241 questions with Microsoft Defender for Identity-related tags

Sort by: Updated
0 answers

Windows Defender Phishing Email Submission and Remediation

Hi, I have a question. We use gmail in my organization for email and Knowbe4 for phishing email submission and remediation. We have microsoft 365 licenses for all staff members. My organization is thinking of getting rid of Knowbe4 but I was wondering if…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,476 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
241 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
168 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
20 questions
asked 2025-01-31T18:10:48.28+00:00
Ennis Pool 0 Reputation points
0 answers

Where do I manage old audit activity alerts?

I have an activity alert setup for an ACCOUNT A and was later changed for ACCOUNT B but we still receive alert for ACCOUNT A. I have checked everywhere and there is no alert setup for account A How can I find it? Tried Powershell too but not much…

Microsoft Purview
Microsoft Purview
A Microsoft data governance service that helps manage and govern on-premises, multicloud, and software-as-a-service data. Previously known as Azure Purview.
1,366 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
241 questions
asked 2025-01-30T19:20:51.0566667+00:00
Gurpreet Kaur Gill 0 Reputation points
commented 2025-01-31T16:13:58.3266667+00:00
Gurpreet Kaur Gill 0 Reputation points
1 answer

Privacy protection VPN option is not visible on my Microsoft defender

Privacy protection VPN option is not visible on my Microsoft defender. Earlier I was used now it's not visible, I have 365 personal plan

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
241 questions
asked 2024-12-10T00:50:54.28+00:00
Thirumal Vellingiri 5 Reputation points
commented 2025-01-31T14:46:52.04+00:00
David Grant 0 Reputation points
1 answer

We received reports from our users that our URL is unsafe, but they are safe.

Hi there, I am trying to contact Microsoft Defender support, but I am experiencing difficulties getting in contact with anyone. I am writing regarding false positive alerts that our users are receiving from Microsoft Defender concerning our legitimate…

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
5,620 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,476 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
241 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
168 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
20 questions
asked 2025-01-24T17:26:36.4766667+00:00
Tirta Wulandari 0 Reputation points
commented 2025-01-31T03:26:53.1933333+00:00
Raja Pothuraju 11,875 Reputation points Microsoft Vendor
0 answers

Azure ATP sensor issue -DC not visible under the security portal

Hi,we have installed the Azure ATP sensor on 33 DC's. But one DC's sensor status was unhealthy. To resolve this, we have cleared the DC entry from security portal and again re-install the ATP but unfortunately this time the affected DCS is visible in…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,476 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
241 questions
asked 2025-01-29T10:55:54.0633333+00:00
Khushboo 0 Reputation points
1 answer

API to get Microsoft Defender Campaigns

Is there a way to get the Campaigns data inside the Microsoft Defender Portal using an API?

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
5,620 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
241 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
168 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
20 questions
asked 2025-01-06T10:36:01.8966667+00:00
Hashem Barakat 0 Reputation points
edited the question 2025-01-29T10:00:16.1133333+00:00
Givary-MSFT 35,216 Reputation points Microsoft Employee
0 answers

What does the Defender Anti-Spam (Inbound) policy overrule?

The Defender Anti-Spam, Anti-Malware and Anti-Phish policies all sit together in the Email Policy and Rules section, but I am trying to understand what an exception to these policies would over rule? Mainly looking at the Anti-Spam Policy, as that is…

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
241 questions
asked 2025-01-28T12:27:10.4433333+00:00
Josh N 20 Reputation points
1 answer

MS Defender web protection / SmartScreen for Google Chrome and Firefox

Hi. We have our CE+ assessment in a few weeks. In our CE basic, we provided information about our browsers Edge, Google Chrome and Firefox they have MS Defender / SmartScreen options enabled for malicious sites and downloads. Unfortunately, MS Defender…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,476 questions
Azure Advisor
Azure Advisor
An Azure personalized recommendation engine that helps users follow best practices to optimize Azure deployments.
72 questions
Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
460 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,491 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
241 questions
asked 2025-01-20T13:18:10.62+00:00
Muhammad Arif 0 Reputation points
edited a comment 2025-01-27T14:21:59.44+00:00
Navya 14,975 Reputation points Microsoft Vendor
1 answer

Data Loss Prevention

i have Microsoft 365 Business Premium license. do i need to Add any Add-on license or i will get full feature of DLP within this license. actually i want to use this DLP to prevent and monitor user activity.

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
241 questions
asked 2025-01-23T10:12:51.9366667+00:00
Parsian02 20 Reputation points
answered 2025-01-27T09:13:24.7366667+00:00
Catherine Kyalo 670 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

I removed defender and now I can't download files in Edge.

