<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>rss.livelink.threads-in-node</title>
    <link>https://techcommunity.microsoft.com/t5/microsoft-security/ct-p/microsoft-security</link>
    <description>rss.livelink.threads-in-node</description>
    <pubDate>Wed, 16 Sep 2026 06:34:17 GMT</pubDate>
    <dc:creator>microsoft-security</dc:creator>
    <dc:date>2026-09-16T06:34:17Z</dc:date>
    <item>
      <title>From DLP Alert Volume to Measurable Detection Assurance</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/from-dlp-alert-volume-to-measurable-detection-assurance/ba-p/4545973</link>
      <description>&lt;H2&gt;&lt;STRONG&gt;Introducing Data Security Workbench&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Built on the newly released Microsoft Purview DLP API, Data Security Workbench is an open-source starting point for any customer who wants to turn DLP alert volume into explainable detection assurance and controlled response.&lt;/P&gt;
&lt;img&gt;Figure 1: The workbench separates operational response from classification assurance while keeping both connected through one governed evidence plane.&lt;/img&gt;
&lt;H4&gt;&lt;STRONG&gt;The gap between alert volume and operational confidence&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Microsoft Purview surfaces the activity that matters. But security teams still face the same operational challenge: connecting alerts to event evidence, understanding&amp;nbsp;&lt;EM&gt;why&lt;/EM&gt;&amp;nbsp;a Sensitive Information Type fired, identifying the right business owner, deciding what should change, and responding without exposing the data they are trying to protect.&lt;/P&gt;
&lt;P&gt;That work is typically split across scripts, exports, spreadsheets, portals, and one-off analyst knowledge. The result is familiar — alert volume grows faster than confidence, tuning decisions are hard to defend, and remediation becomes either too cautious to help or too broad to trust.&lt;/P&gt;
&lt;P&gt;The goal is not to process more alerts. It is to make detection quality and response safety measurable operational controls.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Detection Assurance: a closed-loop control cycle&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Detection Assurance determines whether your sensitive-data controls are behaving accurately. It explains why they fire, produces reviewable improvements, and proves whether those improvements worked — all as a repeatable, closed-loop process.&lt;/P&gt;
&lt;P&gt;STEP 1: &lt;STRONG&gt;Observe &lt;/STRONG&gt;Define the SIT boundary, tuning profile, and control language&lt;/P&gt;
&lt;P&gt;STEP 2: &lt;STRONG&gt;Explain &lt;/STRONG&gt;Analyze detections to separate signal from systemic noise&lt;/P&gt;
&lt;P&gt;STEP 3: &lt;STRONG&gt;Improve &lt;/STRONG&gt;Generate a reviewable Purview implementation plan&lt;/P&gt;
&lt;P&gt;STEP 4: &lt;STRONG&gt;Prove&amp;nbsp;&lt;/STRONG&gt;Compare post-change outcomes against the original baseline&lt;/P&gt;
&lt;img&gt;Figure 2: Classification posture reports retain the evidence period, model routing, detection totals, analysis chunks, and scoped-event count.&lt;/img&gt;
&lt;H4&gt;&lt;STRONG&gt;Full transparency into detection behavior&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Each assessment produces a verbose Classification Efficiency Report documenting every detection across the scoped estate. It shows the total matches processed, how much noise was identified, the contextual patterns, underlying taxonomies, and where false positives concentrate.&lt;/P&gt;
&lt;P&gt;If you need to understand exactly what was flagged and why, the report gives full transparency — noise detection rate, primary workload, false-positive reduction opportunity, and pattern-level detail for every SIT rule in scope.&lt;/P&gt;
&lt;img&gt;Figure 3: Baseline and later observations make noise reduction visible by pattern and SIT rule, with comparison cautions when periods are not equivalent.&lt;/img&gt;
&lt;H4&gt;&lt;STRONG&gt;From report to reviewable Purview implementation plan&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;From this evidence, the system generates a Purview implementation plan. Each recommended step specifies the exact tuning change to make in your environment — the target SIT, the exact portal path, the current problem, and the precise configuration steps.&lt;/P&gt;
&lt;P&gt;Critically, each step explains why the change is safe to implement, quantifies the expected reduction in false positives, and flags associated risks. For example, it may recommend refining a sensitive information type pattern to exclude authentication token structures generating false matches, and tells you the expected noise reduction from that single change.&lt;/P&gt;
&lt;img&gt;Figure 4: The Purview implementation plan: prioritized actions (P0–P2), exact administrative steps, scoped workloads, deployment modes from simulation to operational control, and a copy-and-tune principle preserving rollback. This is a governed, reviewable, and quantifiable improvement to your DLP posture — not a one-time model opinion, but a repeatable control cycle with measurable outcomes.&lt;/img&gt;
&lt;H4&gt;&lt;STRONG&gt;From assurance to operational response&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Each tuning round also updates a DLP response store with the AI verdict for every analyzed incident. The system triages events — identifying which are genuine exposure and which are systemic noise — and records a privacy-safe rationale alongside each verdict.&lt;/P&gt;
&lt;P&gt;These verdicts can then be written in bulk back to the Purview incidents (as comments and tags in Microsoft Defender), or used to reach out to affected end users with guided remediation steps via email or Teams.&lt;/P&gt;
&lt;img&gt;Figure 5: AI-triaged incidents with verdicts, security comments, and deep links back to the specific Purview DLP incidents — ready for bulk action or individual review.&lt;/img&gt;&lt;img&gt;Figure 6: The remediation plan binds a scoped set of incidents to explicit actions: tag incidents, update status, notify affected users. All live actions require deliberate confirmation before execution.&lt;/img&gt;
&lt;P&gt;After an explicitly approved incident update, the privacy-safe Detection Assurance rationale appears in the Microsoft Defender incident activity timeline — making outcomes easy to explain without requiring a separate incident queue.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Useful AI without an uncontrolled data boundary&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Evidence is redacted by default. Classification boundaries fail closed. Microsoft Graph writes remain explicitly controlled.&lt;/P&gt;
&lt;P&gt;The default assessment mode excludes detected values, identities, recipients, content names, senders, and subjects from the AI payload. Departments are resolved locally before identity redaction — the model receives the department, not the person used to resolve it. Sensitive-value analysis, when needed, requires separate configuration, a confirmation phrase, DPAPI protection, and an explicit per-run choice.&lt;/P&gt;
&lt;P&gt;Live Graph actions (incident updates, email, Teams notifications) are disabled by default and require server enablement, an exact confirmation phrase, bounded targets, and an execution ledger. Dry-run is always the first gate.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Model routing&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;The workbench uses a luna model for high-volume event analysis and triage, and a Terra model for generating reports, implementation plans, and next-step recommendations. All AI is grounded in Purview data — no external training, no hosted data path, no opaque execution.&lt;/P&gt;
&lt;P&gt;Get started&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Turn your next DLP review into a measurable control cycle&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Built on the newly released Microsoft Purview DLP API, this open-source workbench is a starting point any customer can build from. Local-first, transparent, and ready to adapt to your organization.&lt;/P&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://github.com/OfficeDev/O365-ActivityFeed-AzureFunction/tree/master/Dataworkbench" target="_blank" rel="noopener"&gt;Explore the project →&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2026 19:54:05 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/from-dlp-alert-volume-to-measurable-detection-assurance/ba-p/4545973</guid>
      <dc:creator>Jon_Nordstrom</dc:creator>
      <dc:date>2026-09-15T19:54:05Z</dc:date>
    </item>
    <item>
      <title>Is it possible to search for emoji usage in Teams?</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-purview/is-it-possible-to-search-for-emoji-usage-in-teams/m-p/4556731#M2940</link>
      <description>&lt;P&gt;I need to look into sending emojis in Teams; is it possible?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2026 13:23:46 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-purview/is-it-possible-to-search-for-emoji-usage-in-teams/m-p/4556731#M2940</guid>
      <dc:creator>anderson2510</dc:creator>
      <dc:date>2026-09-15T13:23:46Z</dc:date>
    </item>
    <item>
      <title>Unity Catalog and Data Map not showing in Chrome</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-purview/unity-catalog-and-data-map-not-showing-in-chrome/m-p/4556410#M2938</link>
