Security principal reconnaissance (LDAP) alert

%3CLINGO-SUB%20id%3D%22lingo-sub-2568162%22%20slang%3D%22en-US%22%3ESecurity%20principal%20reconnaissance%20(LDAP)%20alert%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2568162%22%20slang%3D%22en-US%22%3E%3CP%3EI%20received%20this%20alert%202%20hours%20after%20the%20alert%20was%20first%20seen%20.%20Why%20did%20it%20take%20two%20hours%20to%20send%20an%20alert%20%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Skipster3111_0-1626822618412.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F297205i429CF476901E3B66%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22Skipster3111_0-1626822618412.png%22%20alt%3D%22Skipster3111_0-1626822618412.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2568223%22%20slang%3D%22en-US%22%3ERe%3A%20Security%20principal%20reconnaissance%20(LDAP)%20alert%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2568223%22%20slang%3D%22en-US%22%3ESome%20detectors%20will%20hold%20back%20the%20info%20trying%20to%20collect%20more%20information%20before%20deciding%20if%20it's%20a%20false%20positive%20and%20should%20be%20ignored%20or%20not.%20Also%2C%20at%20time%20there%20could%20be%20ingestion%20delays.%20%3CBR%20%2F%3EIt's%20hard%20to%20tell%20for%20sure%20without%20checking%20each%20individual%20case%20as%20well.%3CBR%20%2F%3EDo%20you%20see%20any%20delays%20in%20any%20logical%20activities%20reported%20in%20the%20profile%20for%20an%20active%20entity%3F%3CBR%20%2F%3ECan%20you%20share%20the%20workspace%20id%20%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2570601%22%20slang%3D%22en-US%22%3ERe%3A%20Security%20principal%20reconnaissance%20(LDAP)%20alert%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2570601%22%20slang%3D%22en-US%22%3ESorry%2C%20very%20knew%20to%20defender%20for%20identity.%20Where%20can%20i%20find%20the%20workspace%20id%20%3F%3C%2FLINGO-BODY%3E
Frequent Contributor

I received this alert 2 hours after the alert was first seen . Why did it take two hours to send an alert ?

 

Skipster3111_0-1626822618412.png

 

4 Replies
Some detectors will hold back the info trying to collect more information before deciding if it's a false positive and should be ignored or not. Also, at time there could be ingestion delays.
It's hard to tell for sure without checking each individual case as well.
Do you see any delays in any logical activities reported in the profile for an active entity?
Can you share the workspace id ?
Sorry, very knew to defender for identity. Where can i find the workspace id ?
Press the ? button on the top right toolbar on the native MDI portal. it will pop up a window with some tech details.
9ea5fd22-168e-4ab1-99d2-9b87763f47d3