%20across%20several%20data%20centers%3A%20Standalone%20vs.%20ATP%20Sensor%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1459786%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F681519%22%20target%3D%22_blank%22%3E%40CurlX%3C%2FA%3E%26nbsp%3B%20if%20you%20look%20at%20this%20alert%20list%3A%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure-advanced-threat-protection%2Fsuspicious-activity-guide%3Ftabs%3Dexternal%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure-advanced-threat-protection%2Fsuspicious-activity-guide%3Ftabs%3Dexternal%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Egoing%20into%20each%20one%2C%20you%20might%20see%20a%20note%20which%20contains%20%22%3CSPAN%3Esupported%20by%20ATP%20sensors%20only.%22%20that%20means%20using%20a%20standalone%20won't%20have%20this%20detection.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EThe%20integrated%20sensor%20is%20by%20far%26nbsp%3B%20more%20advance%2C%20as%20of%20today%2C%20less%20than%204%25%20of%20covered%20DCs%20are%20protected%20with%20standalone%20sensors%2C%20and%20this%20number%20keeps%20dropping.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EWhat%20is%20the%20mentioned%20security%20issue%20which%20tends%20you%20to%20using%20the%20standalone%20version%20which%20provides%20less%20detections%26nbsp%3Band%20also%20much%20more%20expensive%20(dedicated%20hardware%2C%20port%20mirroring%2C%20event%20forwarding)%20%3F%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1462858%22%20slang%3D%22en-US%22%3ERe%3A%20Installing%20sensors%20across%20several%20data%20centers%3A%20Standalone%20vs.%20ATP%20Sensor%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1462858%22%20slang%3D%22en-US%22%3E%3CDIV%20class%3D%22user-login%22%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F106935%22%20target%3D%22_blank%22%3EEli%20Ofek%3C%2FA%3E%3C%2FDIV%3E%3CDIV%20class%3D%22user-login%22%3EThank%20you%20for%20your%20feedback.%20Our%20Operations%20Team%20is%20strongly%20against%20the%20idea%20installing%20an%20agent%20on%20the%20DC%20because%20of%20these%20reasons%3A%3C%2FDIV%3E%3CDIV%20class%3D%22user-login%22%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%20class%3D%22user-login%22%3E-%20The%20DC%20should%20not%20have%20direct%20internet%20connection%20(not%20even%20with%20a%20proxy%20in%20between)%20as%20of%20hardening%20reasons.%26nbsp%3B%3C%2FDIV%3E%3CDIV%20class%3D%22user-login%22%3E-%20The%20agent%20load%20on%20the%20DC%20is%20also%20an%20issue%3C%2FDIV%3E%3CDIV%20class%3D%22user-login%22%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%20class%3D%22user-login%22%3EI%20am%20sure%2C%20we%20are%20not%20the%20only%20ones%20with%20these%20concerns%2C%20do%20you%20have%20any%20solutions%20to%20that%3F%26nbsp%3B%3C%2FDIV%3E%3CDIV%20class%3D%22user-login%22%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%20class%3D%22user-login%22%3EIn%20order%20to%20proceed%2C%20I%20am%20checking%20out%20the%20possibilities%20we%20have%20with%20the%20Standalone%20Sensor%2C%20trying%20to%20understand%20the%20limitations%20and%20difficulties%20we%20could%20face.%20Also%20if%20the%20traffic%20to%20be%20mirrored%20can%20be%20limited%20to%20certain%20ports%2Fprotocols.%20I%20might%20open%20a%20new%20%22Question%22%20in%20this%20respect.%26nbsp%3B%3C%2FDIV%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1466366%22%20slang%3D%22en-US%22%3ERe%3A%20Installing%20sensors%20across%20several%20data%20centers%3A%20Standalone%20vs.%20ATP%20Sensor%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1466366%22%20slang%3D%22en-US%22%3E%3CP%3EAs%20for%20Internet%20hardening%20%2C%20there%20is%20an%20option%20to%20use%20a%20dedicated%20proxy%2C%20set%20only%20the%20sensor%20processes%20to%20use%20this%20proxy%20on%20the%20machine%20(we%20support%20that%20via%20the%20silent%20install)%20and%20limit%20the%20proxy%20to%20only%20connect%20to%20the%20AATP%20service%20tag%20(list%20of%20subnets%20we%20are%20using).%3C%2FP%3E%0A%3CP%3EAs%20for%20the%20load%20on%20the%20DC%2C%20the%20sensor%20has%20a%20resource%20manager%20that%20will%20make%20sure%20that%20the%20DC%20has%20at%20least%2015%25%20of%20free%20RAM%20and%20CPU.%20you%20can%20read%20about%20it%20in%20the%20docs.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Eout%20of%20the%204%25%20of%20sensors%20we%20have%20as%20standalone%2C%20I%20am%20pretty%20sure%20a%20significant%20part%20of%20them%20are%20not%20due%20to%20security%20issues%2C%20but%20due%20to%20hardware%20limit%20sometimes%2C%20for%20example%2C%20if%20the%20current%20DC%20without%20the%20sensor%20is%20so%20load%20that%20it%20has%20no%20room%20for%20the%20sensor%2C%26nbsp%3B%20and%20it's%20a%20physical%20machine%20that%20can't%20be%20scaled%20up%20for%20any%20reason%2C%20then%20you%20are%20kind%20of%20forced%20to%20standalone%20until%20you%20can%20upgrade.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ENote%2C%20that%20while%20you%20try%20to%20enhance%20security%20by%20separating%20the%20sensor%20from%20the%20DC%2C%20you%20are%20also%20hurting%20security%20by%20having%20much%20less%20detection%20on%20the%20DC.%3C%2FP%3E%0A%3CP%3E%3CBR%20%2F%3EWe%20do%20not%20support%20partially%20mirrored%20traffic%20(And%20I%20am%20also%20sure%20it%20will%20be%20pretty%20hard%20to%20implement%20mirroring%20by%20protocol%2Fports).%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EDoes%20the%20Ops%20team%20has%20any%20SPECIFIC%20concerns%2Fuse%20cases%20I%20can%20try%20to%20address%3F%3C%2FP%3E%0A%3CP%3E%22hardening%22%26nbsp%3B%20in%20general%20is%20not%20something%20I%20can%20really%20comment%20on%2C%26nbsp%3B%20as%20I%20proposed%20hardening%20options%20above...%20which%20more%20than%2096%25%20of%20sensors%20wold%20wide%20are%20satisfied%20with%20(most%20of%20them%20are%20satisfied%20with%20much%20less...).%3CBR%20%2F%3EIf%20they%20have%20specific%20concerns%2C%20I%20can%20try%20to%20comment%20on%20them%20or%20help%20in%20engaging%20someone%26nbsp%3B%20else%20who%20can%20if%20I%20don't%20have%20the%20answer.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1467486%22%20slang%3D%22en-US%22%3ERe%3A%20Installing%20sensors%20across%20several%20data%20centers%3A%20Standalone%20vs.%20ATP%20Sensor%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1467486%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F106935%22%20target%3D%22_blank%22%3E%40Eli%20Ofek%3C%2FA%3E%26nbsp%3BThis%20is%20very%20helpful%20information.%20I%20need%20to%20discuss%20this%20further%20in%20our%20organization%20and%20with%20the%20Ops%20Teams.%20I'll%20come%20back%20to%20you%2C%20if%20we%20have%20more%26nbsp%3Buncertainities.%20Thx!%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

