@techspence When you are all requiring compliant/hybrid devices, are you extending that to mobile? We typically deploy MAM instead of MDM and so there is a gap in identifying a trusted mobile device.
@MaxRogers5@JefTek Seeing the same, what are thoughts on leveraging device trust to counter? As in, requiring AD Joined/Compliant.
Of course there are still gaps, but if you can apply this rule it seems to be effective.
Ever seen problems with unwanted push notifications after enabling this feature? If a TA just needs your email address to initiate passwordless push, users get unwanted authentication requests. With number matching and authentication context, the TA isn't going to get anywhere, but still annoying for the user.
@vptrms@malmoeb@InvictusIR Yea but customer would need to have been shipping logs to Log Analytics pre-incident right? Is there a way to easily export historical sign-in logs to LA?
NEW BLOG: AiTM/ MFA phishing attacks in combination with “new” Microsoft protections (2023 edition)
In this blog, I'm going to explore all the new and existing capabilities (Token protection/ attack disruption and more)
https://t.co/xmWKXZwzZs
#AzureAD#MicrosoftSecurity
Seeing more of these types of attacks which are especially dangerous because they circumvent multi factor authentication.
Very important to make users aware and ensure proper safeguards are in place.
A multi-stage AiTM phishing and BEC activity spanning multiple banking & financial services orgs uncovered by Microsoft Defender Experts shows the complexity of these threats that abuse trusted relationships between orgs with the intent of financial fraud: https://t.co/VHIg2tWXbF
@NathanMcNulty@NathanMcNulty et al, deployment of Azure Arc will become optional and customers will be able to onboard the Microsoft Defender for Endpoint agent as they used to, like any other MDE onboarding, with no extra effort or agents.
this is rolling in a Private preview as speak.
@NathanMcNulty@NathanMcNulty et al, deployment of Azure Arc will become optional and customers will be able to onboard the Microsoft Defender for Endpoint agent as they used to, like any other MDE onboarding, with no extra effort or agents.
this is rolling in a Private preview as speak.
@NathanMcNulty@Name02007025 That all makes sense, but in testing we were not able to collect security events from servers without MDC P2 or Sentinel. It could be a problem with our data collection rules, or a licensing limitation.
@Name02007025@NathanMcNulty Right, looks like the options are A: Defender for Servers P2 ($15/mo/server) or B: Pay for Sentinel ingestion on top of Log Analytics ingestion.
If you manage non-Azure servers, I'm starting a new series on Azure Arc you might be interested in :)
My first post is a detailed walkthrough of onboarding Windows Servers using Group Policy since I find the docs a little unclear
https://t.co/brZvNcndZ8
Why use Arc? Mini 🧵 :)
After installing KB5021233, some Windows devices might start up to an error (0xc000021a) with a blue screen. See more details on this issue with workaround steps on the Windows release health dashboard.
https://t.co/f04ENukfmO
Beginning January 5, 2023 Microsoft will reject (delete) emails that contain attachments ending with file extensions associated with Malware (like .ISO, .EXE, etc). The previous behavior was to quarantine the email.
You can override the behavior
#MC468187
https://t.co/SytyYVpZVd
‼️MISSING PERSON - Community Help Needed‼️We need your help in locating missing 16-year-old Kiely Rodni who was last seen near the Prosser Family Campground, in Truckee on 8/6. If you have any information contact the Placer County Sheriff’s Office immediately: 530-886-5375.