netwrix / pingcastle

PingCastle - Get Active Directory Security at 80% in 20% of the time
https://www.pingcastle.com
Other
2.35k stars 292 forks source link

AZUREADSSOACC reported in multiple issues #186

Open RobinMJD opened 1 year ago

RobinMJD commented 1 year ago

Hello, Is it normal to have the AZUREADSSOACC account reported in the following issues or are these false positives? S-DC-NotUpdated (Domain controller update) S-DCRegistration (Check if all DC are well registered) S-DC-Inactive (Check if all DC are active)

This AD object is created by Azure AD Connect and used for Azure Active Directory Seamless Single Sign-On.

Thanks in advance.

An-dir commented 1 year ago

Hi @RobinMJD, Could you figure out what Problem you had? Did you use at least Version 3.0.0.4? I can't reproduce your problem. AZUREADSSOACC doesn't make false positives for me. Does your AD object have:

testman57 commented 1 year ago

Hello, I do happen to have the exact same case here.

In addition, there does not seem to be a special GUID in the CN and it seems to be related to Azure Active Directory Seamless Single Sign-On

The object is matching the S-DCRegistration (Check if all DC are well registered) and S-DC-Inactive (Check if all DC are active) rules only (not the Domain Controller Update)

It would help greatly if it could be correctly excluded from the checks !

Thanks for your attention,

An-dir commented 8 months ago

Why do you have it in the "Domain Controllers" OU? This is the reason for the "false positives"

testman57 commented 3 months ago

Hi, Indeed we moved it away from this OU, and now it is much better! Thanks!