In order to get full coverage of a large enterprise, besides installing on all DC's, should we install standalone sensors also? My thinking is that it is a good idea to have both types of sensors installed. 

 

Just got out of a design meeting where it was discussed that its either one or the other, not both. Any clarity on the subject would be helpful

 

Thanks 

8 Replies

Sensor duplication (monitoring a DC with more than one sensor) is not supported.

For best experience, use the integrated sensor, as it provide the complete set of detections AATP offers.

Standalone sensors provide only partial detection.

Highlighted

@Eli Ofek 

 

So if I understand you correctly, ATP Sensors are installed on all DC's and send alerts to ATP Cloud service. All other non-domain controllers are set up to send traffic to the standalone sensor and then the standalone sensor sends traffic to ATP. 

 

Is this correct?

Highlighted

@jbchris , pretty much, the sensor collects data we think is relative for detection and send it to Azure.

in standalone, you need to mirror traffic and forward windows events, but there are stuff you can't forward like ETW events. so the integrated sensor is far better is possible.

Highlighted

@Eli Ofek Is there an overview of what kind of use cases cannot be covered when using the Standalone Sensor? As of security related issues, we tend to proceed with the standalone sensors, thus the question. 

Highlighted

@CurlX  if you look at this alert list:

https://docs.microsoft.com/en-us/azure-advanced-threat-protection/suspicious-activity-guide?tabs=ext...

 

going into each one, you might see a note which contains "supported by ATP sensors only." that means using a standalone won't have this detection.

The integrated sensor is by far  more advance, as of today, less than 4% of covered DCs are protected with standalone sensors, and this number keeps dropping.

 

What is the mentioned security issue which tends you to using the standalone version which provides less detections and also much more expensive (dedicated hardware, port mirroring, event forwarding) ?

Highlighted

 

Highlighted

As for Internet hardening , there is an option to use a dedicated proxy, set only the sensor processes to use this proxy on the machine (we support that via the silent install) and limit the proxy to only connect to the AATP service tag (list of subnets we are using).

As for the load on the DC, the sensor has a resource manager that will make sure that the DC has at least 15% of free RAM and CPU. you can read about it in the docs.

 

out of the 4% of sensors we have as standalone, I am pretty sure a significant part of them are not due to security issues, but due to hardware limit sometimes, for example, if the current DC without the sensor is so load that it has no room for the sensor,  and it's a physical machine that can't be scaled up for any reason, then you are kind of forced to standalone until you can upgrade.

 

Note, that while you try to enhance security by separating the sensor from the DC, you are also hurting security by having much less detection on the DC.


We do not support partially mirrored traffic (And I am also sure it will be pretty hard to implement mirroring by protocol/ports).

 

Does the Ops team has any SPECIFIC concerns/use cases I can try to address?

"hardening"  in general is not something I can really comment on,  as I proposed hardening options above... which more than 96% of sensors wold wide are satisfied with (most of them are satisfied with much less...).
If they have specific concerns, I can try to comment on them or help in engaging someone  else who can if I don't have the answer.

Highlighted

@Eli Ofek This is very helpful information. I need to discuss this further in our organization and with the Ops Teams. I'll come back to you, if we have more uncertainities. Thx!