Sep 20 2023 01:41 AM
We are implementing Windows Defender for Identity. As our domain controllers are not allowed to communicate with the internet, we have setup a dedicated member server for the sensor.
The operating system is Windows Server 2019 (10.0.17763). We have installed the sensor, however the sensor fails to start. The Log "Azure Advanced Threat Protection Sensor" does not hold any information besides the installation:
[07B8:0A9C][2023-09-19T14:46:35]i410: Variable: WixBundleOriginalSource = C:\temp\Azure ATP Sensor Setup\Azure ATP Sensor Setup.exe [07B8:0A9C][2023-09-19T14:46:35]i410: Variable: WixBundleOriginalSourceFolder = C:\temp\Azure ATP Sensor Setup\ [07B8:0A9C][2023-09-19T14:46:35]i410: Variable: WixBundleProviderKey = {47d0bc49-a03e-408c-bc8d-251917ef0d75} [07B8:0A9C][2023-09-19T14:46:35]i410: Variable: WixBundleRollbackLog_MsiPackage = C:\Users\ADM_JD~1\AppData\Local\Temp\Azure Advanced Threat Protection Sensor_20230919144435_000_MsiPackage_rollback.log [07B8:0A9C][2023-09-19T14:46:35]i410: Variable: WixBundleSourceProcessFolder = C:\temp\Azure ATP Sensor Setup\ [07B8:0A9C][2023-09-19T14:46:35]i410: Variable: WixBundleSourceProcessPath = C:\temp\Azure ATP Sensor Setup\Azure ATP Sensor Setup.exe [07B8:0A9C][2023-09-19T14:46:35]i410: Variable: WixBundleTag = [07B8:0A9C][2023-09-19T14:46:35]i410: Variable: WixBundleUILevel = 4 [07B8:0A9C][2023-09-19T14:46:35]i410: Variable: WixBundleVersion = 2.213.17071.5302 [07B8:0A9C][2023-09-19T14:46:36]i007: Exit code: 0x0, restarting: No |
the only thing we see is the event in the system event log:
The Azure Advanced Threat Protection Sensor service terminated unexpectedly
The majority of the logs described here are missing
Troubleshooting the sensor using logs - Microsoft Defender for Identity | Microsoft Learn
the only ones we see are:
Name : Azure Advanced Threat Protection Sensor_20230920102142.log
Name : Azure Advanced Threat Protection Sensor_20230920102208.log
Name : Azure Advanced Threat Protection Sensor_20230920102208_000_MsiPackage.log
Name : Azure Advanced Threat Protection Sensor_20230920102427.log
Name : Azure Advanced Threat Protection Sensor_20230920102427_000_MsiPackage.log
Name : Microsoft.Tri.Sensor.Deployment.Deployer_20230920082231.log
Name : Microsoft.Tri.Sensor.Deployment.Deployer_20230920082542.log
Sep 20 2023 05:05 AM
Sep 20 2023 07:27 AM
Sep 20 2023 08:21 AM
SolutionSep 21 2023 12:26 AM
Sep 21 2023 12:33 AM
Sep 21 2023 06:38 AM
Sep 21 2023 07:08 AM
Sep 22 2023 02:29 AM
Sep 22 2023 02:45 AM - edited Sep 24 2023 11:56 PM
i Ran the following command Azure ATP Sensor Setup.exe ProxyURL="http://10.0.100.4:8080"
2023-09-22 09:36:22.3192 Info Program Main Deployer started [arguments=UupWdR8YVoHtaVBj0WBPKQ==] 2023-09-22 09:36:22.4129 Debug InstallActionGroup Apply started 2023-09-22 09:36:22.4129 Debug CreateCertificateAction Apply started [suppressFailure=False] 2023-09-22 09:36:26.4754 Debug CreateCertificateAction Apply finished 2023-09-22 09:36:26.4754 Debug CreateSensorAction Apply started [suppressFailure=False] 2023-09-22 09:36:27.1004 Info CreateSensorAction ApplyInternal Adfs installation research log [adfsCommandOutput=Get-Command : The term 'Get-AdfsProperties' is not recognized as the name of a cmdlet, function, script file, or operable program. Check the spelling of the name, or if