After configuring the windows defender, windows defender apt, and windows defender smartscreen processes not to start by removing the execute permissions on the corresponding exe files, I am unable to download files in Edge. When I try to download the…

Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
10,600 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
241 questions
asked 2025-01-27T00:51:19.2733333+00:00
rikuto.tomizuka 40 Reputation points
commented 2025-01-27T01:24:38.9133333+00:00
rikuto.tomizuka 40 Reputation points
1 answer

Phishing attack simulation payload editor is extremely broken

We are using the attack simulation training module in Defender for Office. So we have used the solution to run phishing exercises the past year. I now wanted to change our custom positive reinforcement notification. It seems the editor…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,476 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
241 questions
asked 2025-01-14T12:22:45.53+00:00
Emil Gertsen Grønkjær 0 Reputation points
commented 2025-01-26T18:40:42.45+00:00
Raja Pothuraju 11,875 Reputation points Microsoft Vendor
1 answer

How to find installed software's on servers

from Windows defender portal (security.microsoft.com) can we get report of all installed software's running on servers only not client machines

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
241 questions
asked 2024-11-14T09:07:16.2933333+00:00
Muhammad Zeeshan 100 Reputation points
answered 2025-01-22T09:21:58.1266667+00:00
K-Mohammed 235 Reputation points Microsoft Employee
1 answer

Alerting when break-glass domain admin account has been used by someone

Hi, I have a break-glass domain admin account in several forests whose DCs have MDI sensors installed. Is it possible to get alert/mail notification when that account has been used by someone leveraging MDI events/logs?

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
241 questions
asked 2024-12-08T20:28:49.3066667+00:00
Bojan Zivkovic 506 Reputation points
answered 2025-01-21T06:42:54.9066667+00:00
Catherine Kyalo 670 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

Advanced Hunting Query -> Risky sign-ins & Risky users in EntraID?

Hi Everyone, Quick question - how can I query users/sign-ins that are flagged under Risky Activities (Security) in Entra ID within the Microsoft Defender Security portal under Advanced hunting? Essentially what I want to do is when a user is flagged on…

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
241 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
23,067 questions
asked 2025-01-09T20:15:47.94+00:00
OwlTecAB 60 Reputation points
commented 2025-01-10T14:28:54.63+00:00
OwlTecAB 60 Reputation points
1 answer One of the answers was accepted by the question author.

Microsoft Defender Email Collaboration

I want to customize quaratine notification. When user recieve malicous mail ( for example it will be phishing link , malicous attachment, spam mail and etc) , it will go quarantine due policies. Quarantine also sends notification to user, as quarantine…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,476 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
241 questions
asked 2024-12-20T10:46:32.79+00:00
Kanan Ganiyev 20 Reputation points
commented 2025-01-08T05:25:34.8366667+00:00
Kanan Ganiyev 20 Reputation points
1 answer One of the answers was accepted by the question author.

Phishing Confidence

We are considering increasing the phishing threshold within Defender for Office Anti-Phishing policies, but we want to get a good understanding of how many emails this will effect when we do. I tried looking at the EmailEvents table within defender to…

Microsoft Exchange
Microsoft Exchange
Microsoft messaging and collaboration software.
657 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,476 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
241 questions
asked 2025-01-02T19:51:13.72+00:00
George Zerphey 176 Reputation points
commented 2025-01-07T13:26:17.7633333+00:00
George Zerphey 176 Reputation points
2 answers One of the answers was accepted by the question author.

Defender XDR - Broswer extension

Hello, We have the all Defender P1/P2 plan, etc. We had in the past few months in the device page the software inventory->Browser extension. Now, we can received the Data from there and would like to know if something change in the platform or if i…

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,987 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
241 questions
asked 2024-03-05T19:16:51.87+00:00
Étienne Fiset 50 Reputation points
commented 2025-01-06T05:25:04.29+00:00
Subham Thapa 0 Reputation points
1 answer

Troubles Enrolling Server through Microsoft Defender

Hi, I’m working on configuring Hybrid Azure AD Join for our domain-joined devices, and I've already set up Active Directory and Hybrid Azure AD. The next step I’m trying to take is enrolling devices through Microsoft Defender Settings > Endpoints >…

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
241 questions
asked 2024-12-05T17:12:17.0133333+00:00
Kaleb Francoeur 0 Reputation points
answered 2025-01-03T08:00:45.5333333+00:00
Prathista Ilango 170 Reputation points Microsoft Employee
1 answer

how to export scan data and xml report of an asset that has been detected for being vulnerable by MS Defender

Hello I am trying to figure out how to generate scan data and XML report of an asset that has been detected for vulnerability for a specific CVE on defender XDR. I am trying to provide this information to the Rapid7 team as the vulnerability report they…

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
241 questions
asked 2024-12-12T12:51:28.27+00:00
Saborni Barua 0 Reputation points
answered 2025-01-03T07:59:00.8933333+00:00
Prathista Ilango 170 Reputation points Microsoft Employee
0 answers

Whats goin on?

<Event xmlns="__http://schemas.microsoft.com/win/2004/08/events/event__"> <System>   <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" />  …

Microsoft Authenticator
Microsoft Authenticator
A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation.
7,871 questions
Microsoft System Center
Microsoft System Center
A suite of Microsoft systems management products that offer solutions for managing datacenter resources, private clouds, and client devices.
1,068 questions
Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,990 questions
Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
10,600 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
241 questions
asked 2024-12-30T13:57:06.6066667+00:00
Sherwin pillai 0 Reputation points