Malicious replication of Directory Services- Alert for iPv6

Fahad Noaman 131 Reputation points
2020-11-05T09:00:32.873+00:00

When ever a DC with iPv6 tries to replicate with its partner, it shows as malicious.

which is false positive, how to avoid this.

37658-image.png

Microsoft Configuration Manager
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Eli Ofek (MSFT) 911 Reputation points Microsoft Employee
    2020-11-05T14:13:53.887+00:00

    You need to check why the sensor is failing to resolve this IP address to the machine name (which will allow it to understand this is a DC...)
    Are all the ports open as described in the docs?
    If yes, open a support ticket, as it's tricky to diagnose this over a forum thread...

    0 comments No comments