      <description>&lt;P&gt;I don't know if this is the right place to post this question, but I haven't been able to find an answer elsewhere. My organization is beginning to use Purview and are still trying to figure out how all of it works. I am able to log in to our Purview tenant from Microsoft Edge with no problem. When I log in I see the Unity Catalog and Data Map features and can use them. However, when I log in to Purview from Google Chrome, apparently with the same account and to the same tenant ID, I don't see either of Unity Catalog or Data Map. Could there be some obscure difference in how I am logging in through Edge and Chrome? If so, I'm not seeing it in the Account properties.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2026 20:24:22 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-purview/unity-catalog-and-data-map-not-showing-in-chrome/m-p/4556410#M2938</guid>
      <dc:creator>DA_Larry1558</dc:creator>
      <dc:date>2026-09-14T20:24:22Z</dc:date>
    </item>
    <item>
      <title>Please fix your spoofing issues with From: email address removed for privacy reasons</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/please-fix-your-spoofing-issues-with-from-email-address-removed/m-p/4556396#M10029</link>
      <description>&lt;P&gt;Feel free to reach out for full headers.&amp;nbsp; Your admin email address is being spoofed and this isn't the first time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From: email address removed for privacy reasons&lt;BR /&gt;To: omitted&lt;BR /&gt;Subject: 459 USD payment received successfully.Please check your transaction&lt;BR /&gt;details at payinfogeek.us OR =?utf-8?b?w6fDoGxs?= 8133804297 account email&lt;BR /&gt;verification code&lt;/P&gt;&lt;P&gt;X-MXTHUNDER-RF-AuthResults: bolt105b.mxthunder.net;&lt;BR /&gt;dkim=pass header.d=microsoftonline.com header.s=s1024 header.b=iqnvyKM7;&lt;BR /&gt;dmarc=pass (policy=reject) header.from=microsoftonline.com;&lt;BR /&gt;spf=pass (bolt105b.mxthunder.net: domain of email address removed for privacy reasons designates 40.93.14.108 as permitted sender) smtp.mailfrom=email address removed for privacy reasons&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2026 19:54:05 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/please-fix-your-spoofing-issues-with-from-email-address-removed/m-p/4556396#M10029</guid>
      <dc:creator>ProgentCT</dc:creator>
      <dc:date>2026-09-14T19:54:05Z</dc:date>
    </item>
    <item>
      <title>Windows, TLS 1.3 and Post Quantum Crypto FAQ</title>
      <link>https://techcommunity.microsoft.com/t5/post-quantum-crypto-tech-blog/windows-tls-1-3-and-post-quantum-crypto-faq/ba-p/4556389</link>
      <description>&lt;H2&gt;Q01: What is the real threat?&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;A:&lt;/STRONG&gt; The threat is that attackers can collect encrypted network data and then break the asymmetric cryptography (RSA/ECC/DH) used to protect bulk data encryption keys (AES) once cryptographically relevant quantum computers come online. This is known as Harvest Now, Decrypt Later (HNDL).&lt;/P&gt;
&lt;H2&gt;Q02: Do I need to use TLS 1.3 for PQ support?&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;A:&lt;/STRONG&gt; Yes. Earlier versions of TLS, including TLS 1.0, TLS 1.1, and TLS 1.2, do not and will not support post-quantum key establishment.&lt;/P&gt;
&lt;H2&gt;Q03: Does enabling TLS 1.3 give me hybrid PQ support?&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;A:&lt;/STRONG&gt; No. By default, you will get ‘classic’ crypto algorithms. You must enable the PQ algorithms; this is explained later.&lt;/P&gt;
&lt;H2&gt;Q04: What Windows OS version must I use to get TLS 1.3 and post-quantum support?&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;A:&lt;/STRONG&gt; TLS Hybrid Key Exchange using ML-KEM groups is available on Windows 11 starting with update&amp;nbsp;&lt;A href="https://support.microsoft.com/en-us/servicing/os/windows-11/2026/05/may-26-2026-kb5089573-os-builds-26200-8524-and-26100-8524-preview" target="_blank"&gt;KB5089573&lt;/A&gt;&amp;nbsp;for 24H2 and 25H2 and&amp;nbsp;&lt;A href="https://support.microsoft.com/en-us/servicing/os/windows-11/2026/06/june-23-2026-kb5095091-os-build-28000-2340-preview" target="_blank"&gt;KB5095091&lt;/A&gt;&amp;nbsp;for 26H1.&lt;/P&gt;
&lt;P&gt;For Windows Server 2025 use the patch from &lt;A href="https://support.microsoft.com/en-us/servicing/os/windows-server/2026/07/july-14-2026-kb5099536-os-build-26100-33158" target="_blank"&gt;July 14, 2026-KB5099536 (OS Build 26100.33158)&lt;/A&gt;&lt;/P&gt;
&lt;H2&gt;Q05: What is hybrid crypto in TLS 1.3?&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;A:&lt;/STRONG&gt; Hybrid crypto establishes cryptographic keys by combining elliptic-curve cryptography with post-quantum cryptography, allowing the client and server to use both algorithms during the TLS 1.3 key establishment. It’s a hedge in case the PQ cryptography is broken.&lt;/P&gt;
&lt;H2&gt;Q06: What crypto is used in hybrid?&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;A:&lt;/STRONG&gt; Like all crypto in TLS, this is flexible; however, the most common hybrid crypto for web browser-based key establishment is X25519_MLKEM768 which combines the classic X25519 Elliptic Curve with post-quantum ML-KEM.&lt;/P&gt;
&lt;H2&gt;Q07: What is ML-KEM?&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;A:&lt;/STRONG&gt; ML‑KEM (Module-Lattice Key Encapsulation Mechanism) is the new quantum-resistant method for securely establishing cryptographic keys between hosts. It is defined in &lt;A href="https://csrc.nist.gov/pubs/fips/203/ipd" target="_blank"&gt;FIPS 203&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;Q08: Is hybrid TLS 1.3 enabled in Windows today?&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;A:&lt;/STRONG&gt; No not by default; you must enable it. If you use Group Policy, you can set the policy there. If the machine does not have GP, then you can use the following from an elevated PowerShell prompt:&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;Enable-TlsEccCurve -Name "X25519_MLKEM768" -Position 0&lt;/LI-CODE&gt;
&lt;P&gt;Note that -Position 0 is important as it places the hybrid group X25519_MLKEM768 at the top of the preferred group list. If you do not do this, you might not negotiate to the hybrid PQC group.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;IMPORTANT: &lt;/STRONG&gt;Note that Group Policy will override this setting, so don’t mix-n-match! If you see your group ordering change after calling the PS cmdlet, it's probably GP coming in and overriding the setting.&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Q09: In the prior answer, you used the word ‘group’ what is a group?&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;A:&lt;/STRONG&gt; In TLS 1.3, a "group" is simply the method (or algorithm) that the client and server agree to use to securely establish keys during the connection. Examples include X25519 (the most common Elliptic Curve TLS 1.3 group) or the newer hybrid X25519_MLKEM.&lt;/P&gt;
&lt;P&gt;As a side note, the word "group" isn't arbitrary - it comes from the underlying algebra (elliptic-curve groups, finite-field multiplicative groups). It's mathematically precise; it's just opaque to anyone who isn't thinking about group theory! However, ML-KEM isn't built on a group at all - its hardness comes, in part, from lattices.&lt;/P&gt;
&lt;H2&gt;Q10: Is a group the same as a ciphersuite in TLS 1.3?&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;A:&lt;/STRONG&gt; No, a group is not the same as a ciphersuite in TLS 1.3. The group is how the client and server agree on secret keys. The ciphersuite is how they use secret keys to encrypt and protect the traffic. They work together in a TLS 1.3 handshake, but they are two separate parts&lt;/P&gt;
&lt;H2&gt;Q11: Are there other groups I should know about?&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;A:&lt;/STRONG&gt; Yes. There are three common hybrid groups; you have already met X25519_MLKEM768, but there is also SecP256r1_MLKEM768 and SecP384r1_MLKEM1024.&lt;/P&gt;
&lt;H2&gt;Q12: What group should I use?&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;A:&lt;/STRONG&gt; Follow your organization’s cryptographic policy and required assurance profile. For browser interoperability, prefer X25519_MLKEM768 where supported and place it ahead of other groups. For regulated environments, use a hybrid group and implementation permitted by the applicable policy and validated cryptographic module; this may require SecP256r1_MLKEM768 or SecP384r1_MLKEM1024 instead of X25519_MLKEM768.&lt;/P&gt;
&lt;H2&gt;Q13: If there is TLD 1.3 with hybrid crypto, is there a version that is NOT hybrid?&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;A:&lt;/STRONG&gt; Yes, it’s called ‘pure’, and that is where rather than using ECC+PQC, you use just PQC; for example instead of X25519+MLKEM768, you use only MLKEM768 or MLKEM1024 if CNSA 2.0 compliance is in scope. Some customers may eventually require this. You can read about the MLKEM-only Windows schannel update here&amp;nbsp;&lt;A href="https://support.microsoft.com/en-us/servicing/os/windows-11/2026/08/kb5120998-windows-11-24h2-25h2-update" target="_blank"&gt;August 27, 2026—KB5120998 (OS Builds 26200.9278 and 26100.9278) Preview | Microsoft Support&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;Q14: What’s CNSA 2.0?&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;A:&lt;/STRONG&gt; CNSA 2.0, the Commercial National Security Algorithm Suite 2.0, is the NSA's set of quantum-resistant cryptographic algorithm requirements for U.S. National Security Systems. It updates CNSA 1.0 by introducing post-quantum algorithms intended to protect classified and other national-security-sensitive information against both classical and future quantum attacks. It is important because transitioning cryptographic infrastructure takes years, while adversaries can collect encrypted data now and attempt to decrypt it later. Although its formal scope is National Security Systems, CNSA 2.0 also provides vendors and other organizations with a concrete high-assurance target for planning, product development, and post-quantum migration.&lt;/P&gt;
