MDI Sensor vs Standalone Sensor - Updated Guidance

%3CLINGO-SUB%20id%3D%22lingo-sub-2162889%22%20slang%3D%22en-US%22%3EMDI%20Sensor%20vs%20Stanalone%20Sensor%20-%20Updated%20Guidance%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2162889%22%20slang%3D%22en-US%22%3E%3CP%3EIt%20appears%20that%20guidance%20on%20MDI%20Sensor%20vs%20Stanalone%20Sensor%20has%20shifted%20towards%20discouraging%20Standalone%20sensors%20altogether.%20Standalone%20is%20now%20lacking%20functionality%2C%20while%20all%20the%20older%20materials%20highlighting%20its%20benefits%20had%20been%20removed.%20(E.g.%20higher%20stability%2Fthroughput%3B%20better%20security%20and%20separation%20of%20duties%2C%20especially%20when%20deployed%20as%20a%20member%20of%20a%20Workgroup%20etc.)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20begs%20the%20question%20-%20is%20Standalone%20on%20its%20way%20out%3F%20And%20what%20are%20the%20use%20cases%20you%20still%20believe%20it%20is%20best%20suited%20for%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2163751%22%20slang%3D%22en-US%22%3ERe%3A%20MDI%20Sensor%20vs%20Standalone%20Sensor%20-%20Updated%20Guidance%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2163751%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F977542%22%20target%3D%22_blank%22%3E%40MDIAdminMax%3C%2FA%3E%26nbsp%3B%3CBR%20%2F%3EIntegrated%20is%20clearly%20superior%20to%20standalone%20because%20it%20has%20many%20more%20data%20sources%20we%20can%20use%20to%20do%20detection%20and%20add%20additional%20security.%3C%2FP%3E%0A%3CP%3EUsing%20a%20Workgroup%20standalone%20is%20better%20security%20wise%20only%20in%20theory%2C%20assuming%20that%20it%20will%20be%20maintained%20and%20patched%20in%20the%20same%20level%20of%20a%20domain%20joined%20machine.%20In%20most%20cases%20it%20is%20not...%3CBR%20%2F%3EThere%20is%20no%20throughput%20change%20compared%20to%20integrated%2C%20but%20there%20is%20a%20possible%20scale%20issue%20if%20your%20DC%20is%20limited%20to%20scaling%20up%2C%20and%20your%20current%20spec%20will%20not%20allow%20the%20additional%20resources%20needed%20for%20the%20sensor%20(old%20physical%20machine%20for%20example).%3CBR%20%2F%3E%3CBR%20%2F%3EAs%20of%20today%2C%20only%203.19%25%20of%20sensors%20we%20have%20are%20standalone.%20the%20number%20keeps%20dropping%20monthly.%3CBR%20%2F%3EFor%20now%20there%20is%20no%20planned%20decision%20to%20remove%20this%20option%2C%20but%20in%20theory%20this%20can%20happen%20some%20time%20in%20the%20future%20once%20this%20umber%20will%20go%20down%20to%20a%20ridiculous%20number...%3CBR%20%2F%3E%3CBR%20%2F%3EThe%20Advice%20is%20clear%20-%20use%20Integrated%20whenever%20possible%2C%20use%20standalone%20as%20last%20option.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Visitor

It appears that guidance on MDI Sensor vs Standalone Sensor has shifted towards discouraging Standalone sensors altogether. Standalone is now lacking functionality, while all the older materials highlighting its benefits had been removed. (E.g. higher stability/throughput; better security and separation of duties, especially when deployed as a member of a Workgroup etc.)

 

This begs the question - is Standalone on its way out? And what are the use cases you still believe it is best suited for?

 

Thank you!

1 Reply

@MDIAdminMax 
Integrated is clearly superior to standalone because it has many more data sources we can use to do detection and add additional security.

Using a Workgroup standalone is better security wise only in theory, assuming that it will be maintained and patched in the same level of a domain joined machine. In most cases it is not...
There is no throughput change compared to integrated, but there is a possible scale issue if your DC is limited to scaling up, and your current spec will not allow the additional resources needed for the sensor (old physical machine for example).

As of today, only 3.19% of sensors we have are standalone. the number keeps dropping monthly.
For now there is no planned decision to remove this option, but in theory this can happen some time in the future once this umber will go down to a ridiculous number...

The Advice is clear - use Integrated whenever possible, use standalone as last option.