Forum Discussion
Philpen
Nov 07, 2024Copper Contributor
Support for LDAPS Auth events in XDR IdentityLogonEvents table?
We have a requirement to implement LDAPS auth for an appliance against AD DCs in a legacy environment. The DCs are running Defender for Identity.
While testing, using LDAP, I can trace login events in the IdentityLoginEvents table, however when switching to LDAPS, I can't see any related events logged here.
Interactive logins using LDAPS are working successfully, as expected, and appear in the Windows event log as EventID:4776 on the DC (but don't appear in the defender portal).
It was then that I discovered that this expected behaviour according to the list of supported logon types listed here.
IdentityLogonEvents table in the advanced hunting schema - Microsoft Defender XDR | Microsoft Learn
I'm puzzled that XDR would support a cleartext legacy authentication method like LDAP, but would not support the more secure LDAPS protocol.
Is there any rationale for this, or intention to introduce support ?
No RepliesBe the first to reply