A troubleshooting guide
First things first – I suggest you visit this documentation and read it; it's the currently known issues list for MDI: https://docs.microsoft.com/en-us/defender-for-identity/troubleshooting-known-issues.
Moving along, let's cover some of the known issues that are most common when troubleshooting MDI installations that I've come across. I'd have to ballpark the number of domain controllers I've onboarded to be over 5,000, so I think I've seen most of the wonky issues that will arise.
We'll start with the most common in a bullet-point list, with some information on each:
- The sensor failed to connect to service: If you see this when installing, check for the needed root certificates. This can be done by running the following
Get-ChildItem
cmdlets. It's likely one of them is missing, and if they are, the links to get them are in the URL provided previously for troubleshooting known issues:# Certificate...