MCAS Activity log: "back and forth" entries on changed properties

%3CLINGO-SUB%20id%3D%22lingo-sub-2372247%22%20slang%3D%22en-US%22%3EMCAS%20Activity%20log%3A%20%22back%20and%20forth%22%20entries%20on%20changed%20properties%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2372247%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20everyone%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%26nbsp%3BMCAS%20Activity%20log%20we%20have%20many%20%22back%20and%20forth%22%20entries%20regarding%20the%20property%20%22%3CSPAN%3EComputer%20Operating%20System%22%20%26amp%3B%20%22AccountSupportedEncryptionTypes%22%20changed%20from%20N%2FA%20to%20a%20value%20and%203%20minutes%20later%20the%20property%20changed%26nbsp%3B%3C%2FSPAN%3Eback%20from%20a%20value%20to%20N%2FA.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CU%3EExamples%3C%2FU%3E%3A%3C%2FP%3E%3CP%3E%3CSPAN%3E5%2F15%2F21%203%3A20%20AM%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3Eproperty%3C%2FSPAN%3E%3CSPAN%3E%3A%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3EComputer%20Operating%20System%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3Edevice%26nbsp%3B%3CSTRONG%3EAWxxxxx001%3C%2FSTRONG%3E%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3Efrom%20property%26nbsp%3B%3CSTRONG%3EWindows%20Server%202019%20Datacenter%2C%2010.0%20(17763)%3C%2FSTRONG%3E%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3Eto%20property%26nbsp%3B%3CSTRONG%3EN%2FA%3C%2FSTRONG%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3E5%2F15%2F21%203%3A23%20AM%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3Eproperty%3A%26nbsp%3BComputer%20Operating%20System%26nbsp%3Bdevice%26nbsp%3B%3CSTRONG%3EAWxxxxx001%3C%2FSTRONG%3E%26nbsp%3Bfrom%20property%26nbsp%3B%3CSTRONG%3EN%2FA%3C%2FSTRONG%3E%26nbsp%3Bto%20property%26nbsp%3B%3CSTRONG%3EWindows%20Server%202019%20Datacenter%2C%2010.0%20(17763)%3C%2FSTRONG%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3E5%2F15%2F21%203%3A20%20AM%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3ESet%20property%3C%2FSPAN%3E%3CSPAN%3E%3A%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3EAccountSupportedEncryptionTypes%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3Edevice%26nbsp%3B%3CSTRONG%3EAWxxxxx001%3C%2FSTRONG%3E%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3Efrom%20property%26nbsp%3B%3CSTRONG%3ERc4%2CAes128%2CAes256%3C%2FSTRONG%3E%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3Eto%20property%26nbsp%3B%3CSTRONG%3EN%2FA%3C%2FSTRONG%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3E5%2F15%2F21%203%3A23%20AM%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3ESet%20property%3C%2FSPAN%3E%3CSPAN%3E%3A%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3EAccountSupportedEncryptionTypes%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3Edevice%26nbsp%3B%3CSTRONG%3EAWxxxxx001%3C%2FSTRONG%3E%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3Efrom%20property%26nbsp%3B%3CSTRONG%3EN%2FA%3C%2FSTRONG%3E%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3Eto%20property%26nbsp%3B%3CSTRONG%3ERc4%2CAes128%2CAes256%3C%2FSTRONG%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3E5%2F15%2F21%203%3A24%20AM%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3ESet%20property%3A%26nbsp%3BAccountSupportedEncryptionTypes%26nbsp%3Bdevice%26nbsp%3B%3CSTRONG%3EAWxxxxx001%3C%2FSTRONG%3E%26nbsp%3Bfrom%20property%26nbsp%3B%3CSTRONG%3ERc4%2CAes128%2CAes256%3C%2FSTRONG%3E%26nbsp%3Bto%20property%26nbsp%3B%3CSTRONG%3EN%2FA%3C%2FSTRONG%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EI%20suppose%20these%20property%20changes%20are%20detected%20by%20MDI%20on%20the%20AD%20computer%20attribute%20object.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20have%20many%20similar%20cases%2C%20in%20this%20example%20the%20device%20is%20a%20Domain%20Controller%2C%20created%20one%20year%20ago.%3CBR%20%2F%3EWe%20do%20not%20touch%20the%20attributes%20msDS-SupportedEncryptionTypes%2C%26nbsp%3BoperatingSystem%20or%26nbsp%3BoperatingSystemVersion%20in%20AD.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20idea%20who%20detected%20these%20property%20changes%20(MDI%3F)%20and%20why%3F%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EBest%20regards%2C%3CBR%20%2F%3EDanny%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22MDI_MCAS_Activity_log_set_property_back_and_forth.jpg%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F282183i79E54D0EBD70B0F0%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22MDI_MCAS_Activity_log_set_property_back_and_forth.jpg%22%20alt%3D%22MDI_MCAS_Activity_log_set_property_back_and_forth.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22MDI_MCAS_Activity_log_set_property_back_and_forth_2.jpg%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F282185iAC8F028C88EAE5E9%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22MDI_MCAS_Activity_log_set_property_back_and_forth_2.jpg%22%20alt%3D%22MDI_MCAS_Activity_log_set_property_back_and_forth_2.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2378872%22%20slang%3D%22en-US%22%3ERe%3A%20MCAS%20Activity%20log%3A%20%22back%20and%20forth%22%20entries%20on%20changed%20properties%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2378872%22%20slang%3D%22en-US%22%3EThose%20are%20detected%20by%20MDI.%20MDI%20follows%20the%20usn%20changes%20on%20those%20entities%2C%20and%20when%20the%20usn%20%23%20changes%2C%20it%20checks%20what%20has%20changed%20from%20the%20previous%20syn%20and%20log%20the%20activity.%3CBR%20%2F%3Efor%20this%20machine%20that%20keeps%20changing%2C%20can%20you%20check%20the%20usn%20number%20after%20every%20MDI%20report%20%3F%20does%20it%20stay%20the%20same%3F%20if%20not%2C%20it's%20a%20proof%20that%20something%20indeed%20touched%20this%20entity%20(maybe%20for%20a%20brief%20moment)...%20and%20you%20might%20not%20be%20aware%20of%20what%20does%20it.%3C%2FLINGO-BODY%3E
Occasional Contributor