a path was included, verify that the path is correct and try again. At line:1 char:2 + (Get-Command Get-AdfsProperties).Source + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + CategoryInfo : ObjectNotFound: (Get-AdfsProperties:String) [Get-Command], CommandNotFoundException + FullyQualifiedErrorId : CommandNotFoundException,Microsoft.PowerShell.Commands.GetCommandCommand adfssrv state=null user=Contoso\administrator] 2023-09-22 09:36:27.6629 Debug CreateSensorAction Apply finished 2023-09-22 09:36:27.6629 Debug TestCertificateAndProxyAction Apply started [suppressFailure=False] 2023-09-22 09:36:27.8661 Debug TestCertificateAndProxyAction Apply finished 2023-09-22 09:36:27.8661 Debug SaveSensorMandatoryConfigurationAction Apply started [suppressFailure=False] 2023-09-22 09:36:27.8973 Debug SaveSensorMandatoryConfigurationAction Apply finished 2023-09-22 09:36:27.8973 Debug CreateServicesActionGroup Apply started 2023-09-22 09:36:27.8973 Debug CreateServiceAction Apply started [suppressFailure=False] 2023-09-22 09:36:27.8973 Debug CreateServiceAction Apply finished 2023-09-22 09:36:27.8973 Debug SetServiceDescriptionAction Apply started [suppressFailure=False] 2023-09-22 09:36:27.9129 Debug SetServiceDescriptionAction Apply finished 2023-09-22 09:36:27.9129 Debug ConfigureServiceAction Apply started [suppressFailure=False] 2023-09-22 09:36:27.9285 Debug ConfigureServiceAction Apply finished 2023-09-22 09:36:27.9285 Debug SetServicePreshutdownTimeoutAction Apply started [suppressFailure=False] 2023-09-22 09:36:27.9285 Debug SetServicePreshutdownTimeoutAction Apply finished 2023-09-22 09:36:27.9285 Debug CreateServiceAction Apply started [suppressFailure=False] 2023-09-22 09:36:27.9285 Debug CreateServiceAction Apply finished 2023-09-22 09:36:27.9285 Debug SetServiceDescriptionAction Apply started [suppressFailure=False] 2023-09-22 09:36:27.9285 Debug SetServiceDescriptionAction Apply finished 2023-09-22 09:36:27.9285 Debug ConfigureServiceAction Apply started [suppressFailure=False] 2023-09-22 09:36:27.9442 Debug ConfigureServiceAction Apply finished 2023-09-22 09:36:27.9442 Debug SetServicePreshutdownTimeoutAction Apply started [suppressFailure=False] 2023-09-22 09:36:27.9442 Debug SetServicePreshutdownTimeoutAction Apply finished 2023-09-22 09:36:27.9442 Debug CreateServicesActionGroup Apply finished 2023-09-22 09:36:27.9442 Debug ConfigureVirtualServiceAccountAction Apply started [suppressFailure=False] 2023-09-22 09:36:27.9754 Debug ConfigureVirtualServiceAccountAction Apply finished 2023-09-22 09:36:27.9754 Debug RegisterCrashDumpsAction Apply started [suppressFailure=False] 2023-09-22 09:36:27.9754 Debug RegisterCrashDumpsAction Apply finished 2023-09-22 09:36:27.9754 Debug EnableTls12Action Apply started [suppressFailure=False] 2023-09-22 09:36:27.9754 Debug EnableTls12Action Apply finished 2023-09-22 09:36:27.9754 Debug CopyServiceLogsOnRevertAction Apply started [suppressFailure=False] 2023-09-22 09:36:27.9754 Debug CopyServiceLogsOnRevertAction Apply finished 2023-09-22 09:36:27.9754 Debug StartServiceAction Apply started [suppressFailure=False] 2023-09-22 09:36:34.8232 Debug StartServiceAction Apply finished 2023-09-22 09:36:34.8232 Debug InstallActionGroup Apply finished 2023-09-22 09:36:34.8232 Info Program Main Deployer finished |
Sep 26 2023 06:05 AM