Git Product home page Git Product logo

atadocs's Introduction

atadocs's People

Contributors

batamig avatar danaim1 avatar dcurwin avatar fngrhth avatar huypub avatar kgremban avatar lizap avatar martin77s avatar meganbradley avatar mestew avatar mlottner avatar msmbaldwin avatar ophirp avatar ortsemah avatar prmerger-automator[bot] avatar rkarlin avatar ronitlitinsky avatar saisang avatar shsagir avatar stacyrch140 avatar stevenpo-ms avatar syntaxc4 avatar taojunshen avatar ttorble avatar tynevi avatar v-anpasi avatar v-ccolin avatar v-dirichards avatar v-makoud avatar v-maudel avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

atadocs's Issues

If you use Azure AD Connect ... Beware

If your using Azure AD Connect, make sure you add the MSOL_XXXYYY account to this policy else you will not be able to do password reset or self service password resets. Also just be very very wary of this, once we turned it on, a lot of poorly developed apps broke, which required the service account being added to this policy.


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Licensing Requirements

What user accounts specifically need to be licensed for this feature? Admins? Users? Both?


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Yammer group is closed

Suggest to update this article mentioning that the yammer group is now closed and moved to Tech Community


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

  • ID: 13ab0c38-25db-8bc9-4cbb-dde15db222ed
  • Version Independent ID: 73b4cba8-1dc6-9bee-d234-4378e3df2408
  • Content: Azure ATP support
  • Content Source: ATPDocs/atp-support.md
  • Service: azure-advanced-threat-protection
  • GitHub Login: @mlottner
  • Microsoft Alias: mlottner

Domain synchronizer candidate for ATP sensors

Could clarity be added in the 'Domain synchronizer candidate' section to understand if Azure ATP sensors should be enable as synchronizer candidates in an exclusively ATP sensor environment (i.e. no ATP Standalone sensors)


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Need to update guidance for multiple workspaces

Multiple workspaces are blocked by default: customer can only create one workspace.

Workspaces are moving to support multi-forest deployment

Need to remove this guidance :
In Azure ATP, you have the ability to manage and monitor multiple workspaces. This is especially helpful if you want to create a demo workspace and a test workspace in which you can POC Azure ATP before rolling it out to your whole organization. This is also needed to support deployments with multiple forests. A single workspace can only monitor multiple domains from a single forest.


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Offline installsource is wrong

@mbrogies commented on Mon Oct 08 2018

The offline install source of .net4.7 is wrong.
It's referencing to .net4.6.1


Dokumentdetails

Bearbeiten Sie diesen Abschnitt nicht. Er ist für die Verknüpfung von docs.microsoft.com zum GitHub-Artikel erforderlich.

Configuration recommendations - which Windows Firewall rules should be enabled?

please be specific
and please fix the doc:
"Port 135" should be changed to "TCP port 135"
"Port 137" should be changed to "UDP port 137"


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Additional instruction request

Please can you add Command Line/PowerShell commands for resolving the VMWare issue?

Set the following settings to 0 or Disabled in the virtual machine's NIC configuration: TsoEnable, LargeSendOffload, TSO Offload, Giant TSO Offload.

I need to do the TSO Offload (as per the note) on Windows Server Core in particular

Thank you


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

How to manually create a backup on demand?

It's great that ATA backs up it's config every 4 hours, but let's say I've just made a change and want to manually backup the config. How can I do that?


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Small spelling error

"report is always available is LMPs were discovered"
should be
"report is always available if LMPs were discovered"
In other words: is -> if

Step 5 screenshot does not match text

The text states that the screen shot should show a standalone install, but the screen shot shows the installation on a domain controller. Please make the text and image consistent


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

The "Before you Start" Section has incorrect licensing info on it

The top bullet point "Acquire a license for Enterprise Mobility + Security 5 (EMS E5) directly via the Microsoft 365 portal or through the Cloud Solution Partner (CSP) licensing model." is not factually correct.