Hi everyone,

 

In MCAS Activity log we have many "back and forth" entries regarding the property "Computer Operating System" & "AccountSupportedEncryptionTypes" changed from N/A to a value and 3 minutes later the property changed back from a value to N/A.

 

Examples:

5/15/21 3:20 AM

propertyComputer Operating System device AWxxxxx001 from property Windows Server 2019 Datacenter, 10.0 (17763) to property N/A

5/15/21 3:23 AM

property: Computer Operating System device AWxxxxx001 from property N/A to property Windows Server 2019 Datacenter, 10.0 (17763)

 

5/15/21 3:20 AM

Set propertyAccountSupportedEncryptionTypes device AWxxxxx001 from property Rc4,Aes128,Aes256 to property N/A

5/15/21 3:23 AM

Set propertyAccountSupportedEncryptionTypes device AWxxxxx001 from property N/A to property Rc4,Aes128,Aes256

5/15/21 3:24 AM

Set property: AccountSupportedEncryptionTypes device AWxxxxx001 from property Rc4,Aes128,Aes256 to property N/A


I suppose these property changes are detected by MDI on the AD computer attribute object.

 

We have many similar cases, in this example the device is a Domain Controller, created one year ago.
We do not touch the attributes msDS-SupportedEncryptionTypes, operatingSystem or operatingSystemVersion in AD.

 

Any idea who detected these property changes (MDI?) and why?


Best regards,
Danny

MDI_MCAS_Activity_log_set_property_back_and_forth.jpg

 

MDI_MCAS_Activity_log_set_property_back_and_forth_2.jpg

1 Reply
Those are detected by MDI. MDI follows the usn changes on those entities, and when the usn # changes, it checks what has changed from the previous syn and log the activity.
for this machine that keeps changing, can you check the usn number after every MDI report ? does it stay the same? if not, it's a proof that something indeed touched this entity (maybe for a brief moment)... and you might not be aware of what does it.