Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium
A global organization uses Microsoft Defender for Identity to protect its hybrid Active Directory environment. A security analyst frequently observes alerts related to 'Suspicious Kerberos authentication activity' (Event ID 4769) originating from legacy applications that perform legitimate, high-volume Kerberos ticket requests. These alerts are generating significant noise and are not indicative of actual threats. The analyst needs to reduce these false positives without disabling the detection for other critical systems. What is the most appropriate action for the analyst to take in Microsoft Defender for Identity?
- AAdjust the sensitivity threshold for all Kerberos-related detections globally.
- BCreate an exclusion rule for the specific legacy applications or service accounts generating the false positives.
- CDisable the entire 'Suspicious Kerberos authentication activity' detection.
- DConfigure a custom alert suppression rule in Microsoft Defender XDR for all Event ID 4769 alerts.
Show answer & explanationAnswer & explanation
Correct answer: B. Create an exclusion rule for the specific legacy applications or service accounts generating the false positives.
Creating an exclusion rule for specific entities (legacy applications or service accounts) allows the analyst to suppress false positives from legitimate sources while keeping the detection active for other critical systems, thus reducing noise without compromising overall security.
Why the other options are wrong
- A. Adjusting global sensitivity might suppress legitimate threats from other systems or allow more false positives from other sources.
- C. Disabling the entire detection would remove protection for actual threats, which is not desired.
- D. A custom alert suppression rule in Defender XDR would hide the alerts but not prevent the underlying detection and potential performance impact on Defender for Identity sensors. It's a reactive suppression, not a proactive fine-tuning within Defender for Identity itself.
Defender for Identity Exclusion Rules
Configurations within Microsoft Defender for Identity that allow specific entities (users, computers, or groups) to be excluded from certain detections to reduce false positives for legitimate activities.
- Reduces false positives.
- Targets specific entities or activities.
- Maintains detection for other entities.
Memory trick: Don't throw out the baby with the bathwater; exclude the noisy parts, keep the protection.