Azure ATP may be procured as a standalone product by a customer. EM+S E5 is not required. However, if a customer owns EM+S E5, then yes, they will also own Azure ATP as well. Same thing as Microsoft 365 E5 -- if you own that license, then you also already own Azure ATP (because M365 E5 includes the EM+S E5 suite).


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Unable to download report from ATA

I have a ATA 1.9.7312.32791. When ever i go to reports and try to download, it would not download with a error. please help. I am very sure it is not the browser issue and i have reinstall ATA a few times, and even create a new OS from start and reinstall it. Seems like it does not work.

image

Tip for "All domain controllers are unreachable by a sensor"

Make sure you have defined credentials for the forest under Directory Services in Settings. (I forgot to enter a Service account, and the install package includes all the service accounts for all forests).


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Missing Images and Formatting

The images are missing, and there is broken formatting in Step 2, section 1c.


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Wrong syntax for ATP sensor install

The syntax for the install of the azure atp sensor has an inconsistency on the AccessKey param. In the syntax box is shows as prefaced with a slash but in the installation params section it doesn't. The install fails with an error "Option /AccessKey is unknown" if you include the slash.

This was mentioned in issue 98 but wasn't corrected completely.

server 2019

After KB4487044 Windows Server 2019 should be supported. isn't it?


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

How to Verify the machine has connectivity to the relevant Azure ATP cloud service endpoint(s)

One thing my might be helpful would be to give some options on how to verify connectivity to the ATP Cloud service.


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Monitored user activities: AD security principal operations

I just wonder, for these, i notice it says it is changed, but it did not say who change it. Is this something can be done in Azure ATP?


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Incorrect order for steps

The step to start ATA Center service should be after the system profile import
Step 5, a, iii - Start the ATA Center service
** should be moved to before Step 5, c


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Please clarify how to use as a Pure Azure AD customer

Hi,
The path/prerequisites don't seem to explain how a customer that has implemented pure Azure AD, with Azure AD joined systems could possibly implement Azure ATP. It seems like the pre-requisites should mention that this only applies for on-premise (or traditional) Windows domains. I know that one can conclude that after reading all content carefully but why lead us down a path that is in the end invalid.
Also: What if we have a radius server that is connected to Azure AD, what document do we need to consult? How can we possible set up Azure ATP. Did Microsoft built ATP sensors into Azure AD?
Bart


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Please add that this is only for "standard Active Directory"

Hi,
We are a pure Azure Active Directory shop and when I went through the motions to set this up, one of the first steps was indeed to download the sensor to one of our Domain controllers, which we don't have since we don't have Domain Controllers.
Please add some clarification that this is not for Azure Active Directory. And maybe you can then also point users of Azure Active Directory to ATP for those setups, if they exist?
Thank you
Bart


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

PDF not working

https://docs.microsoft.com/en-us/advanced-threat-analytics/opbuildpdf/TOC.pdf?branch=live
...has a Download PDF option, that doesn't open.

[Enter feedback here]


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

More endpoints for Azure ATP

Under Step 1, there are a number of endpoints listed, however the following article shows even more endpoints. I would suggest to align both articles so they have the same endpoints listed.

https://docs.microsoft.com/en-us/azure-advanced-threat-protection/configure-proxy


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Missing graphic

![Sample capacity planning tool](media/capacity tool.png)

I assume there was supposed to be a graphic embedded in the page?


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Enabling Advanced Audit Policy Configuration

You need to enable "Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings" in Group Policy. The setting can be found under Computer Configuration\Policies\Security Settings\Local Policies\Security Options, and sets the SCENoApplyLegacyAuditPolicy registry key to prevent basic auditing being applied.


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Wrong information?

