{"id":13835,"date":"2025-11-18T09:05:47","date_gmt":"2025-11-18T00:05:47","guid":{"rendered":"https:\/\/m365jp.net\/?p=13835"},"modified":"2025-11-18T09:06:40","modified_gmt":"2025-11-18T00:06:40","slug":"mc1187390-unified-sensor-v3-x-new-remote-procedure-call-rpc-configuration-health-alert-for-microsoft-defender-for-identity","status":"publish","type":"post","link":"https:\/\/m365jp.net\/index.php\/2025-11-18-mc1187390-unified-sensor-v3-x-new-remote-procedure-call-rpc-configuration-health-alert-for-microsoft-defender-for-identity","title":{"rendered":"MC1187390 | Unified sensor (v3.x) \u2013 new Remote Procedure Call (RPC) configuration health alert for Microsoft Defender for Identity"},"content":{"rendered":"<div class=\"postie-post\">\n<div>\n<hr>\n<table id=\"section\">\n<tbody>\n<tr>\n<th width=\"95%\">MC1187390 | Unified sensor (v3.x) \u2013 new Remote Procedure Call (RPC) configuration health alert for Microsoft Defender for Identity<\/th>\n<\/tr>\n<\/tbody>\n<\/table>\n<hr>\n<table id=\"data\">\n<tbody>\n<tr>\n<th>Classification<\/th>\n<td>stayInformed<\/td>\n<\/tr>\n<tr>\n<th>Last Updated<\/th>\n<td>11\/17\/2025 23:49:38<\/td>\n<\/tr>\n<tr>\n<th>Start Time<\/th>\n<td>11\/17\/2025 23:49:31<\/td>\n<\/tr>\n<tr>\n<th>End Time<\/th>\n<td>01\/14\/2026 08:00:00<\/td>\n<\/tr>\n<tr>\n<th>Message Content<\/th>\n<td>\n<p><b>[Introduction]<\/b><\/p>\n<p>  We\u2019re introducing a new <b>Remote Procedure Call (RPC) Configuration Health Alert for sensors v3.x<\/b> in Microsoft Defender for Identity. This capability proactively monitors RPC configuration across your environment, helping administrators quickly identify   and remediate misconfigurations that could impact detection accuracy or security posture. Additionally, applying the Unified Sensor RPC Audit tag enables advanced identity detections, improving security visibility and unlocking additional detection capabilities.  <\/p>\n<p><b>[When this will happen:]<\/b><\/p>\n<p>  <b>General availability (Production, GCC, GCCH):<\/b> We will begin rolling out early December 2025 and expect to complete by mid-December 2025.  <\/p>\n<p><b>[How this affects your organization:]<\/b><\/p>\n<p>  <\/p>\n<ul>  <\/p>\n<li><b>Who is affected:<\/b> Admins managing Microsoft Defender for Identity v3.x sensors.<\/li>\n<p>  <\/p>\n<li><b>What will happen:<\/b><br \/> \n<ul>  <\/p>\n<li>A new health alert will monitor RPC configuration status on v3.x sensors.<\/li>\n<p>  <\/p>\n<li>Applying the <b>Unified Sensor RPC Audit tag <\/b>will enforce configuration on existing and future v3.x sensors that match rule criteria.<\/li>\n<p>  <\/p>\n<li>The tag will be visible in <b>Device Inventory <\/b>and<b>&nbsp;Advanced Hunting<\/b>, providing transparency and auditing capabilities.<\/li>\n<p>  <\/p>\n<li>This feature improves detection accuracy and overall security coverage.<\/li>\n<p>  <\/ul>\n<p>  <\/li>\n<p>  <\/ul>\n<p>  <\/p>\n<p><b>[What you can do to prepare:]<\/b><\/p>\n<p>  To apply the <b>RPC Audit tag<\/b> on your v3.x sensors:  <\/p>\n<ol>  <\/p>\n<li>In the Microsoft Defender portal, navigate to: <b>System <\/b>&gt; <b>Settings <\/b>  &gt; <b>Microsoft Defender XDR<\/b> &gt; <b>Asset Rule Management<\/b>.<\/li>\n<p>  <\/p>\n<li>Select <b>Create a new rule<\/b>.