Low success rate of active name resolution using RPC over NTLM

%3CLINGO-SUB%20id%3D%22lingo-sub-960911%22%20slang%3D%22en-US%22%3ELow%20success%20rate%20of%20active%20name%20resolution%20using%20RPC%20over%20NTLM%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-960911%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20all%20--%26nbsp%3B%3C%2FP%3E%3CP%3EI'm%20looking%20to%20resolve%20this%20last%20warning%2Falert%20from%20AATP%3B%26nbsp%3B%20we've%20had%20warnings%20about%20NetBIOS%20and%20reverse%20DNS%2C%20but%20those%20seem%20to%20have%20resolved%20on%20their%20own.%26nbsp%3B%20This%20last%20warning%20about%20RPC%20over%20NTLM%20is%20sticking%20around.%3C%2FP%3E%3CP%3EUnfortunately%2C%20I'm%20not%20even%20sure%20where%20to%20start.%26nbsp%3B%20I've%20looked%20thru%20Microsoft.Tri.Sensor.log%20on%20the%20server%20noted%20in%20the%20alert%2C%20and%20I'm%20seeing%20plenty%20of%20Warn's%2C%20but%20I%20don't%20know%20what%20to%20do%20about%20them.%20The%20vast%20majority%20are%20similar%20to%20this%3A%3C%2FP%3E%3CP%3E%3CFONT%20face%3D%22courier%20new%2Ccourier%22%20size%3D%222%22%3EWarn%20EntityResolver%20ResolveNtlmEventAsync%20%5BTime%3D10%2F28%2F2019%2022%3A20%3A16%20SourceAccountName%3Ddomain%5CsvcAccount%20SourceAccountId%3D34562b44-f302-43ef-9f53-a93e676514ef%20SourceComputerName%3D%20SourceComputerId%3D%20SourceIpAddress%3D%20DomainControllerName%3DDomainName%3D%20Name%3DDC01.ht.dom%20DomainControllerId%3D1d3c2345-954b-4d3c-aaf3-7753afcea337%20ErrorCode%3DSuccess%20ResourceIdentifier%3D%5D%3C%2FFONT%3E%3C%2FP%3E%3CP%3EAm%20i%20even%20looking%20in%20the%20right%20log%20file%20for%20clues%3F%26nbsp%3B%20Is%20there%20a%20more%20descriptive%2Fhelpful%20location%20for%20details%20on%20exactly%20where%20the%20communication%20is%20failing%20and%20how%20to%20fix%20it%3F%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-960934%22%20slang%3D%22en-US%22%3ERe%3A%20Low%20success%20rate%20of%20active%20name%20resolution%20using%20RPC%20over%20NTLM%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-960934%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F435172%22%20target%3D%22_blank%22%3E%40thatguy000%3C%2FA%3E%26nbsp%3B%2C%20You%20can%20ignore%20this%20warn%20message%20you%20found%20on%20the%20logs.%20it's%20unrelated.%3C%2FP%3E%0A%3CP%3EAS%20for%20the%20name%20resolution%20issue%2C%20it's%20a%20bit%20tricky%20to%20resolve%20it%20on%20your%20own%2C%20I%20strongly%20suggest%20to%20open%20a%20support%20ticket%20and%20get%20guidance%20from%20the%20support%20engineer%20about%20which%20data%20you%20need%20to%20collect%20and%20how.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EEli%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-960952%22%20slang%3D%22en-US%22%3ERe%3A%20Low%20success%20rate%20of%20active%20name%20resolution%20using%20RPC%20over%20NTLM%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-960952%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F106935%22%20target%3D%22_blank%22%3E%40Eli%20Ofek%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWell%20that's%20disappointing..%20one%20would%20think%20if%20a%20service%20is%20deemed%20%22Ready%20for%20the%20public%22%20then%20it%20would%20have%20documentation%20and%20tools%20available%20to%20the%20enduser%20to%20resolve%20these%20issues.%20So%20much%20for%20logic.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%20for%20the%20quick%20response%20tho.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-961026%22%20slang%3D%22en-US%22%3ERe%3A%20Low%20success%20rate%20of%20active%20name%20resolution%20using%20RPC%20over%20NTLM%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-961026%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F435172%22%20target%3D%22_blank%22%3E%40thatguy000%3C%2FA%3E%26nbsp%3B%2C%20This%20is%20indeed%20the%20aspiration%2C%20sadly%2C%20when%20the%20service%20depends%20on%20a%20sensor%20that%20still%20has%20to%20run%20on%20prem%2C%26nbsp%3B%20there%20are%20environmental%20challenges%20which%20we%20cannot%20easily%20control%20(Yet%20we%20always%20try%20to%20improve%20that%20in%20new%20ways).%3CBR%20%2F%3EThe%20issue%20you%20mentioned%20is%20not%20happening%26nbsp%3B%20due%20to%20misconfiguration%20of%26nbsp%3B%20the%20product%20or%20service%2C%20but%20due%20to%20on%20prem%26nbsp%3B%20network%20characteristics%20and%20configuration%20(Giving%20that%20you%20followed%20the%20deployment%20guide%20already%2C%20and%20made%20sure%20requested%20ports%20are%20properly%20open).%26nbsp%3B%20Those%20at%20times%20can%20be%20complicated%20to%20troubleshoot%20for%20some%20customers.%3C%2FP%3E%0A%3CP%3EWhile%20we%20are%20currently%20researching%20the%20development%20of%20tools%20that%20will%20make%20it%20easier%20for%20the%20customers%20to%20troubleshoot%20this%20issue%2C%20currently%20getting%20guidance%20from%20support%20is%20still%20the%20quickest%20way%20for%20most%20customers.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