&lt;P&gt;The list of algorithms that affect TLS includes:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Key establishment: ML-KEM-1024 only (not 512, not 768)&lt;/LI&gt;
&lt;LI&gt;Digital signatures: ML-DSA-87 only (not 44, not 65)&lt;/LI&gt;
&lt;LI&gt;Hashing: SHA-384 or SHA-512 only&lt;/LI&gt;
&lt;LI&gt;Symmetric encryption: AES-256 only&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Q15: How do I test if my server supports TLS 1.3?&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;A:&lt;/STRONG&gt; See Appendix A.&lt;/P&gt;
&lt;H2&gt;Q16: How do I test if my server supports TLS 1.3 and PQC?&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;A:&lt;/STRONG&gt; See Appendix B.&lt;/P&gt;
&lt;H2&gt;Q17: How do I use Wireshark to determine if my server supports TLS 1.3 and PQC?&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;A:&lt;/STRONG&gt; See Appendix C.&lt;/P&gt;
&lt;H2&gt;Q18: Do both the client and server need to support hybrid PQC TLS?&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;A:&lt;/STRONG&gt; Yes.&lt;/P&gt;
&lt;H2&gt;Q19: What happens if one side does not support hybrid PQC TLS?&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;A:&lt;/STRONG&gt; If one side does not support hybrid PQC TLS, the connection may still succeed using another mutually supported TLS 1.3 key establishment group, for example X25519, but it will not use hybrid PQC protection. The exact behavior depends on the client, server, and TLS configuration.&lt;/P&gt;
&lt;H2&gt;Q20: How do I know if my client, such as a browser, supports PQC TLS?&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;A:&lt;/STRONG&gt; Point your application or browser at a tool like this &lt;A href="https://pqc.ninja/api/browsertest/" target="_blank"&gt;https://pqc.ninja/api/browsertest/&lt;/A&gt; it will output something like:&lt;/P&gt;
&lt;LI-CODE lang="json"&gt;{
  "negotiated_curve": "X25519MLKEM768",
  "offered_curves": "X25519MLKEM768:X25519:prime256v1:secp384r1",
  "negotiated_cipher": "TLS_AES_256_GCM_SHA384",
  "offered_ciphers": "TLS_AES_128_GCM_SHA256:TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256",
  "alpn_protocol": "h3",
  "protocol": "TLSv1.3"
}&lt;/LI-CODE&gt;
&lt;P&gt;You can see that the browser and server negotiated to use the X25519_MLKEM768 hybrid group and the browser supports this along with two classic (ie; non-PQC) curves, prime256v1 and secp384r1.&lt;/P&gt;
&lt;H2&gt;Q21: Are PQC (ML-DSA) certificates required for TLS 1.3?&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;A:&lt;/STRONG&gt; No, not for hybrid PQC key establishment. PQC certificates are a separate part of the post quantum migration and relate to authentication and digital signatures. Hybrid key establishment protects the session key agreement; PQC certificates will protect the certificate signature and authentication path.&lt;/P&gt;
&lt;H2&gt;Q22: Following the previous question, why does the server still use a classic certificate if the key negotiation is post-quantum?&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;A:&lt;/STRONG&gt; This is by design. We need to secure data in transit first and foremost, since that represents the most immediate quantum threat. An adversary can perform a harvest-now, decrypt-later attack by storing encrypted communications today and waiting until quantum computers are available to decrypt them - any data being transmitted currently needs quantum-safe key exchange to be secure in the future. Authentication, however, does not have that same window of exposure: to perform a successful spoof via certificate misuse, an attacker would need a cryptographically meaningful quantum computer at the time of the session - they do not get to use it later. As we don't have that ability currently, by securing key exchange first we mitigate the most imminent threat while the ecosystem around it (CAs, trust anchors, relying parties, etc.) works towards supporting PQC signatures.&lt;/P&gt;
&lt;H2&gt;Q23: Is there a performance impact from hybrid PQC TLS?&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;A:&lt;/STRONG&gt; We will provide more stats as they become available, but current details look good; X25519 vs X25519-MLKEM768 is about a 3%-6% latency delta and less than 1% CPU hit using Azure Linux, nginx + OpenSSL + SymCrypt and similar stats using https.sys on Windows Server 2025.&lt;/P&gt;
&lt;H2&gt;Q24: Should I enable this on internet-facing services first or internal services first?&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;A:&lt;/STRONG&gt; Start with controlled pilots, then prioritize services that protect long-lived or high-value confidential data. Internet-facing services may provide broader coverage, but internal services can be easier to test and control. The right rollout order should balance risk, compatibility, visibility, and operational readiness.&lt;/P&gt;
&lt;H2&gt;Q25: What logging or telemetry should I capture during testing?&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;A:&lt;/STRONG&gt; Capture the client and server IP addresses, the negotiated key-establishment group, the negotiated cipher suite, and the TLS protocol version for every test connection. Also record whether the handshake succeeded or failed and correlate each result with a timestamp or connection identifier. This makes it possible to confirm that TLS 1.3 and the expected hybrid PQC group were negotiated.&lt;/P&gt;
&lt;P&gt;Below is a screen shot from a tool I have on GitHub that shows most of this passively in Windows using schannel and pktmon. The code is here &lt;A href="https://github.com/x509cert/schannel-cap" target="_blank"&gt;x509cert/schannel-cap&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;H1&gt;Appendix A - Testing for TLS 1.3&lt;/H1&gt;
&lt;P&gt;You can use tools like OpenSSL, PowerShell or a modern browser to test a server to determine if it supports TLS 1.3.&lt;/P&gt;
&lt;P&gt;Let’s look at each.&lt;/P&gt;
&lt;H2&gt;OpenSSL&lt;/H2&gt;
&lt;P&gt;Use the following from a Windows or Linux command-line, obviously replacing the IP address and port number for your target service.&lt;/P&gt;
&lt;LI-CODE lang=""&gt;openssl s_client -connect 192.168.1.1:443 -tls1_3 -brief&lt;/LI-CODE&gt;
&lt;P&gt;Success is when you see:&lt;/P&gt;
&lt;LI-CODE lang=""&gt;CONNECTION ESTABLISHED
Protocol version: TLSv1.3&lt;/LI-CODE&gt;
&lt;H2&gt;PowerShell 7+&lt;/H2&gt;
&lt;P&gt;Save the following as Test-Tls13.ps1.&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;param(
    [Parameter(Mandatory)][string]$IpAddress,
    [Parameter(Mandatory)][int]$Port
)

$tcp = New-Object System.Net.Sockets.TcpClient
$tcp.Connect($IpAddress, $Port)
$tls = New-Object System.Net.Security.SslStream($tcp.GetStream(), $false)

try {
    $tls.AuthenticateAsClient($IpAddress, $null, [System.Security.Authentication.SslProtocols]::Tls13, $false)
    Write-Host "Connected: $($tls.SslProtocol), cipher $($tls.NegotiatedCipherSuite)" -ForegroundColor Green
}

catch {
    Write-Host "TLS 1.3 handshake failed: $($_.Exception.Message)" -ForegroundColor Red
}

finally {
    $tls.Dispose()
    $tcp.Dispose()
}&lt;/LI-CODE&gt;
&lt;P&gt;You can call this using positional syntax:&lt;/P&gt;
&lt;LI-CODE lang=""&gt;.\Test-Tls13.ps1 192.168.1.1 443&lt;/LI-CODE&gt;
&lt;P&gt;Or using parameters:&lt;/P&gt;
&lt;LI-CODE lang=""&gt;.\Test-Tls13.ps1 -IpAddress "192.168.1.1" -Port 443&lt;/LI-CODE&gt;
&lt;P&gt;Success is indicated by output like this:&lt;/P&gt;
&lt;LI-CODE lang=""&gt;Connected: Tls13, cipher TLS_AES_256_GCM_SHA384&lt;/LI-CODE&gt;
&lt;H2&gt;Edge and Chrome Browsers&lt;/H2&gt;
&lt;P&gt;Current versions of Edge and Chrome support hybrid TLS 1.3. After you make a connection to the server, click the ellipsis in the top right (…) -&amp;gt; More Tools -&amp;gt; Developer Tools -&amp;gt; Security.&lt;/P&gt;
&lt;P&gt;If you don’t see the security option:&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;Then click on the + symbol and add the Security tab.&lt;/P&gt;
&lt;P&gt;Now you will see the connection details, if you see TLS 1.3, then the server and client are connected with TLS 1.3. In the example below, the connection is also using X25519MLKEM, so the connection is not just using TLS 1.3, it’s using TLS 1.3 in PQ hybrid.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;H1&gt;Appendix B – Testing for TLS 1.3 and PQC&lt;/H1&gt;
&lt;P&gt;The simplest and most reliable way to test a server to determine if it supports TLS 1.3 and PQC, is to use the following OpenSSL command-line:&lt;/P&gt;
&lt;LI-CODE lang="shell"&gt;.\openssl s_client -connect 127.0.0.1:8443 -tls1_3 -brief&lt;/LI-CODE&gt;
&lt;P&gt;You will see output like this:&lt;/P&gt;
&lt;LI-CODE lang=""&gt;Connecting to 127.0.0.1
CONNECTION ESTABLISHED
Protocol version: TLSv1.3
Ciphersuite: TLS_AES_256_GCM_SHA384
Peer certificate: CN=localhost
Hash used: SHA256
Negotiated TLS1.3 group: X25519MLKEM768&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The group information, in this case X25519MLKEM is at the bottom, this indicates that hybrid PQC is in place for this connection.&lt;/P&gt;
&lt;H1&gt;Appendix C – Wireshark Filtering&lt;/H1&gt;
&lt;P&gt;Wireshark is commonly used to determine what data is travelling across a network. You can determine if a connection uses hybrid groups using the following steps:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Start Wireshark,&lt;/LI&gt;
&lt;LI&gt;Perform some sample network connections (like make an API call or load a page in a browser),&lt;/LI&gt;
&lt;LI&gt;Stop the collection&lt;/LI&gt;
&lt;LI&gt;Enter the following in the filter window: &lt;STRONG&gt;&lt;SPAN class="lia-text-color-15"&gt;tls.handshake.extensions_key_share_group&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Click on the packet of interest and scroll to the &lt;STRONG&gt;&lt;SPAN class="lia-text-color-15"&gt;Extension: key_share&lt;/SPAN&gt;&lt;/STRONG&gt; line.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;You will see something like this:&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;The line in this example shows that the connection uses X25519MLKEM768 which is a hybrid PQC group.&lt;/P&gt;