<\/li>\n<p>  <\/p>\n<li>Enter a <b>Rule name<\/b> and <b>Description<\/b>, then set conditions using <b>  Device name<\/b>, <b>Domain<\/b>, or <b>Device tag<\/b>. Ensure the Defender for Identity v3.x sensor is deployed on targeted devices.<\/li>\n<p>  <\/p>\n<li>Add the tag <b>Unified Sensor RPC Audit<\/b>.<\/li>\n<p>  <\/p>\n<li>Review and submit the rule.<\/li>\n<p>  <\/ol>\n<p>  For more details, refer to <a href=\"https:\/\/learn.microsoft.com\/defender-for-identity\/\" target=\"_blank\">  Microsoft Defender for Identity documentation<\/a>.  <\/p>\n<p><b>[Compliance considerations:]<\/b><\/p>\n<p>  No compliance considerations identified; review as appropriate for your organization.  <\/p>\n<\/td>\n<\/tr>\n<tr>\n<th>Machine Translation<\/th>\n<td>\n<p><b>[\u306f\u3058\u3081\u306b]<\/b><\/p>\n<p>  Microsoft Defender for Identity\u3067\u3001 <b>\u30bb\u30f3\u30b5\u30fcv3.x\u5411\u3051\u306e\u65b0\u3057\u3044\u30ea\u30e2\u30fc\u30c8\u30d7\u30ed\u30b7\u30fc\u30b8\u30e3\u30ea\u30f3\u30b0\u30b3\u30fc\u30eb(RPC)\u69cb\u6210\u5065\u5eb7\u8b66\u5831<\/b> \u3092\u5c0e\u5165\u3057\u307e\u3059\u3002\u3053\u306e\u6a5f\u80fd\u306f\u74b0\u5883\u5168\u4f53\u3067RPC\u69cb\u6210\u3092\u7a4d\u6975\u7684\u306b\u76e3\u8996\u3057\u3001\u7ba1\u7406\u8005\u304c\u691c\u51fa\u7cbe\u5ea6\u3084\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u4f53\u5236\u306b\u5f71\u97ff\u3092\u4e0e\u3048\u308b\u53ef\u80fd\u6027\u306e\u3042\u308b\u8aa4\u8a2d\u5b9a\u3092\u8fc5\u901f\u306b\u7279\u5b9a\u30fb\u4fee\u6b63\u3059\u308b\u306e\u306b\u5f79\u7acb\u3061\u307e\u3059\u3002\u3055\u3089\u306b\u3001Unified Sensor RPC Audit\u30bf\u30b0\u306e\u9069\u7528\u306b\u3088\u308a\u9ad8\u5ea6\u306a\u30a2\u30a4\u30c7\u30f3\u30c6\u30a3\u30c6\u30a3\u691c\u51fa\u304c\u53ef\u80fd\u3068\u306a\u308a\u3001\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u306e\u53ef\u8996\u6027\u304c\u5411\u4e0a\u3057\u3001\u8ffd\u52a0\u306e\u691c\u51fa\u6a5f\u80fd\u304c\u89e3\u653e\u3055\u308c\u307e\u3059\u3002  <\/p>\n<p><b>[\u3044\u3064\u8d77\u3053\u308b\u304b:]<\/b><\/p>\n<p>  <b>\u4e00\u822c\u5411\u3051\u63d0\u4f9b(\u751f\u7523\u3001GCC\u3001GCCH):<\/b> 2025\u5e7412\u6708\u521d\u65ec\u304b\u3089\u5c55\u958b\u3092\u958b\u59cb\u3057\u30012025\u5e7412\u6708\u4e2d\u65ec\u307e\u3067\u306b\u5b8c\u4e86\u3059\u308b\u4e88\u5b9a\u3067\u3059\u3002  <\/p>\n<p><b>[\u3053\u308c\u304c\u3042\u306a\u305f\u306e\u7d44\u7e54\u306b\u3069\u306e\u3088\u3046\u306a\u5f71\u97ff\u3092\u4e0e\u3048\u308b\u304b:]<\/b><\/p>\n<p>  <\/p>\n<ul>  <\/p>\n<li><b>\u5f71\u97ff\u3092\u53d7\u3051\u308b\u4eba\u7269:<\/b> \u7ba1\u7406\u8005\u304cMicrosoft Defender for Identity v3.x\u30bb\u30f3\u30b5\u30fc\u3092\u7ba1\u7406\u3057\u3066\u3044\u307e\u3059\u3002<\/li>\n<p>  <\/p>\n<li><b>\u4eca\u5f8c\u306e\u5c55\u958b:<\/b><br \/> \n<ul>  <\/p>\n<li>\u65b0\u3057\u3044\u30d8\u30eb\u30b9\u30a2\u30e9\u30fc\u30c8\u306fv3.x\u30bb\u30f3\u30b5\u30fc\u306eRPC\u8a2d\u5b9a\u72b6\u614b\u3092\u76e3\u8996\u3057\u307e\u3059\u3002<\/li>\n<p>  <\/p>\n<li><b>\u7d71\u4e00\u30bb\u30f3\u30b5\u30fcRPC\u76e3\u67fb\u30bf\u30b0<\/b>\u3092\u9069\u7528\u3059\u308b\u3068\u3001\u65e2\u5b58\u304a\u3088\u3073\u5c06\u6765\u306ev3.x\u30bb\u30f3\u30b5\u30fc\u3067\u30eb\u30fc\u30eb\u57fa\u6e96\u306b\u5408\u81f4\u3059\u308b\u8a2d\u5b9a\u3092\u5f37\u5236\u3057\u307e\u3059\u3002<\/li>\n<p>  <\/p>\n<li>\u30bf\u30b0\u306f <b>\u30c7\u30d0\u30a4\u30b9\u30a4\u30f3\u30d9\u30f3\u30c8\u30ea <\/b>\u304a\u3088\u3073<b>&nbsp;Advanced