Microsoft Defender for Identity
Identity protection

Integrate VPN with Microsoft Defender for Identity

In brief

The guide now requires at least one connected, healthy Defender for Identity sensor version 2.x to receive RADIUS accounting events. It also reiterates that FIPS environments aren't supported and updates Microsoft Defender terminology and navigation.

What Defender admins need to know

Verify a healthy version 2.x sensor is connected before configuring VPN integration, and ensure the environment doesn't use FIPS.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Defender for Identity VPN integration in Microsoft Defender XDR

Microsoft Defender for Identity can integrate with your VPN solution by listening to RADIUS accounting events forwarded to Defender for Identity sensors, such as the IP addresses and locations where connections originated. VPN accounting data can help your investigations by providing more information about user activity, such as the locations from where computers are connecting to the network, and an extra detection for abnormal VPN connections.

Defender for Identity's VPN integration is based on standard RADIUS Accounting (RFC 2866), and supports the following VPN vendors:

  • Microsoft
  • Check Point
  • Cisco ASA

VPN integration is not supported in environments adhering to Federal Information Processing Standards (FIPS)

Defender for Identity's VPN integration supports both primary UPNs and alternate user principal names. Calls to resolve external IP addresses to a location are anonymous and no personal identifier is sent in the call.

Prerequisites

Before you start, make sure that you have:

  • Microsoft Defender for Identity deployed

  • At least one connected and healthy Defender for Identity sensor version 2.x to receive RADIUS accounting events.

  • Access to the Settings area in Microsoft Defender XDR.Defender. For more information, see Microsoft Defender for Identity role groups.

  • The ability to configure RADIUS on your VPN system.

    The following procedure provides an example of how to configure Microsoft Defender for Identity to collect accounting information from VPN solutions, using Microsoft Routing and Remote Access Server (RRAS). If you're using a third-party VPN solution, consult their documentation for instructions on how to enable RADIUS Accounting.

Configure RADIUS accounting on your VPN system

This procedure describes how to configure RADIUS accounting on an RRAS server for integrating a VPN system with Defender for Identity. Your system's instructions may differ.

On your RRAS server:

  1. Open the Routing and Remote Access console.

  2. Right-click the server name and select Properties.

  3. In the Security tab, under Accounting provider, select RADIUS Accounting > Configure. For example:

    Screenshot of the Security tab showing RADIUS Accounting selected as the accounting provider.

  4. In the Add RADIUS Server dialog, enter the Server name of the closest Defender for Identity sensor with network connectivity. For high availability, you can add additional Defender for Identity sensors as RADIUS accounting servers in RRAS.

  5. Under Port, make sure the default value of 1813 is configured.

  6. Select Change and enter a new shared secret string of alphanumeric characters. Take note of the new shared secret string, as you'll need it later when configuring the VPN integration in Defender for Identity.

  7. Check the Send RADIUS Account On and Accounting Off messages box and select OK on all open dialog boxes. For example:

    Screenshot of RRAS accounting settings showing the Send RADIUS Account On and Accounting Off messages option enabled.

Configure VPN in Defender for Identity

This procedure describes how to configure Defender for Identity's VPN integration in Microsoft Defender XDR.

  1. Sign into Microsoft Defender XDR

    Configure RADIUS accounting on your VPN system

    This procedure describes how to configure RADIUS accounting on an RRAS server for integrating a VPN system with Defender for Identity. Your system's instructions may differ.

    On your RRAS server

    1. Open the Routing and Remote Access console.

    2. Right-click the server name and select Properties.

    3. In the Security tab, under Accounting provider, select RADIUS Accounting > Configure. For example:

      :::image type="content" source="media/radius-setup.png" alt-text="Screenshot of the Security tab showing RADIUS Accounting selected as the accounting provider.":::

    4. In the Add RADIUS Server dialog, enter the Server name of the closest Defender for Identity sensor with network connectivity. For high availability, you can add additional Defender for Identity sensors as RADIUS accounting servers in RRAS.

    5. Under Port, make sure the default value of 1813 is configured.

    6. Select Change and enter a new shared secret string of alphanumeric characters. Take note of the new shared secret string. You'll enter it in the Shared Secret field in the Defender for Identity VPN integration settings.

    7. Check the Send RADIUS Account On and Accounting Off messages box and select OK on all open dialog boxes. For example:

      :::image type="content" source="media/vpn-set-accounting.png" alt-text="Screenshot of RRAS accounting settings showing the Send RADIUS Account On and Accounting Off messages option enabled.":::

    Configure VPN in Defender for Identity

    This procedure describes how to configure Defender for Identity's VPN integration in Microsoft Defender.

    1. Sign into Microsoft Defender and select Settings > Identities > VPN.

    2. Select Enable radius accounting and enter the Shared Secret you'd previously configured on your RRAS VPN server. For example:

      Screenshot of VPN integration settings with Enable radius accounting selected and Shared Secret field populated.:::image type="content" source="media/vpn-integration.png" alt-text="Screenshot of VPN integration settings with Enable radius accounting selected and Shared Secret field populated.":::

    3. Select Save to continue.

    Related content

    For more information, see Listen for SIEM events on your Defender for Identity standalone sensor.