SOLVED

MDI sensors required on ADFS WAP servers?

%3CLINGO-SUB%20id%3D%22lingo-sub-2073794%22%20slang%3D%22en-US%22%3EMDI%20sensors%20required%20on%20ADFS%20WAP%20servers%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2073794%22%20slang%3D%22en-US%22%3E%3CP%3EHi%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20the%20MDI%20sensor%20required%20on%20the%20ADFS%20WAP%20servers%2C%20or%20will%20installing%20them%20on%20the%20regular%20ADFS%20servers%20be%20sufficient%3F%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3CP%3EOur%20WAP%20servers%20are%20not%20domain%20joined%2C%20so%20not%20sure%20how%20that%20would%20work%20with%20the%20Directory%20Service%20accounts%2C%20on%20the%20regular%20ADFS%20servers%20the%20agent%20would%20not%20start%20until%20it%20had%20access%20to%20the%20gMSA%20account.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2076619%22%20slang%3D%22en-US%22%3ERe%3A%20MDI%20sensors%20required%20on%20ADFS%20WAP%20servers%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2076619%22%20slang%3D%22en-US%22%3ENo%20you%20do%20not%20need%20to%20install%20it%20the%20WAP%20servers%3C%2FLINGO-BODY%3E
Occasional Contributor

Hi

 

Is the MDI sensor required on the ADFS WAP servers, or will installing them on the regular ADFS servers be sufficient?

Our WAP servers are not domain joined, so not sure how that would work with the Directory Service accounts, on the regular ADFS servers the agent would not start until it had access to the gMSA account.

3 Replies
best response confirmed by Joachim83 (Occasional Contributor)
Solution
No you do not need to install it the WAP servers
Spoiler
 

@Bjarne Abraham  And exactly why not? I mean, activity on the WAP may not reach ADFS, hence you miss these signals of possible malicious actions.

One do not install MDI sensors on servers that does not hand out keys to the kingdom.