<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Controller and Microsoft Defender for Identity in parallel? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Controller-and-Microsoft-Defender-for-Identity-in/m-p/153740#M25869</link>
    <description>&lt;P&gt;Looks like both are using 4624, at least according to the list you provided.&lt;BR /&gt;I think you listed the two possible solutions to this issue, unless&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;can suggest something else.&lt;/P&gt;</description>
    <pubDate>Mon, 25 Jul 2022 10:47:23 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2022-07-25T10:47:23Z</dc:date>
    <item>
      <title>Identity Controller and Microsoft Defender for Identity in parallel?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Controller-and-Microsoft-Defender-for-Identity-in/m-p/153732#M25862</link>
      <description>&lt;P&gt;Hello Checkmates,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;just a question which came to my mind.&lt;BR /&gt;i heard a costumer had issues running IDC &amp;amp;&amp;nbsp;Microsoft Defender for Identity in parallel on the same domain controllers.&lt;BR /&gt;the IDC has no longer received any events from the Domain Controllers and stopped working.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;i have seen similar symptoms when people try to forward the security events to other SIEM solutions, and the IDC got cut off from the events, or when people harden the AD and make it perhaps to hard for the IDC to collect the proper event ID´s&lt;BR /&gt;&lt;BR /&gt;so question to the audience, what would you do when you are running is such situations?&lt;/P&gt;
&lt;P&gt;+ forward the logs to a dedicated server and collect the event ID´s from this machine?&lt;BR /&gt;(causing perhaps some latency)&lt;/P&gt;
&lt;P&gt;+ better move to IA Agents anyhow&lt;BR /&gt;(the IT staff will be happy to support just another agent on all clients)&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Important to know,&lt;BR /&gt;Microsoft Defender for Identity starts with this Event ID´s&lt;BR /&gt;&lt;A href="https://docs.microsoft.com/en-us/defender-for-identity/configure-windows-event-collection" target="_blank"&gt;https://docs.microsoft.com/en-us/defender-for-identity/configure-windows-event-collection&lt;/A&gt;&lt;/P&gt;
&lt;H2 id="relevant-windows-events" class="heading-anchor"&gt;Relevant Windows Events&lt;/H2&gt;
&lt;H3 id="for-active-directory-federation-services-ad-fs-events" class="heading-anchor"&gt;For Active Directory Federation Services (AD FS) events&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;1202 - The Federation Service validated a new credential&lt;/LI&gt;
&lt;LI&gt;1203 - The Federation Service failed to validate a new credential&lt;/LI&gt;
&lt;LI&gt;4624 - An account was successfully logged on&lt;/LI&gt;
&lt;LI&gt;4625 - An account failed to log on&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3 id="for-other-events" class="heading-anchor"&gt;For other events&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;1644 - LDAP search&lt;/LI&gt;
&lt;LI&gt;4662 - An operation was performed on an object&lt;/LI&gt;
&lt;LI&gt;4726 - User Account Deleted&lt;/LI&gt;
&lt;LI&gt;4728 - Member Added to Global Security Group&lt;/LI&gt;
&lt;LI&gt;4729 - Member Removed from Global Security Group&lt;/LI&gt;
&lt;LI&gt;4730 - Global Security Group Deleted&lt;/LI&gt;
&lt;LI&gt;4732 - Member Added to Local Security Group&lt;/LI&gt;
&lt;LI&gt;4733 - Member Removed from Local Security Group&lt;/LI&gt;
&lt;LI&gt;4741 - Computer Account Added&lt;/LI&gt;
&lt;LI&gt;4743 - Computer Account Deleted&lt;/LI&gt;
&lt;LI&gt;4753 - Global Distribution Group Deleted&lt;/LI&gt;
&lt;LI&gt;4756 - Member Added to Universal Security Group&lt;/LI&gt;
&lt;LI&gt;4757 - Member Removed from Universal Security Group&lt;/LI&gt;
&lt;LI&gt;4758 - Universal Security Group Deleted&lt;/LI&gt;
&lt;LI&gt;4763 - Universal Distribution Group Deleted&lt;/LI&gt;
&lt;LI&gt;4776 - Domain Controller Attempted to Validate Credentials for an Account (NTLM)&lt;/LI&gt;
&lt;LI&gt;7045 - New Service Installed&lt;/LI&gt;
&lt;LI&gt;8004 - NTLM Authentication&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;but the IDC uses only:&lt;BR /&gt;&lt;BR /&gt;Windows 2003 servers: 672, 673, 674&lt;BR /&gt;Windows 2008 servers: 4624, 4768, 4769, 4770&lt;BR /&gt;Windows 2012 servers: 4624, 4768, 4769, 4770&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i see no overlapp in here?&lt;/P&gt;
&lt;P&gt;best regards&lt;BR /&gt;Thomas&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 09:43:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Controller-and-Microsoft-Defender-for-Identity-in/m-p/153732#M25862</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2022-07-25T09:43:34Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Controller and Microsoft Defender for Identity in parallel?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Controller-and-Microsoft-Defender-for-Identity-in/m-p/153740#M25869</link>
      <description>&lt;P&gt;Looks like both are using 4624, at least according to the list you provided.&lt;BR /&gt;I think you listed the two possible solutions to this issue, unless&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;can suggest something else.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 10:47:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Controller-and-Microsoft-Defender-for-Identity-in/m-p/153740#M25869</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-07-25T10:47:23Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Controller and Microsoft Defender for Identity in parallel?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Controller-and-Microsoft-Defender-for-Identity-in/m-p/153741#M25870</link>
      <description>&lt;P&gt;yes right .... 4624 overlaps ... i should wear glasses ...&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;thank you, i didnt see that...&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 10:50:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Controller-and-Microsoft-Defender-for-Identity-in/m-p/153741#M25870</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2022-07-25T10:50:54Z</dc:date>
    </item>
  </channel>
</rss>

