Lateral movement report is empty

Alistair Nelson 21 Reputation points
2021-03-24T13:15:02.89+00:00

My ATA Lateral Movement detection scheduled report is empty. It seems to not have the right permissions.

The group policy "Network access: Restrict clients allowed to make remote calls to SAM" is not configured right now - I understand that is the most lenient setting and should allow ATA in? Port 445 is also allowed.

Microsoft Security Intune Configuration Manager Other
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Abdulrehman Altaf 226 Reputation points
    2021-04-27T13:27:19.317+00:00

    @Alistair Nelson its not a big deal, if there is no lateral movement in your environment you will receive empty email without attachment
    ie Lateral movement paths to sensitive accounts or Cleartext passwords exposed using unencrypted LDAP authentications report etc
    make sure you are part of "Microsoft Advanced Threat Analytics Administrators" group in ATA server
    91754-ata1.png

    to check the report from ATA login at ATALOGINURL/reports and follow the below
    91771-ata2.png

    1 person found this answer helpful.
    0 comments No comments

  2. Eli Ofek (MSFT) 911 Reputation points Microsoft Employee
    2021-03-24T15:56:05.957+00:00
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.