Hello all -- 

I'm looking to resolve this last warning/alert from AATP;  we've had warnings about NetBIOS and reverse DNS, but those seem to have resolved on their own.  This last warning about RPC over NTLM is sticking around.

Unfortunately, I'm not even sure where to start.  I've looked thru Microsoft.Tri.Sensor.log on the server noted in the alert, and I'm seeing plenty of Warn's, but I don't know what to do about them. The vast majority are similar to this:

Warn EntityResolver ResolveNtlmEventAsync [Time=10/28/2019 22:20:16 SourceAccountName=domain\svcAccount SourceAccountId=34562b44-f302-43ef-9f53-a93e676514ef SourceComputerName= SourceComputerId= SourceIpAddress= DomainControllerName=DomainName= Name=DC01.ht.dom DomainControllerId=1d3c2345-954b-4d3c-aaf3-7753afcea337 ErrorCode=Success ResourceIdentifier=]

Am i even looking in the right log file for clues?  Is there a more descriptive/helpful location for details on exactly where the communication is failing and how to fix it?  

Thanks

3 Replies
Highlighted

@thatguy000 , You can ignore this warn message you found on the logs. it's unrelated.

AS for the name resolution issue, it's a bit tricky to resolve it on your own, I strongly suggest to open a support ticket and get guidance from the support engineer about which data you need to collect and how. 

 

Eli

Highlighted

@Eli Ofek 

Well that's disappointing.. one would think if a service is deemed "Ready for the public" then it would have documentation and tools available to the enduser to resolve these issues. So much for logic. 

 

Thank you for the quick response tho.

Highlighted

@thatguy000 , This is indeed the aspiration, sadly, when the service depends on a sensor that still has to run on prem,  there are environmental challenges which we cannot easily control (Yet we always try to improve that in new ways).
The issue you mentioned is not happening  due to misconfiguration of  the product or service, but due to on prem  network characteristics and configuration (Giving that you followed the deployment guide already, and made sure requested ports are properly open).  Those at times can be complicated to troubleshoot for some customers.

While we are currently researching the development of tools that will make it easier for the customers to troubleshoot this issue, currently getting guidance from support is still the quickest way for most customers.