ASR rules in audit mode give you zero protection.
Call to action: stop treating audit mode as a final stop.
It is a starting point. The data is only useful if you act on it.
Full walkthrough with KQL queries and Intune steps:
https://t.co/k48mLQPZKC
If you're curious about how Microsoft access tokens work under the hood, maybe it's useful to you too. I call it "A Token of Appreciation" ๐
https://t.co/UuLAhNQ1Dx
#Microsoft#EntraID#JWT#IdentitySecurity#SecurityResearch
Update: AzureWithTom is now SecurityWithTom. ๐ฆ
The site has a new name a little refreshed look, and the content focus is now broader across multiple tracks.
Read about it here: https://t.co/e6VWdEdUQx
If youโve followed the site so far, thank you. ๐ซถ
Ever seen PIM throw โCannotDeleteLastAdminAssignmentโ?
๐งฉI ran into a strange edge case that ended up as an MSRC report, Microsoft confirmed and fixed it. Full write-up
๐ https://t.co/HM5boQ2RLR
Reminder for #WindowsAutopatch admins:
Migrate to the Win32 Client Broker for better reliability and on-demand deployment. Script-based installs still work, but the Win32 app is the new standard.
โก๏ธ https://t.co/AhdxDAzyYm
Windows Autopatch just got better in 2025:
โ Hotpatching for Win11
โ Better reporting in Intune
โ Now for Business Premium
I wrote a quick rundown on whatโs new + how to get started:
https://t.co/d3HNKQs5FR
#Windows11#Autopatch#Intune#hotpatch#microsoftsecurity
New blogpost!
Implementing "Attack Surface Reduction" policies is in my opinion mandatory.
If you have not yet touched this feature, please make sure to give it a shot and configure it!
https://t.co/Z1gsPUCpS1
#ASRrules#MicrosoftSecurity#AttackSurfaceReduction#MDE
๐ You can now add the E5 Security Add-on to Business Premium!
๐ข Important: Check out if your license state is correct! ๐ Read more about it:
https://t.co/iSvqbT2RPC
#Entra#XDR#E5Security#Microsoft
๐จ ๐๐จ๐ข๐ง ๐ฎ๐ฌ ๐จ๐ง ๐๐๐ซ๐๐ก 6๐ญ๐ก ๐๐จ๐ซ #Yellowhat ๐ท A ๐๐๐๐๐๐ ๐๐๐๐๐๐๐๐๐๐ dedicated to Microsoft Security ๐ฅท Ticket sales NOW OPEN for live-audience (๐๐ฎ๐ด๐ต๐ฆ๐ณ๐ฅ๐ข๐ฎ): https://t.co/CKQ1iMDvfG ๐๐น๐ต๐ณ๐ฆ๐ฎ๐ฆ๐ญ๐บ ๐ญ๐ช๐ฎ๐ช๐ต๐ฆ๐ฅ ๐ฒ๐ถ๐ข๐ฏ๐ต๐ช๐ต๐บ!
Want to create a set of Analytic rules for your Microsoft Sentinel environment based on used Solutions? I wrote a blog post about it.
Go check it out! :-D
https://t.co/5Cq10nrnmi
#MicrosoftSecurity#MicrosoftSentinel#AnalyticRules
๐ New Blog Post Alert! ๐
After a long time with no blog posts it was time to dust of that good 'ol website.
Todays blog "Manage permissions for Microsoft Sentinel across Multiple Environments with Lighthouse"! ๐๐
https://t.co/0xkZqdSrSZ
#AzureLighthouse#MicrosoftSentinel
New blogpost!
We tend to improve our security in our Microsoft environments. But lets not forget our DNS configurations. In this blog I will tell you more about this. Also more about e-mail validation!
https://t.co/mdyNh1EyQe
#emailsecurity#Microsoft#mfa#dns#mdo
@janbakker_@JussiRoine 60% keyboard hereโฆ anyway, in allot of cases you can add the kind of language to the first three โโโJSON for example. It will have the same effect as VSC does!