MDI and Azure Arc

Silver Contributor

If we have deployed MDI to monitor the AD DCs, is there any reason to:

1. register these servers with Azure Arc

2. Connect them with MMA to Sentinel

 

I don't think so, but I would like to make sure that I'm not overlooking something

TIA

5 Replies

@Dean Gross 

It is not required for MDI.

 

thanks but i dont understand your response, could you please elaborate

@Dean Gross 

Registering the server with AzureArc and installing the MMA agent would enable you several other benefits, some are described in Azure Arc overview - Azure Arc | Microsoft Docs. But they are not required for MDI to work properly in your environment.

@Martin_Schvartzman thanks, as a follow up, if we arc enable a DC and monitor it with Defender for Servers, how will that overlap with functionality provided by MDI?

 

In a total coincidence, @matthew zorich posted this https://learnsentinel.blog/2022/04/12/monitoring-active-directory-with-microsoft-sentinel-the-agent-... which provides a great explanation and may be helpful to others