Forum Discussion

akl472's avatar
akl472
Copper Contributor
Jan 22, 2025

How does Defender detect file version limit default changes?

Hi all,

 

I am currently reviewing a historic article that mentions a Cloud Ransomware attack where attackers can change the default number of file versions saved by default. They change this from the default 500 to 1 and then save over your files to make them unrecoverable. Apparently this doesn't need admin credentials, a standard user can do this themselves.

All of the Microsoft guidance says that Microsoft is protected against cloud ransomware attacks of this type because of the file versioning feature, as well as being able to contact Microsoft for 14 days after such an incident and they can retrieve your data.

My questions are:

  1. Where do I find what the current settings are for file version limit defaults? Is it in the OneDrive/SharePoint admin centres?
  2. How do I find out whether such a change has been made?
  3. Is there an alert already configured in Defender to detect such a change?
  4. If not, does anyone know how to set one up, e.g., KQL and a custom detection?

 

I tried asking Copilot, but it just sends me to the official Microsoft documentation, so any help is greatly appreciated.

  • luchete's avatar
    luchete
    Iron Contributor

    Hi akl472!

    To find the current file version limit settings, you can check the OneDrive or SharePoint admin centers under the storage settings for versioning. To see if the limit has been changed, you’ll need to look at the version history or activity logs. Defender doesn’t automatically alert for changes to file version limits, but you can set up a custom detection using KQL queries in Microsoft Sentinel or Defender for Endpoint. You’d need to monitor for any changes to version settings or unusual file activity.

    Regards!

Resources