Where to install Defender for Identity Sensor for VPN Integration

David Agosta 0 Reputation points
2024-08-19T18:40:56.1966667+00:00

We have followed the steps in this document https://learn.microsoft.com/en-us/defender-for-identity/vpn-integration to setup VPN Integration for Defender for Identity. However we don't see the sensor receiving any data.

As per the document we have added a server with the Defender for Identity sensor installed on it to the RADIUS Accounting server list on the VPN server. This server was given the same priority as the NPS server that was already in that list.

However when we used Wireshark on the server with the sensor we see no RADIUS Accounting traffic being .

I'm wondering if all servers in the RADIUS Accounting list receive the accounting data? If not then I assume the sensor must be installed on the NPS server for Defender for Identity VPN Integration to work?

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
201 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. K-Mohammed 235 Reputation points Microsoft Employee
    2024-09-17T12:52:24.5133333+00:00

    Hi David, thanks for posting your question!

    Based on my research, it seems that the RADIUS client sends accounting messages only to the first server in the list. Could you maybe be try changing the accounting providers list on the RRAS to prioritize MDI’s sensor first and NPS second, if it’s not already set up that way?

    Hope this helps!

    0 comments No comments

  2. K-Mohammed 235 Reputation points Microsoft Employee
    2024-09-17T12:54:39.21+00:00

    Hi David, thanks for posting your question!

    Based on my research, it seems that the RADIUS client sends accounting messages only to the first server in the list. Could you maybe be try changing the accounting providers list on the RRAS to prioritize MDI’s sensor first and NPS second, if it’s not already set up that way?

    Hope this helps! 

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.