SOLVED

Number of sensors to install

%3CLINGO-SUB%20id%3D%22lingo-sub-275493%22%20slang%3D%22en-US%22%3ENumber%20of%20sensors%20to%20install%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-275493%22%20slang%3D%22en-US%22%3E%3CP%3EOn%20a%20small%2040%20user%20network%20is%20one%20sensor%20on%20a%20DC%20sufficient%20or%20should%20the%20sensor%20be%20installed%20on%20multiple%20domain%20controllers%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-275691%22%20slang%3D%22en-US%22%3ERe%3A%20Number%20of%20sensors%20to%20install%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-275691%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Eric%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ENo%20matter%20how%20many%20users%20you've%2C%20it%20matters%20how%20many%20DC's%20you've%20because%20of%20Azure%20ATP%20sensor%20reads%20events%20locally%2C%20so%20every%20DC%20server%20needs%20a%20sensor.%3C%2FP%3E%0A%3CP%3EAzure%20ATP%20Architecture%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure-advanced-threat-protection%2Fatp-architecture%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure-advanced-threat-protection%2Fatp-architecture%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EEli.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-275495%22%20slang%3D%22en-US%22%3ERe%3A%20Number%20of%20sensors%20to%20install%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-275495%22%20slang%3D%22en-US%22%3E%3CP%3EIt's%20not%20a%20matter%20of%20load%20for%20that%20matter%2C%20it's%20a%20matter%20of%20coverage.%3C%2FP%3E%0A%3CP%3EIf%20you%20have%20only%20one%20DC%20in%20the%20network%20that%20works%2C%20then%20you%20need%20to%20deploy%20only%20to%20it.%3C%2FP%3E%0A%3CP%3Eif%20you%20have%20many%20DCs%2C%20all%20of%20them%20should%20be%20deployed%20with%20a%20sensor%20to%20get%20good%20coverage.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Visitor

On a small 40 user network is one sensor on a DC sufficient or should the sensor be installed on multiple domain controllers?

2 Replies
Highlighted
Best Response confirmed by Eric Wukowitch (Occasional Visitor)
Solution

It's not a matter of load for that matter, it's a matter of coverage.

If you have only one DC in the network that works, then you need to deploy only to it.

if you have many DCs, all of them should be deployed with a sensor to get good coverage.

Highlighted

Hi Eric,

 

No matter how many users you've, it matters how many DC's you've because of Azure ATP sensor reads events locally, so every DC server needs a sensor.

Azure ATP Architecture https://docs.microsoft.com/en-us/azure-advanced-threat-protection/atp-architecture

 

Eli.