254 questions with Microsoft Defender for Identity-related tags
Travel Alerting
So I am a little familiar with Atypical Travel Alerts and Impossible Travel. Is there a way to setup just travel alerts? The Example a U.S. Employee was only hired in to work remotely in the U.S. So i would only expect U.S. based locale data. Is there…
Microsoft Defender for Identity
How to remove AV instance registry entry as i am not able to access this path getting access denied
Hi, I am using trellix AV and while installing agent malware protection AV created having WMI instance and registry entry under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av but after running Trellix AgentCleanupTool.exe it removes…
Microsoft Defender for Identity
How to load the Azure IP address list for east us 2 into the hunting query "Detect Azure RemoteIP"
in the Defender dashboard in Azure, under Hunding , advanced Hunting, Queries, General Queries, Detect Azure RemoteIP I downloaded the .json file that is the list of all IP address ranges. I copied the ip address list for east us 2 and pasted it into…
Microsoft Defender for Identity
My windows defender is not working properly
i have just configured that agent also enable the protaction mode but when some file which is unauthorised, that file is not deleted, and my server is compromised pls look into it or just set up a call for this ASAP
Microsoft Defender for Identity
Microsoft Defender Vulnerability Management is not displaying accurate Exposed Devices count
<< NOTE: This relates to Microsoft Defender for Endpoint but there isn't a child tag available for that >> The Weaknesses table in Microsoft Defender Vulnerability Manager is indicating that there are exposed devices, but when I open the…
Microsoft Defender for Identity
Duplicate SecurityEvent logging after migrating from MMA to AMA
Greetings, I added a few extra tags to this as we are not quite sure of why we cannot Disconnect or Delete the Security Events Via the Legacy Agent Connector from our Sentinel environment. All Azure VMs have been migrated from the MMA (Legacy) agent to…
Microsoft Defender for Cloud
Microsoft Sentinel
Microsoft Defender for Identity
MS Defender - How to manage Tenant Allow/Block Lists with graph api
Hi, I'm trying to create an integration to block certain URLs on Microsoft Defender with the Graph API. After looking into the documentation, I found this endpoint:…
Microsoft Graph
Microsoft Defender for Cloud
Microsoft Defender for Identity
How to resolve about Sentinel and XDR not connecting properly.
We are currently doing integration testing between Sentinel and XDR. After onboarding and offboarding the workspace from XDR side several times ,following the steps provided in Microsoft's official documentation, encountered the following…
Microsoft 365
Microsoft Sentinel
Microsoft Defender for Identity
Microsoft Entra ID
What does the Defender Anti-Spam (Inbound) policy overrule?
The Defender Anti-Spam, Anti-Malware and Anti-Phish policies all sit together in the Email Policy and Rules section, but I am trying to understand what an exception to these policies would over rule? Mainly looking at the Anti-Spam Policy, as that is…
Microsoft 365
Microsoft Intune Security
Microsoft Defender for Identity
Microsoft Defender for identity auto disable user account.
Hello, Recently, we are experiencing a lot of user accounts being automatically disable by Microsoft Defender for Identity when they authenticated by Exchange Online. Somehow, Defender think the user's accounts being attacked, and just disabled users…
Microsoft Defender for Identity
Data connector buttons are grayed out saying No permissions
cannot enable Microsoft Defender XDR connector in sentinel despite being logged in as owner of tenant, subscription and resource group. My licence is Microsoft 365 Business Premium which I see in documentation is an Microsoft XDR eligible licence
Microsoft Sentinel
Microsoft Defender for Identity
Need IOC's
Hi MSTeam, Can i have IOC's for the vulnerability "CVE-2024-21413" to hunt.
Microsoft Defender for Identity
Security Recommendations for LAPS are outdated
These recommendations in the Microsoft Secure Score seems to be ignoring the new Windows LAPS and looking at the old LAPS. When we changed over to the Windows LAPS, these recommendations started getting flagged. I thought Microsoft would eventually…
Windows
Windows Server
Microsoft Defender for Identity
Defender for Identity Radius Aad Syncer Disabling User Accounts - Not Sure Why?
We have users randomly getting disabled and the audit logs are showing that Radius Aad Syncer is the culprit. The logs don't offer much more information so I'm not sure how to approach troubleshooting this, but a growing number of users are affected.
Microsoft Defender for Identity
Why defender is not correlating the Entra ID protection alerts?
Hi Team, In my environment, Entra ID Protection is generating multiple alerts even when the user, IP address, and sign-in events are the same and occur within seconds. These alerts are forwarded to Microsoft Defender, but they are not being correlated,…
Microsoft Sentinel
Microsoft Defender for Identity
Microsoft Entra ID
Issue with Attack Simulator - Not all targeted users showing up
Hello, I'm currently experiencing issues with the Attack Simulator. I'm running a phishing simulation, and I've selected the "Include all users in my organization" option, which should total to 193 users. However, the pages are only adding up…
Microsoft 365
Microsoft Defender for Identity
Defender for Identity - Directory Services Advanced Auditing is not enabled
Hi Everyone, We have followed the following guide from Microsoft in regards to enabling "advanced auditing" for Defender for Identity: https://learn.microsoft.com/en-us/defender-for-identity/configure-windows-event-collection However, we keep…
Windows
Active Directory
Microsoft Defender for Identity
Duplicated Defender AAD Identity Protection alerts due to different sign-in request ID in milliseconds
Hi, We are seeking some advise regarding the duplication alerts in our defender portal. Any help is greatly appreciated. Subject: Duplicated Defender AAD Identity Protection Alerts Due to Different Sign-In Request IDs in Milliseconds Alert Name:…
Active Directory
Microsoft Defender for Identity
Microsoft Entra ID
Privacy protection VPN option is not visible on my Microsoft defender
Privacy protection VPN option is not visible on my Microsoft defender. Earlier I was used now it's not visible, I have 365 personal plan
Microsoft Defender for Identity
How can I investigate risky sign in's to determine if an account is actually compromised?
I am trying to determine why some user sign in's are flagged as risky. When I check the IP address that was associated with the sign in, most of the time it is from a GTHost server. Our users are mostly using iPhones and trying to log into the…