&lt;P&gt;Note, you will often see TLS 1.2 used as the protocol version, Wireshark explains why:&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;The TLS Version field is a deprecated field, so ignore it!&lt;/P&gt;
&lt;H1&gt;Thanks!&lt;/H1&gt;
&lt;P&gt;As usual, a big thanks to the people who helped write and edit this document:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Jessica Krynitsky - Windows Security&lt;/LI&gt;
&lt;LI&gt;Andrei Popov - Windows Security&lt;/LI&gt;
&lt;LI&gt;Aabha Thipsay - Windows Security&lt;/LI&gt;
&lt;LI&gt;Vick Mukherjeee - Azure Security&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 14 Sep 2026 19:37:05 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/post-quantum-crypto-tech-blog/windows-tls-1-3-and-post-quantum-crypto-faq/ba-p/4556389</guid>
      <dc:creator>MichaelHoward-MSFT</dc:creator>
      <dc:date>2026-09-14T19:37:05Z</dc:date>
    </item>
    <item>
      <title>Public Preview: Multi-account support for Microsoft Sentinel codeless connectors</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/public-preview-multi-account-support-for-microsoft-sentinel/ba-p/4544380</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Security teams rarely have just one of anything. Most SOCs run separate production, staging, and development accounts. Large enterprises segment by region, business unit, or brand. And managed security service providers (MSSPs) watch over many customers at once.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; Traditionally, ISVs have used the following configuration – one connector for one product (or workspace), over as many instances of that product as are implemented. We set out to simplify and streamline that experience.&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Today we're excited to announce the public preview of &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;multi-account&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; support for codeless connectors&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; in Microsoft Sentinel. A single connector built on the &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/sentinel/isv/create-codeless-connector" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="auto"&gt;Codeless Connector Framework (CCF)&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; can now support multiple, independently deployable connections in the same workspace, each shown in one unified list so that one connector scales to however many accounts a customer runs.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;335551550&amp;quot;:2,&amp;quot;335551620&amp;quot;:2}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;What's new&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The current CCF separates a connector's user interface from its connection configuration. That separation is what makes multiple connections possible. With the multi-account pattern, a connector provides:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;A unified connections list:&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; Every connection appears as its own row, labeled with the details that identify it such as account name, tenant ID, or environment (as seen in the screenshot above).&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;An &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Add connection&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; experience:&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; Users add another connection through a guided&amp;nbsp; form without disturbing the connections that already exist.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Independent lifecycle per connection:&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; Each connection is deployed, edited, and deleted on its own. Removing one leaves the others untouched.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Shared, efficient ingestion:&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; All connections flow through the same data collection rule and land in the same table, so adding connections doesn't multiply your ingestion plumbing.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The result is a clean, predictable way to bring many sources of the same product into one Sentinel workspace.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;In brief, here’s how it looks in practice: Under the hood, the connector definition that renders the UI is shared, and so are the ingestion resources — the data collection rule, the data collection endpoint, and the destination table. What's created per connection is a single lightweight data connector resource with a unique name, tagged with the metadata that labels it in the grid. That unique name is what lets connections coexist instead of overwriting one another.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft recommends all new CCF connectors support multi-account where appropriate. For a full walkthrough, annotated JSON, and an authoring checklist, see our &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/azure/sentinel/isv/multi-account-ccf-connector" target="_blank" rel="noopener"&gt;MS Learn documentation&lt;/A&gt; on the topic&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/sentinel/isv/multi-account-ccf-connector" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Use Cases for having your Sentinel Connector utilize the Multi Account capabilities&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Multiple accounts for an ISV&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:1,&amp;quot;335551620&amp;quot;:1,&amp;quot;335559737&amp;quot;:0,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Different regional accounts &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:1,&amp;quot;335551620&amp;quot;:1,&amp;quot;335559737&amp;quot;:0,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Developer/QA Accounts&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:1,&amp;quot;335551620&amp;quot;:1,&amp;quot;335559737&amp;quot;:0,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Pre-Production Cloud Environments&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:1,&amp;quot;335551620&amp;quot;:1,&amp;quot;335559737&amp;quot;:0,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;MSSP &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:1,&amp;quot;335551620&amp;quot;:1,&amp;quot;335559737&amp;quot;:0,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Multiple customers streaming logs to same Sentinel Instance&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:1,&amp;quot;335551620&amp;quot;:1,&amp;quot;335559737&amp;quot;:0,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The pattern fits the everyday shape of security operations. Whether you are a team consolidating production and non-production accounts for one product, or an MSSP centralizing several customers' sources in a shared workspace, you now have one connector&amp;nbsp;with&amp;nbsp;many connections, and&amp;nbsp;just&amp;nbsp;one place to investigate.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:1,&amp;quot;335551620&amp;quot;:1,&amp;quot;335559685&amp;quot;:0,&amp;quot;335559737&amp;quot;:0,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Featured Early Adopter&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;One company that has already implemented this feature is&amp;nbsp;Semperis, via&amp;nbsp;their&amp;nbsp;Lightning connector.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="lia-table-wrapper styles_table-responsive__MW0lN"&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-border-style-double" border="1" style="width: 97.5%; height: 310px; border-width: 1px;"&gt;&lt;colgroup&gt;&lt;col style="width: 47.9417%" /&gt;&lt;col style="width: 52.0259%" /&gt;&lt;/colgroup&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-align-center"&gt;&lt;img /&gt;&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://securitystore.microsoft.com/solutions/semperis.azure-sentinel-solution-semperislightning" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Semperis Lightning&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&lt;SPAN data-contrast="auto"&gt;Semperis Lightning integrates with Microsoft Sentinel to deliver deep visibility into identity&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;centric risk across Active Directory and Microsoft Entra environments. The connector ingests identity security telemetry such as indicators of exposure, Tier 0 assets, and attack path insights from multiple Semperis accounts into Sentinel, enabling security teams to correlate identity risks with broader security signals. By bringing rich identity context into Sentinel analytics, hunting, and investigations, this integration helps organizations detect, prioritize, and respond to identity&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;driven attacks more effectively across hybrid identity infrastructures.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And here is what Engineering Team Lead at Semperis, David Bagdasarian had to say about the new Multi-Account feature:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="lia-table-wrapper styles_table-responsive__MW0lN"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Get started&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;If you are a security professional looking to take advantage of this feature across your own environments, look for connectors that present a connections list and an &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Add connection&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; action and bring all your sources into one workspace.