https://docs.microsoft.com/en-us/azure-advanced-threat-protection/atp-prerequisites

How to Configure Azure Advance Threat Protection – ATP

Sharing is caring!

&NewLine;<p><br>Azure ATP monitors your domain controllers by capturing and parsing network traffic and leveraging Windows events directly from your domain controllers&comma; then analyzes the data for attacks and threats&period; Utilizing profiling&comma; deterministic detection&comma; machine learning&comma; and behavioral algorithms Azure ATP learns about your network&comma; enables detection of anomalies&comma; and warns you of suspicious activities&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><img src&equals;"http&colon;&sol;&sol;www&period;thecloudxperts&period;co&period;uk&sol;wp-content&sol;uploads&sol;2018&sol;10&sol;atp-architecture-topology&period;png" alt&equals;"" class&equals;"wp-image-310"&sol;><figcaption>atp-architecture-topology<&sol;figcaption><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>The Azure ATP sensor supports installation on a domain controller running Windows Server 2008 R2 SP1 &lpar;not including Server Core&rpar;&comma; Windows Server 2012&comma; Windows Server 2012 R2&comma; Windows Server 2016 &lpar;including Core but not Nano&rpar;&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p>The domain controller can be a read-only domain controller &lpar;RODC&rpar;&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p>For your domain controllers to communicate with the cloud service&comma; you must open port 443 in your firewalls and proxies to &ast;&period;atp&period;azure&period;com&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p style&equals;"font-size&colon;14px" class&equals;"has-text-color has-background has-very-light-gray-color has-vivid-red-background-color">During installation&comma; the &period;Net Framework 4&period;7 is installed and might require a reboot of the domain controller&comma; if a restart is already pending&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p>The Azure ATP sensor monitors the local traffic on all of the domain controller&&num;8217&semi;s network adapters&period;&nbsp&semi;<br>After deployment&comma; you can use the Azure ATP workspace portal if you want to modify which network adapters are monitored&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p class&equals;"has-text-color has-background has-very-light-gray-color has-vivid-red-background-color">The sensor is not supported on domain controllers running Windows 2008 R2 with Broadcom Network Adapter Teaming enabled&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<h2 class&equals;"wp-block-heading"><br>Azure ATP Components<&sol;h2>&NewLine;&NewLine;&NewLine;&NewLine;<ul class&equals;"wp-block-list"><li><strong class&equals;"">Azure ATP portal<&sol;strong>&nbsp&semi;<br>The Azure ATP portal allows you to create your Azure ATP instance&comma; displays the data received from Azure ATP sensors and enables you to monitor&comma; manage&comma; and investigate threats in your network environment&period;<&sol;li><li><strong>Azure ATP sensor<&sol;strong><br>Azure ATP sensors are installed directly on your domain controllers&period; The sensor directly monitors domain controller traffic&comma; without the need for a dedicated server&comma; or configuration of port mirroring&period;<&sol;li><li><strong>Azure ATP cloud service<&sol;strong><br>Azure ATP cloud service runs on Azure infrastructure and is currently deployed in the US&comma; Europe&comma; and Asia&period; Azure ATP cloud service is connected to Microsoft&&num;8217&semi;s intelligent security graph&period;<&sol;li><&sol;ul>&NewLine;&NewLine;&NewLine;&NewLine;<p>Try selecting and removing or editing the caption&comma; now you don’t have to be careful about selecting the image or other text by mistake and ruining the presentation&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<h2 class&equals;"wp-block-heading">Deployment Options <&sol;h2>&NewLine;&NewLine;&NewLine;&NewLine;<p>There are two Azure advanced threat protection deployment options&comma; that is&comma; you have two methods to collect logs from <g class&equals;"gr&lowbar; gr&lowbar;6 gr-alert gr&lowbar;gramm gr&lowbar;inline&lowbar;cards gr&lowbar;run&lowbar;anim Grammar multiReplace" id&equals;"6" data-gr-id&equals;"6">a domain controllers<&sol;g>&colon;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<ul