SOLVED

Auditing of AD FS events

%3CLINGO-SUB%20id%3D%22lingo-sub-2048443%22%20slang%3D%22en-US%22%3EAuditing%20of%20AD%20FS%20events%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2048443%22%20slang%3D%22en-US%22%3E%3CP%3EI've%20tried%20to%20install%20the%20newest%20MDI%20sensor%20on%20one%20of%20my%20AD%20FS%20servers%20but%20under%20the%20installation%20if%20reports%20that%20auditing%20is%20not%20configured%20correctly%20-%20see%20attached%20image.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt's%20possible%20to%20click%20Next%20and%20proceed%20with%20the%20installation.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI've%20verified%20that%20the%20auditing%20is%20in%20place%20and%20configured%20according%20to%20the%20guide.%20I%20can%20even%20see%20the%20audit%20events%20in%20the%20security%20log.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20am%20I%20missing%20here%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EJust%20for%20your%20information%2C%20then%20the%20service%20wont%20start%20after%20the%20installation%20-%20I'll%20start%20another%20discussion%20about%20that%20issue%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2048443%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3Eadfs%20mdi%20sensor%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2048507%22%20slang%3D%22en-US%22%3ERe%3A%20Auditing%20of%20AD%20FS%20events%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2048507%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F205276%22%20target%3D%22_blank%22%3E%40Bjarne%20Abraham%3C%2FA%3E%26nbsp%3B%3CBR%20%2F%3ECan%26nbsp%3B%20you%20run%20on%20this%20machine%20from%20powershell%20this%20command%20and%20share%20the%20full%20output%3F%3C%2FP%3E%0A%3CPRE%3E%3CSPAN%3E(Get-AdfsProperties).LogLevel%3C%2FSPAN%3E%0A%3C%2FPRE%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2055927%22%20slang%3D%22en-US%22%3ERe%3A%20Auditing%20of%20AD%20FS%20events%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2055927%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F205276%22%20target%3D%22_blank%22%3E%40Bjarne%20Abraham%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EHi%2C%3C%2FP%3E%0A%3CP%3EJust%20got%20another%20similar%20case%2C%26nbsp%3B%20that%20was%20resolved%20by%20running%20the%20setup%20elevated.%3C%2FP%3E%0A%3CP%3ECan%20you%20try%20that%20and%20let%20me%20know%20if%20the%20warning%20is%20gone%20%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2078210%22%20slang%3D%22en-US%22%3ERe%3A%20Auditing%20of%20AD%20FS%20events%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2078210%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F106935%22%20target%3D%22_blank%22%3E%40Eli%20Ofek%3C%2FA%3E%26nbsp%3Brunning%20the%20installation%20elevated%20solved%20the%20issue.%20Then%20it%20doesn't%20raise%20an%20alert%20about%20issue%20regarding%20auditing%20on%20the%20ADFS%20server.%20Thanks.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2078355%22%20slang%3D%22en-US%22%3ERe%3A%20Auditing%20of%20AD%20FS%20events%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2078355%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F205276%22%20target%3D%22_blank%22%3E%40Bjarne%20Abraham%3C%2FA%3E%26nbsp%3BIt%20was%20a%20success%20on%20one%20of%20the%20AD%20FS%20servers%20but%20not%20on%20the%20others%20%3A(%3C%2Fimg%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI've%20checked%20the%20audit%20level%20and%20requirements%20and%20they%20are%20exact%20the%20same.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20good%20ideas%3F%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

I've tried to install the newest MDI sensor on one of my AD FS servers but under the installation if reports that auditing is not configured correctly - see attached image.

 

It's possible to click Next and proceed with the installation.

 

I've verified that the auditing is in place and configured according to the guide. I can even see the audit events in the security log.

 

What am I missing here?

 

Just for your information, then the service wont start after the installation - I'll start another discussion about that issue :)

12 Replies

@Bjarne Abraham 
Can  you run on this machine from powershell this command and share the full output?

(Get-AdfsProperties).LogLevel

 

best response confirmed by Bjarne Abraham (Occasional Contributor)
Solution

@Bjarne Abraham 

Hi,

Just got another similar case,  that was resolved by running the setup elevated.

Can you try that and let me know if the warning is gone ?

@Eli Ofek running the installation elevated solved the issue. Then it doesn't raise an alert about issue regarding auditing on the ADFS server. Thanks.

@Bjarne Abraham It was a success on one of the AD FS servers but not on the others :(

 

I've checked the audit level and requirements and they are exact the same.

 

Any good ideas? :)

@Bjarne Abraham 
Can you share the output of

(Get-AdfsProperties).LogLevel

from the working and non working server? 

PS C:\Windows\system32> (Get-AdfsProperties).LogLevel
Errors
FailureAudits
Information
Verbose
SuccessAudits
Warnings

It's only possible to execute the command on the primary AD FS node as it's a farm setting.

@Bjarne Abraham 

In this case the non working machine is not a primary ?

Can you share the output of this command when running on the non primary machine (even if it returns an error) ?

PS C:\Windows\system32> (Get-AdfsProperties).LogLevel
Get-AdfsProperties : PS0033: This cmdlet cannot be executed from a secondary server in a local database farm. The prim
ary server is presently: server.domain.tld. To execute management cmdlets, either log onto the primary server or conn
ect using PowerShell remoting. For more information see http://go.microsoft.com/fwlink/?LinkId=294129.
At line:1 char:2
+ (Get-AdfsProperties).LogLevel
+ ~~~~~~~~~~~~~~~~~~
+ CategoryInfo : OpenError: (:) [Get-AdfsProperties], InvalidOperationException
+ FullyQualifiedErrorId : PS0033,Microsoft.IdentityServer.Management.Commands.GetServicePropertiesCommand

@Bjarne Abraham 
Thanks! I will open a bug for it.

You can ignore the warning during setup for now, it will work fine.

Great, hereby installed and working :)

@Eli Ofek FYI running setup elevated solved the issue for us too.

Would be nice to either see docs updated or the install file changed.

@RNalivaika 

The docs actually says that already:

https://docs.microsoft.com/en-us/defender-for-identity/install-step4

 

"Run Azure ATP sensor setup.exe with elevated privileges (Run as administrator) and follow the setup wizard."

 

As for changing the exe to auto prompt a UAC dialog, there is currently a technical limitation preventing us from doing so due to the installer infra we use that intentionally block it, but we are working on it to work like that. it will take some time though, as it is going to be incorporated with some other features that will make the deployment a breeze. stay tuned on this topic.... 

www.000webhost.com