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;If you are an ISV interested in implementing multi-account functionality in your Microsoft Sentinel CCF connector, review the MS Learn documentation as a first step. If additional assistance is needed, the App Assure team is available to provide expert guidance for building and publishing your multi-account connector. Reach out to us via &lt;/SPAN&gt;&lt;A href="https://aka.ms/appassurerequest" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;our intake form&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Recent Microsoft Sentinel Public Preview Announcements&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoftsentinelblog/public-preview-announcement-empower-real-time-security-with-microsoft-sentinel%E2%80%99s/4483884" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Public Preview Announcement: Empower Real-Time Security with Microsoft Sentinel’s CCF Push Feature | Microsoft Community Hub&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoft-security-blog/accelerate-connectors-development-using-ai-agent-in-microsoft-sentinel/4507019" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Accelerate connectors development using AI agent in Microsoft Sentinel | Microsoft Community Hub&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoftsentinelblog/extending-sentinel-data-integration-azure-blob-storage-support-for-ccf-connector/4516896?" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Extending Sentinel Data Integration: Azure Blob Storage Support for CCF Connectors | Microsoft Community Hub&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoftsentinelblog/public-preview-nested-api-support-comes-to-microsoft-sentinel-ccf/4537026" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Public Preview: Nested API Support Comes to Microsoft Sentinel CCF | Microsoft Community Hub&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 14 Sep 2026 18:13:41 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/public-preview-multi-account-support-for-microsoft-sentinel/ba-p/4544380</guid>
      <dc:creator>MitchellGulledge</dc:creator>
      <dc:date>2026-09-14T18:13:41Z</dc:date>
    </item>
    <item>
      <title>Simplify Employee Identity Lifecycle with HiBob and Microsoft Entra</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/simplify-employee-identity-lifecycle-with-hibob-and-microsoft/ba-p/4554510</link>
      <description>&lt;P&gt;Every workforce transition creates an identity moment that your IT team must get right. That’s why we’re excited to announce the general availability of HiBob’s native integration with Microsoft Entra. It helps you turn trusted workforce changes in HiBob into governed identity actions, so employees get the right access across on-premises and cloud apps as they join, change roles, or leave.&lt;/P&gt;
&lt;H2&gt;Why this matters&lt;/H2&gt;
&lt;P&gt;New hires need accounts and the right access from day one. When employees change roles, their access needs to change with them. And when someone leaves, that access needs to be removed quickly. Manual handoffs, tickets, and custom integrations slow these moments down, create more work for IT, and add unnecessary security risk. Connecting trusted workforce data in HiBob with Microsoft Entra helps you securely govern and automate the process, reducing the back-and-forth.&lt;/P&gt;
&lt;P&gt;If your organization uses HiBob, this integration gives your HR and IT teams a more connected way to manage identity changes across hybrid environments. HR keeps workforce information current in HiBob, while IT decides how Microsoft Entra applies mappings, scoping rules, provisioning policies, and governance controls. Together, the systems turn workforce events into consistent identity actions - reducing manual handoffs, speeding up lifecycle processes, and creating a stronger foundation for identity governance.&lt;/P&gt;
&lt;H2&gt;Modernize identity without forcing a disruptive migration&lt;/H2&gt;
&lt;P&gt;Many organizations are moving applications and infrastructure to the cloud while still supporting on-premises directories. Modernizing identity does not mean replacing everything at once. The HiBob integration works with the environment you have today and helps you move toward a more cloud-managed model over time.&lt;/P&gt;
&lt;P&gt;This integration advances a broader Microsoft Entra strategy: bring identity lifecycle control, visibility, and governance into a unified cloud service. Microsoft Entra can serve as the control plane for workforce identity changes across hybrid and cloud environments, while IT retains control over which users are in scope, how attributes are mapped, and what actions are performed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Figure 1: HR-driven identity lifecycle flow from HiBob through Microsoft Entra.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Choose the integration that matches your identity environment&lt;/H2&gt;
&lt;P&gt;HiBob Marketplace offers two purpose-built integrations. Choose the one that fits where your organization is in its identity modernization journey.&lt;/P&gt;
&lt;H3&gt;For hybrid identities&lt;/H3&gt;
&lt;P&gt;Use the &lt;A href="https://www.hibob.com/marketplace/adhybrid/overview" target="_blank" rel="noopener"&gt;Windows Server Active Directory (Hybrid) integration&lt;/A&gt; if employees still need identities in an on-premises directory. Microsoft Entra cloud provisioning sends the configured changes through the Microsoft Entra provisioning agent, while Microsoft Entra keeps provisioning visibility and governance in one place.&lt;/P&gt;
&lt;H3&gt;For cloud-only identities&lt;/H3&gt;
&lt;P&gt;Use the &lt;A href="https://www.hibob.com/marketplace/azure-provisioning/overview" target="_blank" rel="noopener"&gt;Microsoft Entra ID integration&lt;/A&gt; if you manage identities directly in the cloud. This integration automatically updates Microsoft Entra user data when changes occur in HiBob.&lt;/P&gt;
&lt;H2&gt;How the integration works&lt;/H2&gt;
&lt;P&gt;The end-to-end flow is simple:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;When an employee record changes, HiBob sends the relevant workforce data to Microsoft Entra.&lt;/LI&gt;
&lt;LI&gt;Microsoft Entra applies provisioning attribute mappings and scoping rules configured by IT.&lt;/LI&gt;
&lt;LI&gt;Microsoft Entra ID Governance can then trigger &lt;A href="https://learn.microsoft.com/entra/id-governance/what-are-lifecycle-workflows" target="_blank" rel="noopener"&gt;lifecycle workflows&lt;/A&gt;, assign birthright access through &lt;A href="https://learn.microsoft.com/entra/id-governance/entitlement-management-overview" target="_blank" rel="noopener"&gt;entitlement management&lt;/A&gt;, and initiate &lt;A href="https://learn.microsoft.com/entra/id-governance/access-reviews-overview" target="_blank" rel="noopener"&gt;access reviews&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This model keeps identity changes HR-driven, IT-controlled, and cloud-managed. HR keeps employee records current in HiBob, while IT controls how Microsoft Entra processes each change. As you use Microsoft Entra &lt;A href="https://learn.microsoft.com/entra/identity/hybrid/user-source-of-authority-overview" target="_blank" rel="noopener"&gt;source of authority capabilities&lt;/A&gt; to move identities toward cloud management, governance remains centralized throughout the transition.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;EM&gt;"Workforce changes have consequences far beyond HR - from identity and access to the systems that keep the business running. Our collaboration with Microsoft connects trusted employee data in HiBob with Microsoft Entra ID and Active Directory, giving HR and IT a more coordinated way to manage those changes as organizations grow - without compromising control."&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Ido Stern&lt;/STRONG&gt;, Senior Vice President, Tech Platform &amp;amp; Engineering Excellence, HiBob&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;Turn workforce changes into governed lifecycle actions&lt;/H2&gt;
&lt;P&gt;When someone joins, employee and job information from HiBob can initiate identity creation in your organization’s hybrid environment. Lifecycle Workflows can automate onboarding tasks, and entitlement management can assign appropriate access through access package policies.&lt;/P&gt;
&lt;P&gt;When someone changes roles, updates to department, manager, job title, or location flow from HiBob to Microsoft Entra. Lifecycle Workflows and other governance policies can trigger tasks and help adjust access to reflect the employee’s current role and business context.&lt;/P&gt;
&lt;P&gt;When someone leaves, a change in employment status can initiate account deactivation and other configured Microsoft Entra lifecycle processes. Timely offboarding helps reduce lingering access to hybrid resources and cloud services.&lt;/P&gt;
&lt;H2&gt;Hear from an early customer&lt;/H2&gt;
&lt;P&gt;Novuna, a UK-based financial services company and HiBob customer, participated in the integration beta and shared its early perspective.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;EM&gt;"During beta testing, our experience with the Microsoft Entra hybrid integration has been very positive. It shows strong potential to support our hybrid identity architecture, simplify provisioning across our existing directory environment and Microsoft Entra ID, and give us a more governed foundation for the future. The integration will streamline joiner, mover, and leaver processes… with a single flow from HiBob through Microsoft Entra and into ServiceNow, where our IT teams can complete the downstream tasks."&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Chris&lt;/STRONG&gt;, Automation Lead, and &lt;STRONG&gt;Alex&lt;/STRONG&gt;, HR Systems Consultant, Novuna&lt;/EM&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;Try the integration&lt;/H2&gt;