class&equals;"wp-block-list"><li>Download an agent &lpar;<strong>Azure ATP sensor<&sol;strong>&rpar; on each domain controller in your environment&comma; and that agent will send data directly to the cloud service&period;<&sol;li><&sol;ul>&NewLine;&NewLine;&NewLine;&NewLine;<ul class&equals;"wp-block-list"><li>Configure a server &lpar;<strong>Azure standalone sensor<&sol;strong>&rpar;&comma; that receives a copy of all traffic sent to domain controllers via port mirroring&period;<&sol;li><&sol;ul>&NewLine;&NewLine;&NewLine;&NewLine;<h2 class&equals;"wp-block-heading"><br>ATP Deployment <&sol;h2>&NewLine;&NewLine;&NewLine;&NewLine;<pre class&equals;"wp-block-preformatted">Once you have decided your option &comma; You need to take following steps to deploy Azure Advance Threat Protection<&sol;pre>&NewLine;&NewLine;&NewLine;&NewLine;<ul class&equals;"wp-block-list"><li><strong>Create an Azure ATP workplace&period;<&sol;strong>  &colon; To successfully login to the Azure ATP portal&comma; you have to log in with a user assigned to an Azure Active Directory security group with access to the Azure ATP portal&period; <br>You can enter the Azure ATP portal either by logging in to the portal <a href&equals;"https&colon;&sol;&sol;portal&period;atp&period;azure&period;com&sol;">https&colon;&sol;&sol;portal&period;atp&period;azure&period;com<&sol;a> and selecting the relevant <g class&equals;"gr&lowbar; gr&lowbar;103 gr-alert gr&lowbar;gramm gr&lowbar;inline&lowbar;cards gr&lowbar;disable&lowbar;anim&lowbar;appear Punctuation only-del replaceWithoutSep" id&equals;"103" data-gr-id&equals;"103">workspace&comma;<&sol;g> or browsing to the workspace URL&colon; <a href&equals;"https&colon;&sol;&sol;&ast;workspacename&ast;&period;atp&period;azure&period;com&sol;" target&equals;"&lowbar;blank" rel&equals;"noreferrer noopener">https&colon;&sol;&sol;<&sol;a><em><a href&equals;"https&colon;&sol;&sol;&ast;workspacename&ast;&period;atp&period;azure&period;com&sol;" target&equals;"&lowbar;blank" rel&equals;"noreferrer noopener">workspacename<&sol;a><&sol;em><a href&equals;"https&colon;&sol;&sol;&ast;workspacename&ast;&period;atp&period;azure&period;com&sol;" target&equals;"&lowbar;blank" rel&equals;"noreferrer noopener">&period;atp&period;azure&period;com<&sol;a>&period;<&sol;li><li><strong>Install Azure ATP sensor&period; &colon; <&sol;strong>After downloading the package&comma; go to your Azure ATP standalone sensor server&comma; that is configured with port mirroring to capture domain controller’s traffic and run the installation&period; The installation will immediately detect that this server is not a domain controller&comma; and will try to install Azure ATP standalone sensor server&comma; and not the Azure ATP sensor<&sol;li><li><strong>VPN Integration&period; &colon;<&sol;strong> Azure Advanced Threat Protection &lpar;ATP&rpar; can collect accounting information from VPN solutions&period; When configured&comma; the user&&num;8217&semi;s profile page includes information from the VPN connections&comma; such as the IP addresses and locations where connections originated&period; This complements the investigation process by providing additional information on user activity as well as a new detection for abnormal VPN connections&period; The call to resolve an external IP address to a location is anonymous&period; No personal identifier is sent in this call&period; <br>Azure ATP integrates with your VPN solution by listening to RADIUS accounting events forwarded to the Azure ATP sensors&period;<&sol;li><li>Configure <g class&equals;"gr&lowbar; gr&lowbar;393 gr-alert gr&lowbar;spell gr&lowbar;inline&lowbar;cards gr&lowbar;disable&lowbar;anim&lowbar;appear ContextualSpelling ins-del multiReplace" id&equals;"393" data-gr-id&equals;"393">Honytokens<&sol;g>&comma; Honeytoken accounts are dummy accounts that you create with a name that attract hackers to attack first&period;<&sol;li><li>Configure exclusions&comma; browse to the <a href&equals;"https&colon;&sol;&sol;docs&period;microsoft&period;com&sol;en-us&sol;azure-advanced-threat-protection&sol;install-atp-step7" target&equals;"&lowbar;blank" rel&equals;"noreferrer noopener"><strong>Exclusions<&sol;strong><&sol;a> section in the Azure ATP management portal&period;<&sol;li><li>Configure Sensitive Accounts by automatic or manual tagging <&sol;li><li>One of the most important parts during your Azure