Hunting<\/b>\u3067\u8868\u793a\u3055\u308c\u3001\u900f\u660e\u6027\u3068\u76e3\u67fb\u6a5f\u80fd\u3092\u63d0\u4f9b\u3057\u307e\u3059\u3002<\/li>\n<p>  <\/p>\n<li>\u3053\u306e\u6a5f\u80fd\u306b\u3088\u308a\u3001\u691c\u77e5\u7cbe\u5ea6\u3068\u5168\u4f53\u7684\u306a\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30ab\u30d0\u30ec\u30c3\u30b8\u304c\u5411\u4e0a\u3057\u307e\u3059\u3002<\/li>\n<p>  <\/ul>\n<p>  <\/li>\n<p>  <\/ul>\n<p>  <\/p>\n<p><b>[\u6e96\u5099\u306e\u305f\u3081\u306b\u3067\u304d\u308b\u3053\u3068:]<\/b><\/p>\n<p>  v3.x\u30bb\u30f3\u30b5\u30fc\u306b <b>RPC\u76e3\u67fb\u30bf\u30b0<\/b> \u3092\u9069\u7528\u3059\u308b\u306b\u306f:  <\/p>\n<ol>  <\/p>\n<li>Microsoft Defender\u30dd\u30fc\u30bf\u30eb\u3067\u3001<b>Microsoft Defender XDR<\/b>&gt;<b>System &gt;<\/b><b>\u8a2d\u5b9a<\/b>&gt;<b>Asset Rule Management<\/b>\u3078\u79fb\u52d5\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/li>\n<p>  <\/p>\n<li>\u300c <b>\u65b0\u3057\u3044\u30eb\u30fc\u30eb\u3092\u4f5c\u6210\u3059\u308b<\/b>\u300d\u3092\u9078\u629e\u3057\u307e\u3059\u3002<\/li>\n<p>  <\/p>\n<li><b>\u30eb\u30fc\u30eb\u540d<\/b>\u3068<b>\u8aac\u660e<\/b>\u3092\u5165\u529b\u3057\u3001<b>\u30c7\u30d0\u30a4\u30b9\u540d<\/b>\u3001<b>\u30c9\u30e1\u30a4\u30f3<\/b>\u3001<b>\u307e\u305f\u306f\u30c7\u30d0\u30a4\u30b9\u30bf\u30b0<\/b>\u3092\u4f7f\u3063\u3066\u6761\u4ef6\u3092\u8a2d\u5b9a\u3057\u307e\u3059\u3002Defender for Identity v3.x\u30bb\u30f3\u30b5\u30fc\u304c\u5bfe\u8c61\u30c7\u30d0\u30a4\u30b9\u306b\u78ba\u5b9f\u306b\u8a2d\u7f6e\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/li>\n<p>  <\/p>\n<li>\u300c <b>\u7d71\u4e00\u30bb\u30f3\u30b5\u30fcRPC\u76e3\u67fb<\/b>\u300d\u3068\u3044\u3046\u30bf\u30b0\u3092\u8ffd\u52a0\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/li>\n<p>  <\/p>\n<li>\u30eb\u30fc\u30eb\u3092\u78ba\u8a8d\u3057\u3066\u63d0\u51fa\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/li>\n<p>  <\/ol>\n<p>  \u8a73\u7d30\u306b\u3064\u3044\u3066\u306f\u3001 <a href=\"https:\/\/learn.microsoft.com\/defender-for-identity\/\" target=\"_blank\">  Microsoft Defender for Identity documentation<\/a>\u3092\u3054\u53c2\u7167\u304f\u3060\u3055\u3044\u3002  <\/p>\n<p><b>[\u30b3\u30f3\u30d7\u30e9\u30a4\u30a2\u30f3\u30b9\u4e0a\u306e\u8003\u616e\u4e8b\u9805:]<\/b><\/p>\n<p>  \u30b3\u30f3\u30d7\u30e9\u30a4\u30a2\u30f3\u30b9\u4e0a\u306e\u8003\u616e\u4e8b\u9805\u306f\u7279\u5b9a\u3055\u308c\u307e\u305b\u3093\u3067\u3057\u305f\u3002\u3042\u306a\u305f\u306e\u7d44\u7e54\u306b\u9069\u3057\u305f\u30ec\u30d3\u30e5\u30fc\u3092\u3057\u3066\u304f\u3060\u3055\u3044\u3002  <\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>MC1187390 | Unified sensor (v3.x) \u2013 new Remote Procedure Call (RPC) configuration health alert for Microsoft D [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-13835","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/posts\/13835","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/comments?post=13835"}],"version-history":[{"count":0,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/posts\/13835\/revisions"}],"wp:attachment":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/media?parent=13835"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/categories?post=13835"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/tags?post=13835"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}