&lt;P&gt;Choose the HiBob integration that matches your identity environment and start by automating a high-value process, such as employee onboarding or offboarding.&lt;/P&gt;
&lt;P&gt;Share your experience in the comments. You can also submit feedback or suggest new capabilities in the &lt;A href="https://feedback.azure.com/d365community/forum/22920db1-ad25-ec11-b6e6-000d3a4f0789" target="_blank" rel="noopener"&gt;Microsoft Entra feedback forum&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Udi Milo&lt;/P&gt;
&lt;P&gt;Partner PM, Access Management and Governance&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/in/udimilo/" target="_blank" rel="noopener"&gt;https://www.linkedin.com/in/udimilo/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/saas-apps/hibob-to-active-directory-user-provisioning-tutorial" target="_blank" rel="noopener"&gt;Configure HiBob to Active Directory hybrid user provisioning - Microsoft Entra ID | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/" target="_blank" rel="noopener"&gt;Microsoft Entra ID Governance documentation - Microsoft Entra ID Governance | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://microsoft.github.io/EntraIDGovernance-Training/" target="_blank" rel="noopener"&gt;Microsoft Entra ID Governance Training Hub&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Help prevent identity attacks, support least-privilege access, unify access controls, and improve user experiences with identity and network access solutions across on-premises and cloud environments.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;⁠&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 14 Sep 2026 18:17:58 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/simplify-employee-identity-lifecycle-with-hibob-and-microsoft/ba-p/4554510</guid>
      <dc:creator>udimilo</dc:creator>
      <dc:date>2026-09-14T18:17:58Z</dc:date>
    </item>
    <item>
      <title>Locking down PAWs internet access when GSA drops</title>
      <link>https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/locking-down-paws-internet-access-when-gsa-drops/ba-p/4553963</link>
      <description>&lt;P&gt;&lt;STRONG&gt;By: Christian Friedel-Jain - Sr. Security Consultant | James Noyce - Sr. Security Solution Engineer&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;H1&gt;&lt;SPAN class="lia-text-color-15"&gt;Introduction&lt;/SPAN&gt;&lt;/H1&gt;
&lt;P&gt;Privileged Access Workstations (PAWs) are among the most sensitive endpoints in any organization. A PAW, in most of our Microsoft consulting projects, exists to do one job safely: administer cloud services from a hardened device that is only ever allowed to reach a small, tightly controlled set of internet destinations. But an endpoint’s security posture is ultimately defined by its behavior under failure conditions.&lt;/P&gt;
&lt;P&gt;When we moved the internet access restriction for our PAW devices from a locally enforced restriction (&lt;EM&gt;more about that later&lt;/EM&gt;) to a solution based on Microsoft Global Secure Access (GSA), we immediately identified a gap under failure conditions – but first a quick grounding on the moving parts.&lt;/P&gt;
&lt;P&gt;Global Secure Access (&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/global-secure-access/overview-what-is-global-secure-access" target="_blank" rel="noopener"&gt;What is Global Secure Access?&lt;/A&gt;) is Microsoft’s umbrella term for Microsoft Entra Internet Access and Microsoft Entra Private Access — the components of Microsoft’s Security Service Edge solution. For a PAW device we are leveraging Microsoft Entra Internet Access as an identity centric secure web gateway solution to control exactly which internet destinations the workstation can reach, by applying a fine-grained set of rules and policies enforced through Conditional Access in Microsoft Entra.&lt;/P&gt;
&lt;P&gt;This configuration provides us better filtering capabilities, like web content filtering (&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-configure-web-content-filtering?tabs=microsoft-entra-admin-center" target="_blank" rel="noopener"&gt;Global Secure Access web content filtering&lt;/A&gt;) with TLS inspection (TLSi) (&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/global-secure-access/concept-transport-layer-security" target="_blank" rel="noopener"&gt;Global Secure Access transport layer security inspection&lt;/A&gt;) and additional features like Threat Intelligence (&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-configure-threat-intelligence" target="_blank" rel="noopener"&gt;Global Secure Access threat intelligence&lt;/A&gt;), but it comes also with a downside. Currently by default, if the GSA client encounters an issue or cannot connect to its required GSA edge services, the GSA client will fall back to a fail-open state, rather than to a fail-close state.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-background-color-16" border="1" style="width: 100%; border-width: 1px;"&gt;&lt;colgroup&gt;&lt;col style="width: 99.9074%" /&gt;&lt;/colgroup&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Difference between those two modes:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Fail-Open:&lt;/STRONG&gt; When a security or control mechanism fails, access is still allowed.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Fail-Close:&lt;/STRONG&gt; When the security or control mechanism fails, access is blocked.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This blog post covers above problem and showcases a solution we built, as part of our projects, to achieve a “Fail-Close” state rather than having the current “Fail-Open” behavior.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The enforcement of the “Fail-Close” solution we developed works at two independent layers, both are deployable through Microsoft Intune:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;A network layer:&lt;/STRONG&gt; Windows Defender Firewall network profiles, a rule set with &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/windows/security/operating-system-security/network-security/windows-firewall/dynamic-keywords" target="_blank" rel="noopener"&gt;Windows Firewall Dynamic Keywords&lt;/A&gt;, and event-driven automation — restricts the device internet access in the moment GSA’s tunnels or services drop.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;An identity layer:&lt;/STRONG&gt; an Intune custom compliance check paired with Conditional Access — denies the device access whenever the GSA client is missing or its services are not running.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Together, they help to make sure a failure that slips past one layer is still caught by the other.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;H1&gt;&lt;SPAN class="lia-text-color-15"&gt;From URL Lock Proxy to Global Secure Access&lt;/SPAN&gt;&lt;/H1&gt;
&lt;P&gt;Historically, we restricted internet access on PAW devices with the Windows Defender Firewall (for more details see here &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/security/privileged-access-workstations/privileged-access-deployment#set-rules-in-the-endpoint-protection-configuration-profile-for-microsoft-defender-firewall" target="_blank" rel="noopener"&gt;Microsoft Defender Firewall&lt;/A&gt;) and a “URL Lock Proxy” approach (and here &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/security/privileged-access-workstations/privileged-access-deployment#url-lock-proxy" target="_blank" rel="noopener"&gt;URL lock proxy&lt;/A&gt;): an allow-list of permitted URLs that blocked every outbound HTTP(S) connection except the ones required for:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Approved management portals,&lt;/LI&gt;
&lt;LI&gt;Authentication to Microsoft Entra ID,&lt;/LI&gt;
&lt;LI&gt;Management by Microsoft Intune, and&lt;/LI&gt;
&lt;LI&gt;Monitoring by Microsoft Defender for Endpoint.&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;img&gt;Previous internet access control via URL lock proxy.&lt;/img&gt;
&lt;P&gt;It worked, but it carried real limitations:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;No auditing of what was allowed or blocked,&lt;/LI&gt;
&lt;LI&gt;It did not scale and required a lot of wildcards to be used,&lt;/LI&gt;
&lt;LI&gt;A limited ruleset size — the size cap on the underlying registry key meant the solution simply could not grow, and&lt;/LI&gt;
&lt;LI&gt;It was not enterprise class.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Microsoft Global Secure Access with its component Entra Internet Access replaces the URL Lock Proxy configuration entirely. We are using dedicated firewall rules for the GSA client, to allow the client to reach the Entra Internet Access edge service. Through Entra Condition Access, a GSA Internet Access traffic profile (security profile) is applied which blocks all internet access except the specific FQDNs needed for approved management portals/platforms, Entra ID authentication, Intune, and Defender for Endpoint. HTTP and HTTPS traffic is evaluated and filtered within the GSA Edge service itself, and a request to a destination that is not on the allow-list is blocked with a simple “&lt;EM&gt;You can’t access this destination&lt;/EM&gt;” message.&lt;/P&gt;
&lt;P&gt;Additional features like filtering on URL level instead of FQDN, due to the use of TLSi, helped to remove most of the wildcards we had to use with the previous URL lock proxy approach.&lt;/P&gt;
&lt;P&gt;The result is:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Access and the access results are auditable,&lt;/LI&gt;
&lt;LI&gt;More granular and centrally managed rule set,&lt;/LI&gt;
&lt;LI&gt;And genuinely enterprise class.&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;img&gt;PAW internet access control via Entra Global Secure Access Internet Access&lt;/img&gt;&lt;img&gt;Result of blocked internet access&lt;/img&gt;