advanced threat protection deployment is to configure event forwarding&period; If the sensor is installed directly on the DC&comma; then nothing to worry about&comma; but if you are using Azure ATP sensor standalone&comma; then remember that you need to send <a href&equals;"https&colon;&sol;&sol;docs&period;microsoft&period;com&sol;en-us&sol;azure-advanced-threat-protection&sol;configure-event-collection" target&equals;"&lowbar;blank" rel&equals;"noreferrer noopener">some Windows Events<&sol;a> from your DC to your Azure ATP sensor standalone server using either Windows Event Forwarding or via SIEM integration&period;<&sol;li><li>Configure your proxy server manually using a registry-based static proxy&comma; to allow Azure ATP sensor to report diagnostic data and communicate with Azure ATP cloud service when a computer is not permitted to connect to the Internet&period;<&sol;li><li>If a proxy or firewall is blocking all traffic by default and allowing only specific domains through or HTTPS scanning &lpar;SSL inspection&rpar; is enabled&comma; make sure that the following URLs are white-listed to permit communication with the Azure ATP service in port 443&colon;<&sol;li><&sol;ul>&NewLine;&NewLine;&NewLine;&NewLine;<table class&equals;"wp-block-table"><thead><tr><th>Service location<&sol;th><th>&period;Atp&period;Azure&period;com DNS record<&sol;th><&sol;tr><&sol;thead><tbody><tr><td>US<&sol;td><td>triprd1wcusw1sensorapi&period;atp&period;azure&period;com<br>triprd1wcuswb1sensorapi&period;atp&period;azure&period;com<br>triprd1wcuse1sensorapi&period;atp&period;azure&period;com<&sol;td><&sol;tr><tr><td>Europe<&sol;td><td>triprd1wceun1sensorapi&period;atp&period;azure&period;com<br>triprd1wceuw1sensorapi&period;atp&period;azure&period;com<&sol;td><&sol;tr><tr><td>Asia<&sol;td><td>triprd1wcasse1sensorapi&period;atp&period;azure&period;com<&sol;td><&sol;tr><&sol;tbody><&sol;table>&NewLine;&NewLine;&NewLine;&NewLine;<h2 class&equals;"wp-block-heading"><br>Integrate Azure ATP with Windows Defender ATP<&sol;h2>&NewLine;&NewLine;&NewLine;&NewLine;<p>Azure Advanced Threat Protection enables you to integrate Azure ATP with Windows Defender ATP&comma; for an even more complete threat protection solution&period; While Azure ATP monitors the traffic on your domain controllers&comma; Windows Defender ATP monitors your endpoints&comma; together providing a single interface from which you can protect your environment&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<ol class&equals;"wp-block-list"><li>Click <strong>Configuration<&sol;strong>&comma; and under <strong>Data sources<&sol;strong> select <strong>Windows Defender ATP<&sol;strong>&period; Then click the link to <strong>Workspace management<&sol;strong>&period; This is only available if you have a license for Windows Defender ATP and you already performed the on-boarding process for Windows Defender ATP&period; Turn the integration On<&sol;li><li>In the <a href&equals;"https&colon;&sol;&sol;securitycenter&period;windows&period;com&sol;preferences&sol;advanced">Windows Defender ATP portal<&sol;a>&comma; go to <strong>Settings<&sol;strong>&comma; <strong>Advanced features<&sol;strong> and set <strong>Azure ATP integration<&sol;strong> to <strong>ON<&sol;strong>&period;<&sol;li><&sol;ol>&NewLine;&NewLine;&NewLine;&NewLine;<p><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><img src&equals;"http&colon;&sol;&sol;www&period;thecloudxperts&period;co&period;uk&sol;wp-content&sol;uploads&sol;2018&sol;10&sol;image&period;png" alt&equals;"" class&equals;"wp-image-315"&sol;><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p><br><br><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<h2 class&equals;"wp-block-heading" id&equals;"types-of-azure-atp-security-groups">Types of Azure ATP security groups<&sol;h2>&NewLine;&NewLine;&NewLine;&NewLine;<p>Azure ATP provides three types of security groups&colon;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<ul class&equals;"wp-block-list"><li>Azure ATP&nbsp&semi;<em>&lpar;workspace name&rpar;<&sol;em>&nbsp&semi;Administrators<&sol;li><li>Azure ATP&nbsp&semi;<em>&lpar;workspace name&rpar;<&sol;em>&nbsp&semi;Users<&sol;li><li>Azure ATP&nbsp&semi;<em>&lpar;workspace name&rpar;<&sol;em>&nbsp&semi;Viewers&period;<br><&sol;li><&sol;ul>&NewLine;&NewLine;&NewLine;&NewLine;<p><&sol;p>&NewLine;

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.