241 questions with Microsoft Defender for Identity-related tags
Windows Defender Phishing Email Submission and Remediation
Hi, I have a question. We use gmail in my organization for email and Knowbe4 for phishing email submission and remediation. We have microsoft 365 licenses for all staff members. My organization is thinking of getting rid of Knowbe4 but I was wondering if…
Where do I manage old audit activity alerts?
I have an activity alert setup for an ACCOUNT A and was later changed for ACCOUNT B but we still receive alert for ACCOUNT A. I have checked everywhere and there is no alert setup for account A How can I find it? Tried Powershell too but not much…
Privacy protection VPN option is not visible on my Microsoft defender
Privacy protection VPN option is not visible on my Microsoft defender. Earlier I was used now it's not visible, I have 365 personal plan
We received reports from our users that our URL is unsafe, but they are safe.
Hi there, I am trying to contact Microsoft Defender support, but I am experiencing difficulties getting in contact with anyone. I am writing regarding false positive alerts that our users are receiving from Microsoft Defender concerning our legitimate…
Azure ATP sensor issue -DC not visible under the security portal
Hi,we have installed the Azure ATP sensor on 33 DC's. But one DC's sensor status was unhealthy. To resolve this, we have cleared the DC entry from security portal and again re-install the ATP but unfortunately this time the affected DCS is visible in…
API to get Microsoft Defender Campaigns
Is there a way to get the Campaigns data inside the Microsoft Defender Portal using an API?
What does the Defender Anti-Spam (Inbound) policy overrule?
The Defender Anti-Spam, Anti-Malware and Anti-Phish policies all sit together in the Email Policy and Rules section, but I am trying to understand what an exception to these policies would over rule? Mainly looking at the Anti-Spam Policy, as that is…
MS Defender web protection / SmartScreen for Google Chrome and Firefox
Hi. We have our CE+ assessment in a few weeks. In our CE basic, we provided information about our browsers Edge, Google Chrome and Firefox they have MS Defender / SmartScreen options enabled for malicious sites and downloads. Unfortunately, MS Defender…
Data Loss Prevention
i have Microsoft 365 Business Premium license. do i need to Add any Add-on license or i will get full feature of DLP within this license. actually i want to use this DLP to prevent and monitor user activity.
I removed defender and now I can't download files in Edge.
After configuring the windows defender, windows defender apt, and windows defender smartscreen processes not to start by removing the execute permissions on the corresponding exe files, I am unable to download files in Edge. When I try to download the…
Phishing attack simulation payload editor is extremely broken
We are using the attack simulation training module in Defender for Office. So we have used the solution to run phishing exercises the past year. I now wanted to change our custom positive reinforcement notification. It seems the editor…
How to find installed software's on servers
from Windows defender portal (security.microsoft.com) can we get report of all installed software's running on servers only not client machines
Alerting when break-glass domain admin account has been used by someone
Hi, I have a break-glass domain admin account in several forests whose DCs have MDI sensors installed. Is it possible to get alert/mail notification when that account has been used by someone leveraging MDI events/logs?
Advanced Hunting Query -> Risky sign-ins & Risky users in EntraID?
Hi Everyone, Quick question - how can I query users/sign-ins that are flagged under Risky Activities (Security) in Entra ID within the Microsoft Defender Security portal under Advanced hunting? Essentially what I want to do is when a user is flagged on…
Microsoft Defender Email Collaboration
I want to customize quaratine notification. When user recieve malicous mail ( for example it will be phishing link , malicous attachment, spam mail and etc) , it will go quarantine due policies. Quarantine also sends notification to user, as quarantine…
Phishing Confidence
We are considering increasing the phishing threshold within Defender for Office Anti-Phishing policies, but we want to get a good understanding of how many emails this will effect when we do. I tried looking at the EmailEvents table within defender to…
Defender XDR - Broswer extension
Hello, We have the all Defender P1/P2 plan, etc. We had in the past few months in the device page the software inventory->Browser extension. Now, we can received the Data from there and would like to know if something change in the platform or if i…
Troubles Enrolling Server through Microsoft Defender
Hi, I’m working on configuring Hybrid Azure AD Join for our domain-joined devices, and I've already set up Active Directory and Hybrid Azure AD. The next step I’m trying to take is enrolling devices through Microsoft Defender Settings > Endpoints >…
how to export scan data and xml report of an asset that has been detected for being vulnerable by MS Defender
Hello I am trying to figure out how to generate scan data and XML report of an asset that has been detected for vulnerability for a specific CVE on defender XDR. I am trying to provide this information to the Rapid7 team as the vulnerability report they…
Whats goin on?
<Event xmlns="__http://schemas.microsoft.com/win/2004/08/events/event__"> <System> <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" /> …