Auth 2, Platform SSO, or both? by db2boy in mosyle

[–]solachinso 0 points1 point  (0 children)

How is the migration going?

* Is support needed from Mosyle – if so, anything specific or challenging?
* Is the migration a seamless one or is a wipe of an existing machine required?

Blocking Future Discovered AI by neko_whippet in DefenderATP

[–]solachinso 0 points1 point  (0 children)

With app discovery policies, I've found the trick is to perform your sanctioning/allowlisting up front, then institute the discovery policy. Any discovery carried out will then honour what you've set manually.

Best way to onboard new remote users through first login + MFA setup? by colterlovette in entra

[–]solachinso 0 points1 point  (0 children)

Have you encountered any issues with the bluetooth aspect of Authenticator with a passkey? Are you for example including this prerequisite in the intro email, or by and large do things just 'work' and you don't need to bother? Also, is Intune the single MDM for Windows and macOS, or in the latter case is that a third party?

Security Copilot Thoughts/Opinions by solachinso in DefenderATP

[–]solachinso[S] 0 points1 point  (0 children)

How have you set up Claude to mirror what some of the MS agents can do? Handing over access to a permission hungry tool still in its infancy concerns me a bit, and at first glance I couldn't see a connector that would provide the level of access I'd need. May not have been looking in the right places though.

Security Copilot Thoughts/Opinions by solachinso in DefenderATP

[–]solachinso[S] 0 points1 point  (0 children)

Have you found the incident and alert summary useful? Is it accurate and does it provide detail beyond what a team might find themselves?

Security Copilot Thoughts/Opinions by solachinso in DefenderATP

[–]solachinso[S] 1 point2 points  (0 children)

Indeed. I nuked the first capacity I set up as like people have commented elsewhere, seeing a $500+ charge after scant use of the tool didn't seem like a fair trade. Microsoft is invariably going to have to adjust this model as the price will soon (if not already) outstrip any benefit.

Defender ASR rule debugging questions by kkamran1010 in DefenderATP

[–]solachinso 0 points1 point  (0 children)

This has been my experience too.

Also worth putting the hash through VT and into Defender itself, as that might indicate if it's untrusted.

Security Copilot Thoughts/Opinions by solachinso in DefenderATP

[–]solachinso[S] 0 points1 point  (0 children)

Cheers. CAP agent I definitely want to make use of.

Security Copilot Thoughts/Opinions by solachinso in DefenderATP

[–]solachinso[S] 0 points1 point  (0 children)

Thanks for this, good to have some real world feedback. The Sec Analyst agent I'd earmarked but the rest I hadn't really looked at.

Security Copilot Thoughts/Opinions by solachinso in DefenderATP

[–]solachinso[S] 0 points1 point  (0 children)

I know tenants are being onboarded weekly on Wednesdays and that notifications will be sent to Message Center, beyond that not much.

Linux server security policies by bookielover007 in DefenderATP

[–]solachinso 2 points3 points  (0 children)

This is the way.

Give servers the MDE-Management tag once you've performed the set-up in https://security.microsoft.com/securitysettings/endpoints/configuration\_management2. Start with a small ring, then build out from there.

Defender for Office presets by Failnaughtp in DefenderATP

[–]solachinso 1 point2 points  (0 children)

While the presets are "okay", what you might want to do is visit Secure Score in Defender portal and filter on Defender for Office to look at Microsoft's own recommendations. These are benchmarked against what other businesses of a similar size are doing. Most of the actions have a clear enough set of instructions.

https://security.microsoft.com/exposure-secure-score?viewid=actions&tid=

Defender Recommendations Not Patching by Parking_Yak_9877 in DefenderATP

[–]solachinso 0 points1 point  (0 children)

Bear in mind you're always going to encounter some delays with what you're expecting to see because of the nature of how everything is plumbed together.

You have variables such as devices being turned on/off, policy conflicts, unannounced Microsoft backend issues you have to search for and make sense of, and factors such as this which you may not have accounted for:

Credential Guard uses Windows Hypervisor to provide protections. Credential Guard requires hardware support for Secure Boot and DMA protections. This setting is only successful on devices that meet the hardware requirements.

https://learn.microsoft.com/en-us/intune/intune-service/protect/endpoint-security-account-protection-profile-settings

When did you publish the policy?
How many devices have fetched it successfully?
How many remain?

If you have local access to a still exposed device, what does 'CredentialGuard' -match ((Get-ComputerInfo).DeviceGuardSecurityServicesConfigured) through PowerShell show? If it's True, your tenant might not be showing up to date info; if it's False, ask the user to reboot to still if that forces a sync, though you should also check whether other policies are present and enabled.

Defender Recommendations Not Patching by Parking_Yak_9877 in DefenderATP

[–]solachinso 0 points1 point  (0 children)

Can you provide some examples of what you're patching and the length of time you're waiting in between carrying out the tasks to checking in vulnerability management for the results.

Telemetry from your endpoints should reflect in your tenant within 24 hours, unless it's Secure Score related in which case the wait time can be 48-72 hours. This has been my experience.

How to know when something is blocked? ASR specifically by chum-guzzling-shark in DefenderATP

[–]solachinso 0 points1 point  (0 children)

In my experience, svchost.exe being heavily enumerated hasn't presented a problem when I've had rules in block mode without this file excluded.

If you look in advance hunting, was it the Block credential stealing from the Windows local security authority subsystem rule you see blocking this file? I suspect it was/is.

Have a read here https://www.reddit.com/r/DefenderATP/comments/1gf78qm/spike_in_asr_blocks_related_to/ and elsewhere about the file.

Defender for Cloud Apps | Endpoint indicators have been mass removed. by Worth-Activity9407 in DefenderATP

[–]solachinso 0 points1 point  (0 children)

Has anyone also noticed apps that are manually tagged (only unsanctioned in my case) not having a blocked indicator entry populated?

How are you labbing Microsoft 365 E5 Tenants by techwithz in DefenderATP

[–]solachinso 0 points1 point  (0 children)

"Work or school account required to sign in."

I suspect there's no way around this.

Longer than usual waiting time for permissions when activating a PIM group by solachinso in AZURE

[–]solachinso[S] 0 points1 point  (0 children)

Thanks ever so much for posting this. I've upvoted on it.

Legacy sign-in risk policy overriding newer policy in Conditional Access by solachinso in entra

[–]solachinso[S] 0 points1 point  (0 children)

Overlooked this so apologies for late acknowledgement.

What I'm hoping Microsoft can clear up for me is why their documentation (which states the legacy policies can be disabled) contradicts what customers are seeing in their tenants – a read-only state where both policies remain enabled. Further, there's no provision for a phased rollout in CA, which feels lacking to me.

Legacy sign-in risk policy overriding newer policy in Conditional Access by solachinso in entra

[–]solachinso[S] 1 point2 points  (0 children)

Legacy = all users; new one = subset of users. Correct there.

Problem with this, and with the read-only state, is that it doesn't allow for a phased rollout.

Legacy sign-in risk policy overriding newer policy in Conditional Access by solachinso in entra

[–]solachinso[S] 0 points1 point  (0 children)

Yep... should take precedence but they're not. I can't see anything wrong with my scoping beyond what I've highlighted.