&lt;P class="lia-clear-both"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H1&gt;&lt;SPAN class="lia-text-color-15"&gt;The catch: Global Secure Access fails open&lt;/SPAN&gt;&lt;/H1&gt;
&lt;P&gt;GSA as the internet access restriction method is powerful, but it builds on the assumption that the GSA client is installed, running, and connected. When that assumption breaks, the client’s&amp;nbsp;&lt;STRONG&gt;&lt;U&gt;current&lt;/U&gt; &lt;/STRONG&gt;behavior is to fail open.&lt;/P&gt;
&lt;P&gt;As a result, the device ends up with unrestricted internet access whenever:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The GSA client is installed but cannot establish its tunnels with the GSA edge services (according to the Entra ID SLA this doesn’t happen that often – see &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-sla-performance#recent-worldwide-sla-performance" target="_blank" rel="noopener"&gt;Service Level Agreement performance for Microsoft Entra ID&lt;/A&gt;),&lt;/LI&gt;
&lt;LI&gt;The GSA client on the PAW is installed but suspended, or&lt;/LI&gt;
&lt;LI&gt;Its services are disabled, or&lt;/LI&gt;
&lt;LI&gt;The GSA client component is not installed at all on the PAW device.&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;img&gt;Current fail open behavior in case GSA internet access is not available&lt;/img&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;Left: normal operations - GSA internet access blocks access | Right: failure state - no filtering of internet access traffic&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On a regular end user device, the fail-open mode is a convenience. On a PAW it is exactly the wrong default: the very moment the protection drops away, the device becomes its most exposed. Therefore, we had to develop a solution to have a fail-close behavior.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;H1&gt;&lt;SPAN class="lia-text-color-15"&gt;The Fail-Close approach&lt;/SPAN&gt;&lt;/H1&gt;
&lt;P&gt;The core idea is deliberately simple, and it uses capability that already exists on most of the Windows devices: the Windows Defender Firewall network profiles (more details here &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/windows/security/operating-system-security/network-security/windows-firewall/#firewall-profiles" target="_blank" rel="noopener"&gt;Windows Firewall Network Profiles&lt;/A&gt;).&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;Two of the available firewall profiles are repurposed to act as separate operating modes&lt;/SPAN&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Private profile:&lt;/STRONG&gt; “unrestricted” HTTP(S). Internet access filtering is delegated to GSA Internet Access, so the firewall itself does not constrain destinations.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Public profile:&lt;/STRONG&gt; “restricted” HTTP(S). Outbound web traffic is limited to a mandatory set of FQDNs via Defender Dynamic Keywords and selected system processes — just enough for the device to stay managed and healthy.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;When the GSA client has successfully established its Internet access tunnel, the device is assigned the &lt;STRONG&gt;Private&lt;/STRONG&gt; network profile. If GSA fails, the Windows Firewall profile is automatically switched to the &lt;STRONG&gt;Public&lt;/STRONG&gt; network profile, restricting Internet access to essential destinations only. This profile transition implements the required &lt;STRONG&gt;fail-close&lt;/STRONG&gt; behavior.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;a id="community--1-NormalState" class="lia-anchor"&gt;&lt;/a&gt;&lt;SPAN class="lia-text-color-15 lia-linked-item"&gt;Normal state — Private profile&lt;/SPAN&gt;&lt;/H3&gt;
&lt;img&gt;Normal state - Windows Firewall profile "private" doesn't perform internet access restrictions, GSA internet access performs filtering&lt;/img&gt;
&lt;P&gt;As soon as the GSA client is running, connected to the GSA edge services and has established the Internet Access tunnel (step 1), the client writes a success event to the GSA event log (step 2) (Internet Access tunnel connected — Event ID 142)&lt;/P&gt;
&lt;P&gt;When that event occurs, a scheduled task (step 3) runs a PowerShell script (step 4) that:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Switches the device to the Private firewall network profile,&lt;/LI&gt;
&lt;LI&gt;Validates the state of all local GSA services, and&lt;/LI&gt;
&lt;LI&gt;Initiates an Intune custom compliance check (to perform additional validations).&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;In case all validates were successfully passed, the PowerShell script enforces the Private firewall profile (step 5) and GSA Internet Access is being used to filter the internet access (step 6).&lt;/P&gt;
&lt;H3&gt;&lt;a id="community--1-FailureState" class="lia-anchor"&gt;&lt;/a&gt;&lt;SPAN class="lia-text-color-15 lia-linked-item"&gt;Failure state — Public profile&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;Failure state - Windows Firewall profile "public" enforces internet access restrictions&lt;/img&gt;
&lt;P&gt;The moment GSA stops protecting (step 1) the device, one of several failure events is written to the GSA event log (step 2) and triggers a different scheduled task (step 3) which runs a PowerShell script (step 4) that switches the device to the Public firewall network profile (step 5) and initiates an Intune custom compliance check, too. The failure signals we watch for are:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Entra or Internet Access tunnel disconnected — Event ID 141 (logged roughly every 10 seconds while the tunnel is down),&lt;/LI&gt;
&lt;LI&gt;GSA services stopped — Event IDs 106, 206, 406, and 705,&lt;/LI&gt;
&lt;LI&gt;No internet connectivity — Event ID 638, and&lt;/LI&gt;
&lt;LI&gt;Services start initiated — Event ID 701.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the Public profile, the HTTP(S) outbound rule has Reusable Settings (Defender Dynamic Keywords - &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/windows/security/operating-system-security/network-security/windows-firewall/dynamic-keywords" target="_blank" rel="noopener"&gt;Windows Firewall Dynamic Keywords&lt;/A&gt;) (step 6) assigned, which restricts the reachable FQDNs down to a mandatory set of endpoints. Additionally, mandatory applications and services are explicitly exempt from that restriction, so the device can still be managed, patched, and monitored even while it is locked down.&lt;/P&gt;
&lt;img&gt;Left: normal operations - GSA internet access blocks access | Right: failure state - internet access filtering by Windows Firewall&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H1&gt;&lt;SPAN class="lia-text-color-15"&gt;Closing the gap when GSA is absent: custom compliance&lt;/SPAN&gt;&lt;/H1&gt;
&lt;P&gt;The firewall profile switch is event-driven — it reacts to the signals the GSA client writes to the event log. That works well for a device where the GSA client is present, but it leaves one blind spot: if the GSA client is not installed at all, or its services never start, there may be no events to react to.&lt;/P&gt;
&lt;P&gt;Those are exactly the scenarios where a device would otherwise fall back to unrestricted access, the solution uses a custom device compliance policy/check that does not depend on any event firing. It directly:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Validates that the GSA client is installed on the device, and&lt;/LI&gt;
&lt;LI&gt;Checks the local GSA service state — confirming that the services are running, not just present.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If either of those checks fails — GSA client is not installed, or its services are not running — Intune reports the device as non-compliant. Because a PAW’s access to cloud resources is gated by Conditional Access requiring a compliant device, a non-compliant PAW is denied access to the very cloud services it exists to manage. So even in the one case the event-driven firewall switch cannot see, access still fails closed — this time at the identity layer rather than the network layer.&lt;/P&gt;
&lt;P&gt;In addition, as soon as the local evaluation detected a non-compliant scenario, the custom compliance check flips the firewall profile to the Public profile, too.&lt;/P&gt;
&lt;P&gt;The profile-switching PowerShell scripts also initiate this compliance evaluation as they run in both the normal and failure states, so the device re-reports its posture promptly instead of waiting for the next routine Intune check-in. The result is defense in depth — two independent layers, neither relying on the other:&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-border-color-21 lia-border-style-solid" border="1" style="width: 1079px; height: 184px; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr style="height: 39px;"&gt;&lt;td class="lia-border-color-21" style="height: 39px;"&gt;
&lt;P&gt;&lt;STRONG&gt;Enforcement layer&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-21" style="height: 39px;"&gt;
&lt;P&gt;&lt;STRONG&gt;Mechanism&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-21" style="height: 39px;"&gt;
&lt;P&gt;&lt;STRONG&gt;What it catches&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr style="height: 78px;"&gt;&lt;td class="lia-border-color-21" style="height: 78px;"&gt;
&lt;P&gt;Network&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-21" style="height: 78px;"&gt;
&lt;P&gt;Defender Firewall profile switch, driven by GSA event IDs (141, 106, 206, 406, 705, 638, 701)&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-21" style="height: 78px;"&gt;
&lt;P&gt;Tunnel drops and service stops while the GSA client is present and reporting&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 67px;"&gt;&lt;td class="lia-border-color-21" style="height: 67px;"&gt;
