#KQL#M365Defender#DFIR
Detect (possible) disablement of Defender for Endpoint by comparing the timestamp of the last entries in DeviceInfo and in AADSignInEvents
What do you think about this idea?
https://t.co/HtxkUIjEvw
Curious about what's changing with @MSIntune App Protection Policies for iOS and Android apps? Check out our article on conditional launch improvements - https://t.co/eGovi9ncTt #MSIntune#MEM#Microsoft365
#M365Defender integration with #AzureSentinel
- Stream all M365D incidents into Sentinel and keep them synchronized between the portals.
- Incidents from M365D include all associated alerts, entities, and relevant info for preliminary investigation.
https://t.co/ahTrwpdGbt
Just announced at #microsoftignite: As part of Passwordless GA, you can now track the registration and usage of all authentication methods across your org using the new Authentication Methods Activity blade in #azuread!
https://t.co/1cxLdWKk19
2 new Azure AD roles are now available - Auth Policy Admin and Domain Name Admin. Now you do not need Global Admin to manage tenant-wide MFA settings or domain names.
@StuartKwan, @TurnOnMfa
https://t.co/dl2syx0WNE
https://t.co/adZgUGgcfD
Our new @Apple WatchOS mail complication is available for testing in @Outlook iOS TestFlight. Check it out if you have a Series 4 or later watch.
#Outlook#EMS#Microsoft365
Three suggestions on how to apply #ZeroTrust#Networking principles
- Use #MEM for context based access control for wireless access (https://t.co/v2SlAegjlS)
- Migrate #VPN servers to #Azure#vWAN#P2S and use AzureVPN clients to connect (#ER to on-prem)
- Use Cloud web proxy
Our #azuread Conditional Access power users are going to love today's announcement from @Vi_Deora: Search/Sort/Filter for policies is finally here!!🙌
https://t.co/W6r83vRfn1
Microsoft has updated the article about #AzureAD#ConditionalAccess for B2B collaboration.
It covers authentication flows and various factors that influence MFA and CA policy behavior for B2B guest users in resource tenant. Strongly recommended to read:
https://t.co/DosjGfMu1J
One of the items we quietly rolled out this week is the ability to clear recipient entries from @Outlook for iOS's recipient cache. Useful, when there is an outdated or wrong address or if you just don't want @gregtaylor_msft to be the first Greg in your list. 😂
#Outlook#EMS
New! ✨We added company branding to the top left of @azuread MFA/SSPR Combined Registration 😃
Before it just had the company name (e.g. Woodgrove), not the company logo. We added branding to My Sign-Ins and the Security Info page too. #Microsoft video: https://t.co/u0fLL4Pg92
Find out how SecOps can cast a wider net when it comes to protecting on-premises identities using Microsoft Defender for Identity's new sensor for AD FS! 🔍 Read the blog here: https://t.co/O1U5W18C2i
There was some interest for examples how to query both logs for Legacy Authentication. I made example using the UNION and iff() in Log Analytics to have analytics based on both tables (SigninLogs&AADNonInteractiveUserSignInLogs) https://t.co/7sdZECvzwZ
With native #CloudAppSecurity connector alerts & Cloud Discovery logs can be ingested into #AzureSentinel. In addition, with #MCAS API & AzureLogicApps you can send MCAS Activity Logs to the underlying Azure LogAnalytics workspace, cool!
https://t.co/HNdgFEvBVw
I'm SO excited about today's big news : #Microsoft#Authenticator now autofills passwords. This is in Preview and we'd love for you to try it! #MicrosoftAutofill https://t.co/ZFupIiuIKX