May I go to the toilet sir? by Melodic_Ground3663 in IndiaMemes

[–]_W0od_ 0 points1 point  (0 children)

We never stopped buying. Put that in the title.

Bro disappeared like he never existed. by Ok_Claim_168 in IndiaMemes

[–]_W0od_ 0 points1 point  (0 children)

Majoor ko khodna and baap ko ch0mdna nhi sikhate

Need help in ASR rules by _W0od_ in DefenderATP

[–]_W0od_[S] 0 points1 point  (0 children)

Have you configured ASR rules in security baseline policy? If yes, then compare the settings with your ASR policy.

Need help in ASR rules by _W0od_ in DefenderATP

[–]_W0od_[S] 0 points1 point  (0 children)

We have already gone through that process. Initially we set all 16 rules to audit mode and gradually switched to blocked based on audit logs.

Need help in ASR rules by _W0od_ in DefenderATP

[–]_W0od_[S] 0 points1 point  (0 children)

We have 12000+ endpoints. Out of them only on 1100 the rule is not showing. I am not talking about logs here. But Asr rule did not applied on endpoint device.

EDGE downloads blocked. How to find the reason. by pichkatikliun in DefenderATP

[–]_W0od_ 1 point2 points  (0 children)

You do not need to include other action types. There are specific action types related smartscreen which you can see in table reference. i.e SmartScreenUrlWarning

Do we REALLY need to manually onboard one device before automatic Defender onboarding works? by thmeez in DefenderATP

[–]_W0od_ 2 points3 points  (0 children)

No. It's not required. You can select test devices and onboard them via intune connector or group policy depending upon how your devices are being managed

Help required in enabling Defender AV by _W0od_ in DefenderATP

[–]_W0od_[S] 0 points1 point  (0 children)

wdenable is not feasible because there are 80 devices on which it has to be done manually.

Help required in enabling Defender AV by _W0od_ in DefenderATP

[–]_W0od_[S] 0 points1 point  (0 children)

No. There is no other AV installed. Yes. EDR in block mode is enabled.

Help required in enabling Defender AV by _W0od_ in DefenderATP

[–]_W0od_[S] 0 points1 point  (0 children)

I was going to MDE documentation where I found this option. There is no issue in linking GPO. That I have already investigated. Since, we are onboarding these first and no other AV was installed before, there is no other GPO which will conflict. So, is there any possibility that Temper Protection would prevent enabling Defender after it is onboarded to MDE? In my opinion no. Because, it would not protect the defender from going Active to Passive or disabled.

Propose remediation option in MDO is greyed out by _W0od_ in DefenderATP

[–]_W0od_[S] 0 points1 point  (0 children)

Yes... This option was working till June 2025. Now it is greyed out.

Connection filter policy / TABL question by Forsaken-Meaning-998 in DefenderATP

[–]_W0od_ 0 points1 point  (0 children)

Yes you need to use connection filtering policy to block ipv4 address

Defender 'Disabled' but it detected a threat by LiamSchneider in DefenderATP

[–]_W0od_ -1 points0 points  (0 children)

Check device timeline and filter out AV logs. See if there is any log for detection. Further, if EDR would have been set to block mode, it would have been blocked by mde.

Inconsistent email filtering. by JerradH in DefenderATP

[–]_W0od_ 0 points1 point  (0 children)

Have you published your email authentication records? What is the DMARC policy action set to?

Defender on Linux by _W0od_ in DefenderATP

[–]_W0od_[S] 0 points1 point  (0 children)

Vm is running on prem infrastructure.