Should registry value DefaultConnectionSetting be DefaultConnectionSettings ? Like HKCU\Software\Microsoft\Windows\CurrentVersion\InternetSetting\Connections\DefaultConnectionSettings


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

"a static non-routable IP address"sample has been used

The Sample is "1.1.1.1/32", but this ip has been used by CloudFlare. it have sensor and it's DNS server.


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Schedule the time for daily reports

The daily reports are always sent shortly after midnight, UTC - that's not great for our timezone (which changes based on daylight savings). Can this be configurable?


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

  • ID: bc9f5742-faf6-f294-440d-d038268a52c8
  • Version Independent ID: ed4a451b-733e-13ba-b21a-3962cd4b8ab8
  • Content: Working with ATA Reports
  • Content Source: ATADocs/reports.md
  • Product: advanced-threat-analytics
  • GitHub Login: @rkarlin
  • Microsoft Alias: rkarlin

Please support GMSA or "run as service" identities, so passwords are not needed...

Requiring a username/password and service account that isn't a GMSA is very old school.


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Event Viewer Subscriptions on Server Core?

Can you update this document to include instructions for Server Core? Subscriptions is not accessible from Event Viewer connected to a remote computer, and Event Viewer is not available on Server Core.


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Provide a DSC and/or Powershell automated installation for this.

In environments with many, many DC's, it's very useful to be able to install via automation / unattended. Please add support for DSC or Powershell based automation...


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Missing letter

In the paragraph:
Optional: When deploying the standalone sensor, it is necessary to forward Windows events 4776, 4732, 4733, 4728, 4729, 4756, 4757, and 7045 to zure ATP to further enhance Azure ATP Pass-the-Hash, Brute Force, Modification to sensitive groups, Honey Tokens detections, and malicious service creation. Azure ATP sensor receives these events automatically. In Azure ATP standalone sensor, these events can be received from your SIEM or by setting Windows Event Forwarding from your domain controller. Events collected provide Azure ATP with additional information that is not available via the domain controller network traffic.

After 7045 you're missing the A in Azure.


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Wrong Syntax for sensor install cmd

The syntax listed for silently installing the sensor has accesskey listed as an option, not a parameter, which causes the install to fail with "Option '/accesskey' is unknown".


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

How can I test Azure ATP?

"nslookup -" > enter > "ls -d" isn't a real sequence of commands. Please correct, thanks.


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

This policy breaks Citrix and RDP logins on pre-Server 2016 systems

Within minutes of enabling this policy all RDP and Citrix logins to pre-Server 2016 systems were blocked. I backed out of the policy, but the registry change on the servers wasn't reversed. Rather than manually edit the registry on several hundred servers I re-enabled the policy, but added Authenticated Users to the ACL to recover. Did anyone at Microsoft ever consider that Server 2008 and Server 2012 are still in use and should be included in testing?


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Recommendations for HoneyToken user

Please give recommendations for for the HT user. The documenation is lacking information about this.


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

add ATA Gateway to "Event Log Reader"

I couldn't get the event log forwarding to function when following this article. Would give me a "Access Denied". When you add the computer object of your ATA Gateway machine to the domain group "Event Log Readers", The subscriptions starts to work.


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Two spelling issues

Hi Team, two things I noticed. There's a "bout" word that should be "about." Also "network recourses" should be "network resources." Hope this helps.


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

npcap installer options should be changed

According to https://nmap.org/npcap/guide/npcap-users-guide.html#npcap-installation-options the installer options should be
/loopback_support=no /winpcap_mode=no


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Network Name Resolution (NNR) - Regarding

Network Name Resolution (NNR) mechanism was improved significantly - Is this done by program logic? or Is there any better Windows API?


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Wrong information

Item 6. Go to Account Logon , double click on Audit Security Group Management and select Configure the following audit events for both success and failure events.
Should be:
Go to Account Management , double click on Audit Security Group Management and select Configure the following audit events for both success and failure events.


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Email Notifications

How does ATA know where to send this notification email to? Is this a configurable field?

Thanks!


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.