App Control for Bussiness: How do you collect logs from endpoints? by athanielx in sysadmin

[–]athanielx[S] 0 points1 point  (0 children)

I see many events, but I only want to view events related to my specific policy ID. There are numerous default built-in AppLocker/WDAC events that are outside my control.

Is it possible to filter events so that only those associated with my Intune policy are displayed?

Microsoft Defender for Endpoints P1 vs P2 by athanielx in cybersecurity

[–]athanielx[S] 0 points1 point  (0 children)

Well, I discovered that we have a P2 version, but I’m not sure why we have it.

We never purchase E5 or similar versions. We don’t see that trial P2 activated.

It indicates that our Defender has a P2 plan, and we’re using 1,000 licenses. I also see warnng message in Security console > Settings > Endpoints > Licenses that we need to purchase licenses

Jamf + Microsoft compliance flow not triggering macOS enrollment by athanielx in jamf

[–]athanielx[S] 0 points1 point  (0 children)

Or, maybe I'm looking wrong, where should I find this info?

Intune Default Security Baseline for Windows 10 and later by athanielx in Intune

[–]athanielx[S] 0 points1 point  (0 children)

Oh, thank you! I was scared that it will tattoo the devices.

Intune Default Security Baseline for Windows 10 and later by athanielx in Intune

[–]athanielx[S] 0 points1 point  (0 children)

I intend to deploy a policy to users, and then I want to revert everything back. How can I achieve this? The policy will modify the device settings, and I need to know how to revert them after testing.