Enable sharing security event information from an on-premises Active Directory server with Attack Surface Risk Management.
Configuring security event forwarding allows Active Directory to share security event
information (such as object access events, logon/logoff events, system events, and
account management events) with Attack Surface Risk Management through a configured
Service Gateway.
Important
|
Procedure
- Obtain the forwarding agent's installation package from the Trend Vision One console.
- Go to .
- Use the toggle to enable or disable the integration.
- In the Security Event Forwarding tab, click
Download Installation Package.A tooltip with information about the installation package appears.
- Click Download Installer.
- Install the agent on your Active Directory server.
- Execute trend-micro-vision-one-ad-connector.exe with administrator rights.
- Follow the on-screen wizard to configure the forwarding agent.
Important
If SSL certificates are imported, the certificates must be the same as the ones used in Service Gateways
- Repeat the previous step to install the agent in multiple Active Directory servers.
- In the Trend Vision One console,
verify that the agent is connected and perform additional integration steps if
necessary.
Note
Any configuration changes on the Trend Vision One console take 5 minutes to reflect on the forwarding agent.- Go to .
- Verify that the forwarding agents appear in the agent list.
- (Optional) Click on Enable automatic updates.
Important
If the forwarding agent user interface is open, the automatic updates process stops.