237 questions with Microsoft Defender for Identity-related tags
MS Defender web protection / SmartScreen for Google Chrome and Firefox
Hi. We have our CE+ assessment in a few weeks. In our CE basic, we provided information about our browsers Edge, Google Chrome and Firefox they have MS Defender / SmartScreen options enabled for malicious sites and downloads. Unfortunately, MS Defender…
Data Loss Prevention
i have Microsoft 365 Business Premium license. do i need to Add any Add-on license or i will get full feature of DLP within this license. actually i want to use this DLP to prevent and monitor user activity.
I removed defender and now I can't download files in Edge.
After configuring the windows defender, windows defender apt, and windows defender smartscreen processes not to start by removing the execute permissions on the corresponding exe files, I am unable to download files in Edge. When I try to download the…
Phishing attack simulation payload editor is extremely broken
We are using the attack simulation training module in Defender for Office. So we have used the solution to run phishing exercises the past year. I now wanted to change our custom positive reinforcement notification. It seems the editor…
We received reports from our users that our URL is unsafe, but they are safe.
Hi there, I am trying to contact Microsoft Defender support, but I am experiencing difficulties getting in contact with anyone. I am writing regarding false positive alerts that our users are receiving from Microsoft Defender concerning our legitimate…
API to get Microsoft Defender Campaigns
Is there a way to get the Campaigns data inside the Microsoft Defender Portal using an API?
How to find installed software's on servers
from Windows defender portal (security.microsoft.com) can we get report of all installed software's running on servers only not client machines
Alerting when break-glass domain admin account has been used by someone
Hi, I have a break-glass domain admin account in several forests whose DCs have MDI sensors installed. Is it possible to get alert/mail notification when that account has been used by someone leveraging MDI events/logs?
Advanced Hunting Query -> Risky sign-ins & Risky users in EntraID?
Hi Everyone, Quick question - how can I query users/sign-ins that are flagged under Risky Activities (Security) in Entra ID within the Microsoft Defender Security portal under Advanced hunting? Essentially what I want to do is when a user is flagged on…
Microsoft Defender Email Collaboration
I want to customize quaratine notification. When user recieve malicous mail ( for example it will be phishing link , malicous attachment, spam mail and etc) , it will go quarantine due policies. Quarantine also sends notification to user, as quarantine…
Phishing Confidence
We are considering increasing the phishing threshold within Defender for Office Anti-Phishing policies, but we want to get a good understanding of how many emails this will effect when we do. I tried looking at the EmailEvents table within defender to…
Defender XDR - Broswer extension
Hello, We have the all Defender P1/P2 plan, etc. We had in the past few months in the device page the software inventory->Browser extension. Now, we can received the Data from there and would like to know if something change in the platform or if i…
Troubles Enrolling Server through Microsoft Defender
Hi, I’m working on configuring Hybrid Azure AD Join for our domain-joined devices, and I've already set up Active Directory and Hybrid Azure AD. The next step I’m trying to take is enrolling devices through Microsoft Defender Settings > Endpoints >…
how to export scan data and xml report of an asset that has been detected for being vulnerable by MS Defender
Hello I am trying to figure out how to generate scan data and XML report of an asset that has been detected for vulnerability for a specific CVE on defender XDR. I am trying to provide this information to the Rapid7 team as the vulnerability report they…
Whats goin on?
<Event xmlns="__http://schemas.microsoft.com/win/2004/08/events/event__"> <System> <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" /> …
Defender for Identity Radius Aad Syncer Disabling User Accounts - Not Sure Why?
We have users randomly getting disabled and the audit logs are showing that Radius Aad Syncer is the culprit. The logs don't offer much more information so I'm not sure how to approach troubleshooting this, but a growing number of users are affected.
Package fails to install for Windows 2016 endpoints in Microsoft Defender for Identity
Problem with enroling Windows 2016 devices in Microsoft Defender for Identity As part of moving from a third party AV to defender (2019 and 2022 work fine). PowerShell Running the installation package fails on 2016 for multiple servers All available…
Can't access Microsoft Secure Score
I get this error when I try to access the Secure score to make improvements I have tried different browsers, credentials are correct, org customization is enabled
Vulnerability Alert - Virtual Machine contains an Entra browser cookie of the user account
Hi Team, We received a Defender alert recently telling us that there is a Virtual Machine that contains an Entra browser cookie of a user account, providing lateral movement to a Key Vault. This happened after one of our Admin users logged in to Azure…
Role & Permissions
What are the correct roles or permissions to let a user read and edit the email threat policies in Microsoft defender portal? From what I can find it would be Security Administrator. Is there a way to lower this role so it is not as privileged, if no…