Using Express Route for Azure ATP sensors

%3CLINGO-SUB%20id%3D%22lingo-sub-388965%22%20slang%3D%22en-US%22%3EUsing%20Express%20Route%20for%20Azure%20ATP%20sensors%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-388965%22%20slang%3D%22en-US%22%3E%3CP%3EHas%20anyone%20ever%20tried%20using%20Azure%20ATP%20sensors%20over%20Express%20route%20and%20have%20some%20details%20on%20how%20it%20is%20done%3F%20For%20domain%20controllers%20that%20do%20not%20have%20internet%20access%20(and%20cannot%20have%20the%20TCP%20443%20opened%20up%2C%20even%20if%20only%20outbound)%20but%20that%20do%20have%20access%20to%20Express%20Route%2C%20this%20would%20be%20useful%20information%20to%20have%20and%20provide%20a%20good%20(and%20cheaper)%20alternative%20to%20using%20standalone%20sensors%20with%20port%20mirroring.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-391715%22%20slang%3D%22en-US%22%3ERe%3A%20Using%20Express%20Route%20for%20Azure%20ATP%20sensors%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-391715%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F45656%22%20target%3D%22_blank%22%3E%40Gerson%20Levitz%3C%2FA%3E-%20Thanks%20for%20your%20reply%2C%20and%20for%20confirming%20that%20Azure%20ATP%20does%20not%20(currently)%20support%20ExpressRoute.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt%20will%20be%20interesting%20to%20see%20how%20the%20new%20unified%20SecOps%20portal%20brings%20the%20three%20products%20together%2C%20and%20how%20this%20%3CEM%3Emight%3C%2FEM%3E%20introduce%20the%20ExpressRoute%20capability%20for%20Azure%20ATP%2C%20but%20for%20now%20it%20looks%20like%20a%20standalone%20Azure%20ATP%20sensor%20server%20will%20need%20to%20be%20used%20for%20my%20customer.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-391467%22%20slang%3D%22en-US%22%3ERe%3A%20Using%20Express%20Route%20for%20Azure%20ATP%20sensors%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-391467%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F293935%22%20target%3D%22_blank%22%3E%40Valon_Kolica%3C%2FA%3E%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F306428%22%20target%3D%22_blank%22%3E%40markwarnes%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAzure%20ATP%20(AATP)%20does%20not%20support%20Express%20route.%20This%20is%20something%20that%20should%20work%20when%20Secops%20Unified%20Portal%20is%20released.%20This%20is%20the%20merging%20of%20the%20Azure%20ATP%20and%20Microsoft%20Cloud%20App%20Security%20(MCAS)%20consoles%20are%20unified.%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20since%20MCAS%20supports%20ExpressRoute%20this%20should%20be%20something%20that%20AATP%20will%20also%20support.%26nbsp%3B%3C%2FP%3E%3CP%3EYou%20can%20read%20about%20the%20Secops%20unified%20portals%20in%20this%20blog%20from%20the%20RSA%20announcements.%26nbsp%3B%3C%2FP%3E%3CP%3EUnified%20SecOps%3A%20%3CA%20href%3D%22https%3A%2F%2Faka.ms%2Funifiedportal%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Faka.ms%2Funifiedportal%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-389560%22%20slang%3D%22en-US%22%3ERe%3A%20Using%20Express%20Route%20for%20Azure%20ATP%20sensors%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-389560%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F94531%22%20target%3D%22_blank%22%3E%40Andrew%20Harris%20(AZURE%20SEC)%3C%2FA%3E%3A%20Is%20this%20something%20you%20can%20speak%20to%3F%20%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1442516%22%20slang%3D%22en-US%22%3ERe%3A%20Using%20Express%20Route%20for%20Azure%20ATP%20sensors%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1442516%22%20slang%3D%22en-US%22%3E%3CP%3ESeeing%20as%20this%20was%20over%20a%20year%20ago%2C%20does%20anyone%20know%20if%20it's%20possible%20for%20on-prem%20AD%20servers%20running%20the%20AATP%20sensor%20to%20communicate%20with%20the%20service%20over%20express%20route%20yet%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1443624%22%20slang%3D%22en-US%22%3ERe%3A%20Using%20Express%20Route%20for%20Azure%20ATP%20sensors%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1443624%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F690028%22%20target%3D%22_blank%22%3E%40jgriff100%3C%2FA%3E%26nbsp%3BStill%20not%20possible.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

Has anyone ever tried using Azure ATP sensors over Express route and have some details on how it is done? For domain controllers that do not have internet access (and cannot have the TCP 443 opened up, even if only outbound) but that do have access to Express Route, this would be useful information to have and provide a good (and cheaper) alternative to using standalone sensors with port mirroring.

5 Replies

@Andrew Harris (AZURE SEC): Is this something you can speak to?  

Highlighted

@Valon_Kolica @markwarnes 

 

Azure ATP (AATP) does not support Express route. This is something that should work when Secops Unified Portal is released. This is the merging of the Azure ATP and Microsoft Cloud App Security (MCAS) consoles are unified. 

So since MCAS supports ExpressRoute this should be something that AATP will also support. 

You can read about the Secops unified portals in this blog from the RSA announcements. 

Unified SecOps: https://aka.ms/unifiedportal

 

Highlighted

@Gerson Levitz- Thanks for your reply, and for confirming that Azure ATP does not (currently) support ExpressRoute.

 

It will be interesting to see how the new unified SecOps portal brings the three products together, and how this might introduce the ExpressRoute capability for Azure ATP, but for now it looks like a standalone Azure ATP sensor server will need to be used for my customer.

Highlighted

Seeing as this was over a year ago, does anyone know if it's possible for on-prem AD servers running the AATP sensor to communicate with the service over express route yet?

Highlighted

@jgriff100 Still not possible.