Defender for Endpoint Users Not in MCAS

Sam C 46 Reputation points


We've onboarded 15 users into Defender for Endpoint. Now that we've got the Sentinel Connector turned on to get the raw logs, we can see these machines/users reporting in. However, only 10 of these users show in the MCAS Cloud Discovery Dashboard. Trying to iron out this process before we push it out to more in the organization, any idea where machines might be dropping off? Does MCAS have some sort of user filtering that I don't know about? Thanks!

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
666 questions
{count} votes