Task 1.6: Configure Group Policy
-
In the Windows search field, enter Group Policy Management, and then open the Group Policy Management App
-
On the Group Policy Management menu, select Forest: MSMDI.local > Domains > MSMDI.local > Default Domain Policy.
-
Right-click on the Default Domain Policy and then select Edit.
-
In the left navigation, select Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > User Rights Assignment.
-
Double-click Log on as a service and select the Define these policy settings checkbox.
-
Select Add User or Group and in User and group names, enter mdiSvc01$, then select OK.
-
Return to the Microsoft Defender portal tab in Microsoft Edge, navigate to Settings > Identities, and select Directory service accounts
-
Select Add credentials and for Account name, enter mdiSvc01.
-
Select the Group managed service account checkbox.
-
In the Domain texbox, enter MSMDI.local and then select Save.
You have successfully completed the Microsoft Defender for Identity lab (Day 1).
It can take up to 24 hours for the MDI functionality to become active. You will not be able to proceed immediately to Day 2.