Share via

false-positive in Microsoft Defender for Identity

Chris W 30 Reputation points
2025-05-22T18:39:42.7666667+00:00

We utilize Entra Connect Sync and have E5 licensing which gives us access to MDE, MDI and various other Defender services. Our Entra Connect Sync has been flagged by the MDI agent installed on it with the following issue:

Remove unnecessary replication permissions for Entra Connect AD DS Connector Account

We utilize Password Hash Sync and Password Writeback in our installation and the MSOL account associated with Entra Connect Sync has been falsely flagged as needing the replication permissions removed in order to clear. In good faith, I attempted the remediation suggested which broke Entra Connect Sync after which I restored the original permissions and still being flagged as needing remediation.

I initially tried Microsoft Support to resolve who stated this issue was out of scope and the case was closed after they suggested opening a ticket via Entra portal which resulted in no ability to open a ticket against it, only suggestions which led me here ultimately. At the time, the link they provided me led to an Azure site which required a personal Microsoft Account to login -- we are a business and do not utilize personal Microsoft Accounts. The Team Lead for Microsoft Support contacted me stating they regret the issue has not been solved but that the issue is out of scope for his team.

I then tried Copilot which helped me troubleshoot the issue and resulted in our Entra Connect Sync MSOL account permissions are correct and provided several PowerShell scripts to validate the permissions and concluded the Secure Score entry was a false-positive based on our configuration. It suggested that we open a case with Microsoft Support (see above) or MRSC. I attempted to open a case with MSRC which was rejected as a non-MSRC case.

Copilot then suggested excluding the MSOL account for the specific rule but I find that's only hiding the issue than resolving it.

How can I get this false-positive to the correct product group to resolve? I have my previous case# from Microsoft Support and all the troubleshooting case notes I did with Copilot. This is bringing our Secure Score down artificially when the problem is a false-positive.

I've literally been running in circles around this and this appears to be my last avenue to try and get this issue raised to the right product team for resolution.

Microsoft Security | Microsoft Defender | Microsoft Defender for Identity
{count} votes

Answer accepted by question author
  1. Catherine Kyalo 2,855 Reputation points Microsoft Employee
    2025-05-26T15:46:52.0266667+00:00

    Hi Chris W,

    I have confirmed that there is an active incident which involves a secure score recommendation for the Microsoft Entra Connect AD DS Connector account, which is incorrectly triggered despite the Password Hash Sync (PHS) being enabled.

    This situation arises due to a conflict when the Entra Connect role is installed on a domain controller rather than a separate server, leading to discrepancies in sensor reporting.

    Investigation is ongoing to determine the root cause and appropriate resolution. I will monitor and update appropriately.

    If you find the answer above helpful, please "Accept the answer" to help anyone in the community who might have a similar question to quickly find the solution.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.