Forum Discussion

Philpen's avatar
Philpen
Copper Contributor
Nov 07, 2024

Support for LDAPS Auth events in XDR IdentityLogonEvents table?

We have a requirement to implement LDAPS auth for an appliance against AD DCs in a legacy environment.   The DCs are running Defender for Identity.

While testing, using LDAP, I can trace login events in the IdentityLoginEvents table, however when switching to LDAPS, I can't see any related events logged here.

Interactive logins using LDAPS are working successfully, as expected, and appear in the Windows event log as EventID:4776 on the DC (but don't appear in the defender portal). 

 

It was then that I discovered that this expected behaviour according to the list of supported logon types listed here.

IdentityLogonEvents table in the advanced hunting schema - Microsoft Defender XDR | Microsoft Learn

I'm puzzled that XDR would support a cleartext legacy authentication method like LDAP, but would not support the more secure LDAPS protocol.

Is there any rationale for this, or intention to introduce support ?

 

 

No RepliesBe the first to reply

Resources