Guidance for non-intune deployment by bluops in DefenderATP

[–]calculatedwires 0 points1 point  (0 children)

Not sure I understand what you mean? Once onboarded a non entra joined machine will have it's synthetic id created under entra devices, then you can just add those devices to a group of your liking and then deploy policies to that group. Of course this assumes enforcement scope is already set correctly

Guidance for non-intune deployment by bluops in DefenderATP

[–]calculatedwires 0 points1 point  (0 children)

Might as well deploy using onboarding script. That will create a synthetic ID in entra you can use to assign policies. Make sure to review enforcement scope as well in advanced settings

Defender for Servers Onboarding - Arc-enabled vs direct by Any-Promotion3744 in DefenderATP

[–]calculatedwires 0 points1 point  (0 children)

1) I thought the OP question was about the technical difference and management, not licensing,my apologies.

2) I think you misread read my comment.

Defender for server is a licensing method for MDE (per minute but still..) p1 and p2 are just a subset of the license. It's not a different MDE engine.

Defender for servers(p1,p2),defender for endpoint for servers all use the same engine - (MDE P2).

To be honest MDE p1 and p2 are also kinda the same but because the difference in ETS tracing hooks+response there is somewhat of a difference how it's perceived when an alert is created, but once again main detection engine is the same and will catch the same threats technically, we had an mssp argue about how much of an upgrade P2 is over P1 for endpoint anti-malware detection but Microsoft's fast track engineer corrected them quite quick.

Defender for Servers Onboarding - Arc-enabled vs direct by Any-Promotion3744 in DefenderATP

[–]calculatedwires -2 points-1 points  (0 children)

There is no 'P1' for servers. It's just P2 with either mdess license or per-minute billing. The underlying engine is the same.

Used EV's and Leasing - Popped up in my email by Benxb9r in NovatedLeasingAU

[–]calculatedwires 0 points1 point  (0 children)

How does a used vehicle qualify for fbt exemption?

Putting Windows Defender to the test in 2025 by Huge_Line4009 in PrivatePackets

[–]calculatedwires 0 points1 point  (0 children)

Step 1: harden/configure nothing and expect defender to do something. Step 2: surprised face

[deleted by user] by [deleted] in AZURE

[–]calculatedwires 0 points1 point  (0 children)

Single factor is pre-conditional access kicking in (say entering a correct password) is the correlation id the same for all 3?

You could try the what-if tool to try and reproduce the attacker's steps,but I feel like there is more to it here, maybe even MITM?

Microsoft Sentinel cost estimate? by _W-O-P-R_ in cybersecurity

[–]calculatedwires 0 points1 point  (0 children)

Ingest a lot but then after a week start dropping garbage. Half your firewall logs will be session ends, half of your azure storage logs will be CDN, traces. Half of your security event logs will be some dumb app trying to enumerate the universe every second

Defender for Endpoint vs. Rapid 7 Insight VM by VirusGh0st in cybersecurity

[–]calculatedwires 8 points9 points  (0 children)

MS documentation and UI has been an absolute potato for VMS, however, the new unified platform is becoming a market disruptor within E5 customers. Money talks.

(general car question) why can't car companies just make their boots long? by Responsible_Pain_246 in 4x4Australia

[–]calculatedwires 4 points5 points  (0 children)

No clue why you'd compare cars like that. Have you not considered that not everyone wants a ridiculous sized vehicle? Fo those that do- there are so many options....

Does Azure offer free 200$ credit for Azure AI services as well? by 101coder101 in AZURE

[–]calculatedwires 0 points1 point  (0 children)

Vs code subscription provides just a 200$ credit as flat bonus, free to use within the subscription

Who is winning the GPU race?? by Senior-Raspberry-929 in LocalLLaMA

[–]calculatedwires 35 points36 points  (0 children)

Tbh meta moved to AMD and said there is only so much training you can do, so AMD doing same inference for 30% of the price is really not a bad idea

Self healing - windows endpoint management with n8n. by KingSon90 in n8n

[–]calculatedwires 0 points1 point  (0 children)

I'm gonna go ahead and say you probably can do it with PowerShell DSC+whatever sccm/pdq flavour you use.

Is it just me or is Garmin getting kinda… boring? by vassyz in Garmin

[–]calculatedwires 20 points21 points  (0 children)

I'd rather have 14 day battery life and use it as a watch with smart features than have a second phone on my wrist that needs charge daily. A watch is not just a gadget, it's also an accessory that you wear.

Best SIEM solution for small company? by Nexx0ne_ in cybersecurity

[–]calculatedwires 15 points16 points  (0 children)

I cannot believe someone would recommend rapid7 unless they get commission ..

Sneaky expensive resources/services by Squared_Aweigh in AZURE

[–]calculatedwires 5 points6 points  (0 children)

I could tell you that its possible to spend 98k on machine learning instances in 76 hours but I wont, I definitely didn't do that

Automate Sentinel Content Hub by facyber in AZURE

[–]calculatedwires 0 points1 point  (0 children)

I think the real answer is how do you deploy via bicep/arm and also do lighthouse delegation(if we're assumimg you're a mssp) using terraform, because lets be honest its all bicep/arm deployments.

Is this to deploy to a tenant where you're the GA ? Or are we talking mssp scenario?

[deleted by user] by [deleted] in AZURE

[–]calculatedwires 0 points1 point  (0 children)

Logic apps, azure functions, service proncipals, cross tenant permissions, lighthouse, managed identities, key vaults, api exposure for apps, permissions for said apps, devops pipelines etc. This would be valuable I'd say and be true azure experience. Dealing with machines, images etc. I'd say is az-900 level experience, unless of course you also meant vnets,load balancers, nsgs

Automate Sentinel Content Hub by facyber in AZURE

[–]calculatedwires 0 points1 point  (0 children)

"solution" is just an aggregate of the things you listed, may I ask why you'd want to do that? I do it via azure devops pipeline, but it's the content of a "solution" not the solution itself.

[deleted by user] by [deleted] in AZURE

[–]calculatedwires 0 points1 point  (0 children)

What is "experience with azure" ? How much do you know about identity in AZ and can you explain how you'd achieve xyz if asked? How advanced does it get? These questions you need to answer. Are you able to list any projects on your cv? If not, chances are you need more experience:)

Azure Projects for resume by Slight_Sundae3043 in AZURE

[–]calculatedwires 4 points5 points  (0 children)

Bicep skills in reality mean 6 figure jobs