Microsoft ATA - Second Entry in ATA for Domain Controller (IP only)? Causing Malicious Replication of DS Alerts

JT 1 Reputation point
2021-06-01T15:59:22.14+00:00

Hello,

We have seen this issue a few times lately where ATA has two entries for our domain controller - one by hostname with correct data in terms of logging, etc, and a second entry with the IP for said domain controller. This results in the false positives shown below. Other than reinstalling the ATA connector, is there anything we can do?

Thanks.

101418-image.png

Microsoft Configuration Manager
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Eli Ofek (MSFT) 911 Reputation points Microsoft Employee
    2021-06-02T07:37:52.34+00:00

    Hi,

    No need to reinstall. This is happening because you have issues resolving this domain controller IP address.
    You need to find out why the Gateway is failing to resolve the IP to a name correctly, probably required ports are not open .
    Once you fix it and delete this alert, it should not alert any more.

    See
    https://learn.microsoft.com/en-us/advanced-threat-analytics/ata-prerequisites#ports

    0 comments No comments