Forum Discussion
Arjun_Rajan
Oct 16, 2021Copper Contributor
Custom Detection rule to find Inactive Device
Hello, My Org Planning to create incidents whenever the device goes inactive state in Microsoft Defender for Endpoint. It would be much appreciated if I get the query(KQL) to list the Inactive device...
Akash553
Nov 25, 2022Copper Contributor
hello Brother
i need to know in this condition for detection, how should we test it like should i have to disable the network connection of the machine and then wait for some time? If yes then how much time it requires
Please mention the test how should i test in testing environment?