I usually don't drink on weekdays, but hear me out:
Over the weekend, I thought about a common conditional access misconfiguration I often see in the wild. I decided to write a blog post about it, but that got me thinking: Is that the best way to reach as many tenant admins as possible?
That gave me the following idea: What if I write a π₯Maester test for it?
Now, as a non-developer, that might be out of your comfort zone, but with the help of @merill and @Thomas_Live, I quickly got this new test added to the existing repository, ready to hit hundreds or thousands of tenants.
Dare to (th)(dr)ink different. π₯
π [Blogpost] https://t.co/pOSGyIUv9n
π [Contribute to Maester] https://t.co/X8dnnRAJSv
β¨ Session Announcement: Build your security data lake with Microsoft Sentinel & Data Explorer; a match made in Azure! βοΈπβ¨
π€ Get ready for a VIP experience with the legendary @KoosGoossens, Microsoft Security MVP & Cloud Wizard @ Wortell! He's spilling the tea on turbo-charged, budget-friendly log storage tricks that'll have your data spinning into the future.
ποΈ March 5, 2025 - mark your calendars for an epic showdown of code and Hollywood glamour at VUE! π₯π«
ποΈ VIPs, let's light up the cloud! π₯π Tickets are flying - catch yours now and join the hype! ππ https://t.co/I1L4o1MhOz
#ELDK2025 #ExpertsLiveDK #Microsoft #Community #Security #Azure #AI #ModernWorkplace #Intune #DevOps #Automation #M365 #PowerPlatform #Data #Purview #Development #OpenAI #Copilot #AVD #W365 #Identity #Entra
ELDK2025 Organizers:
Morten Knudsen (@knudsenmortendk) Thomas Poppelgaard (@_POPPELGAARD) Martin Byskov (@ByzzByskov) Henrik Wojcik (@henrikwojcik) Heine Madsen (@HeineKoldbro) Kent Agerlund (@agerlund)
Investigating Microsoft 365? The Unified Audit Log (UAL) is your go-to for tracking user and admin activities. Learn how to leverage it for security insights and compliance.
π Read more: https://t.co/OZkMoe6kun
One of our very smart Active Directory experts has been putting together a series of blog posts about hardening AD. Already into its 7th installment, it covers SMB hardening, disabling NTLMv1, least privilege and more. Check the series out - https://t.co/KkKfarAX9a
Great reminder for anyone wanting to enrich their Kusto queries with additional information. If you are after enrichment such as geo info for IPs, ASN lookup info, tor exit node data and more, then have a look below. The KQL is already written for you - https://t.co/5GoSenHxDy
A new dedicated resource application to enable Active Directory to Microsoft Entra ID sync using Microsoft Entra Connect Sync or Cloud Sync is coming π±
In the announcement the mentioned reason is "upcoming security hardening"...
6bf85cfa-ac8a-4be5-b5de-425a0d0dc016
#EntraID
@KoosGoossens and I have been working on this for a few months now and while he is away at ESPC24 in Stockholm this week, I thought I'd share this intro - https://t.co/ZorT1GCxp6
Join us for the first of many episodes, coming soon to your favorite podcast player.
For all #KQL fans, I had this list of community repos lying around, the list now consists of 33 repos for you to investigate. Happy hunting! πΉ
Feel free to send a PR if you miss repos! :)
https://t.co/oKNZi0vmRf
Who doesn't want to learn about #security? π
Come to #ExpertsLiveEU to hear from @KoosGoossens and learn how to build your security data lake with #MicrosoftSentitel & #DataExplorer: a match made in #Azure.
π Sept 24-25 Main Conference
π Budapest, Hungary
π https://t.co/8zMlJKvPFl
Wrote a new blog on how to set up Microsoft Defender for External Attack Surface Management. Hope itβs of use to someone out there.
https://t.co/YfetTjsxhe
@mikecybersec@fabian_bader Because we cannot trigger Functions from Sentinel automation. And triggering a Function from a Logic Apps, and bringing back the response to that Logic App is even more ugly. π
@fabian_bader@olafhartong Thatβs easy. Deploy Logic Apps from code and make sure nobody had write access to the Logic Apps. Perhaps a good idea for all resource types capable of using Managed Identites. Oh; and donβt assign owner to those identities. π€ͺ