&lt;P&gt;Identity&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-21" style="height: 67px;"&gt;
&lt;P&gt;Intune custom compliance check + Conditional Access (require compliant device)&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-21" style="height: 67px;"&gt;
&lt;P&gt;GSA not installed, or its services not running — no event required to trigger it&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A failure that slips past one layer is caught by the other:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;If GSA stops mid-session, the firewall restricts access near real-time;&lt;/LI&gt;
&lt;LI&gt;If GSA is missing or disabled entirely, Conditional Access refuses the device to access Entra ID integrated resources.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H1&gt;&lt;SPAN class="lia-text-color-15"&gt;Under the hood: the building blocks&lt;/SPAN&gt;&lt;/H1&gt;
&lt;P&gt;The full solution is a set of several components, which all can be delivered and governed through Microsoft Intune:&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-border-color-21 lia-border-style-solid" border="1" style="width: 1080px; height: 356px; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr style="height: 39px;"&gt;&lt;td class="lia-border-color-21" style="height: 39px;"&gt;
&lt;P&gt;&lt;STRONG&gt;Component&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-21" style="height: 39px;"&gt;
&lt;P&gt;&lt;STRONG&gt;What it does&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-border-color-21"&gt;
&lt;P&gt;Firewall profile&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-21"&gt;
&lt;P&gt;Base firewall settings — default block all inbound and outbound connectivity across all profiles (public, private, and domain).&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-21"&gt;
&lt;P&gt;Firewall rules&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-21"&gt;
&lt;P&gt;Allow mandatory programs and services (~35 rules); restrict HTTP(S) in the Public profile using Dynamic Keywords; allow “unrestricted” HTTP(S) in the Private profile.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-21"&gt;
&lt;P&gt;Defender Dynamic Keywords (Reusable Settings)&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-21"&gt;
&lt;P&gt;The set of FQDNs required for Entra ID, Defender for Endpoint, Intune, Windows Update, and Global Secure Access.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 67px;"&gt;&lt;td class="lia-border-color-21" style="height: 67px;"&gt;
&lt;P&gt;Platform scripts&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-21" style="height: 67px;"&gt;
&lt;P&gt;Switch the firewall network profile to Private (unrestricted HTTP(S)); update the Defender anti-malware engine so it supports the Dynamic Keywords feature.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 39px;"&gt;&lt;td class="lia-border-color-21" style="height: 39px;"&gt;
&lt;P&gt;Win32 app package&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-21" style="height: 39px;"&gt;
&lt;P&gt;Required app that deploys the scheduled tasks and the underlying PowerShell scripts.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 67px;"&gt;&lt;td class="lia-border-color-21" style="height: 67px;"&gt;
&lt;P&gt;Custom device compliance check&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-21" style="height: 67px;"&gt;
&lt;P&gt;Validates that GSA is installed and checks the local GSA service state.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 377px" /&gt;&lt;col style="width: 703px" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN class="lia-text-color-15"&gt;The firewall rules that make it work&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;The heart of the enforcement is a pair of “World Wide Web Services” outbound rules — one per firewall profile:&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-border-color-21 lia-border-style-solid" border="1" style="width: 1078px; height: 88px; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr style="height: 39px;"&gt;&lt;td class="lia-border-color-21" style="height: 39px;"&gt;
&lt;P&gt;&lt;STRONG&gt;Rule&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-21" style="height: 39px;"&gt;
&lt;P&gt;&lt;STRONG&gt;Profile&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-21" style="height: 39px;"&gt;
&lt;P&gt;&lt;STRONG&gt;Action&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-21" style="height: 39px;"&gt;
&lt;P&gt;&lt;STRONG&gt;Ports&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-21" style="height: 39px;"&gt;
&lt;P&gt;&lt;STRONG&gt;Remote destinations&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr style="height: 39px;"&gt;&lt;td class="lia-border-color-21" style="height: 39px;"&gt;
&lt;P&gt;World Wide Web Services (HTTP &amp;amp; HTTPS Out)&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-21" style="height: 39px;"&gt;
&lt;P&gt;Private&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-21" style="height: 39px;"&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-21" style="height: 39px;"&gt;
&lt;P&gt;80, 443&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-21" style="height: 39px;"&gt;
&lt;P&gt;Any address&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 10px;"&gt;&lt;td class="lia-border-color-21" style="height: 10px;"&gt;
&lt;P&gt;World Wide Web Services (HTTP &amp;amp; HTTPS Out)&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-21" style="height: 10px;"&gt;
&lt;P&gt;Public&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-21" style="height: 10px;"&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-21" style="height: 10px;"&gt;
&lt;P&gt;80, 443&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-21" style="height: 10px;"&gt;
&lt;P&gt;Dynamic Keywords only&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 377px" /&gt;&lt;col style="width: 140px" /&gt;&lt;col style="width: 186px" /&gt;&lt;col style="width: 158px" /&gt;&lt;col style="width: 215px" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Private HTTP/HTTPS rule is deliberately open, because GSA is the gatekeeper. The Public HTTP/HTTPS rule scopes outbound web traffic down to the endpoint categories expressed as Dynamic Keywords:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;GSA Edge Endpoints,&lt;/LI&gt;
&lt;LI&gt;Microsoft 365 Common and Office Online,&lt;/LI&gt;
&lt;LI&gt;Microsoft 365 encryption chains,&lt;/LI&gt;
&lt;LI&gt;Windows 11,&lt;/LI&gt;
&lt;LI&gt;Intune &amp;amp; Autopilot, and&lt;/LI&gt;
&lt;LI&gt;Defender for Endpoint.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Because these are Defender Dynamic Keywords with AutoResolve (&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/windows/win32/ics/firewall-dynamic-keywords#autoresolve-dynamic-keyword-addresses" target="_blank" rel="noopener"&gt;AutoResolve dynamic keyword addresses&lt;/A&gt;) deployed via Microsoft Intune reusable settings (&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/device-security/reusable-settings-groups" target="_blank" rel="noopener"&gt;Use reusable groups of settings policies in Microsoft Intune&lt;/A&gt;), rather than hard-coded IP ranges, the allow-list includes endpoints centrally instead of being frozen into a brittle registry key — directly addressing the scale and maintainability limits of the old URL Lock Proxy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Besides the mentioned outbound HTTP/HTTPS firewall rule for the public and private network profile, additional rules are required for our scenario. With those additional firewall rules we cover:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Basic Windows operating system network communication,&lt;/LI&gt;
&lt;LI&gt;Communication for Global Secure Access, and&lt;/LI&gt;
&lt;LI&gt;Critical Windows processes and services.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-background-color-2" border="1" style="width: 100%; border-width: 1px;"&gt;&lt;colgroup&gt;&lt;col style="width: 99.9074%" /&gt;&lt;/colgroup&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Disclaimer:&lt;/STRONG&gt; We are sharing the lists of firewall rules with you AS IS without warranty. Keep in mind that the config might require modifications to match to your scenario or environment.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H5&gt;&lt;SPAN class="lia-text-color-15"&gt;Firewall rules for basic network communication&lt;/SPAN&gt;&lt;/H5&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-border-style-solid" border="1" style="width: 2314px; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Name&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Action&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Network Types&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Direction&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Service / File / App Id&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Protocols&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Local Ports&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Local Address Ranges&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Remote Ports&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Remote Address Ranges&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Delivery Optimization (TCP-In)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Inbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Service name: DoSvc&lt;/P&gt;
&lt;P&gt;File path: C:\windows\system32\svchost.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;7680&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any address&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any remote port&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any address&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Delivery Optimization (UDP-In)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Inbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Service name: DoSvc&lt;/P&gt;
&lt;P&gt;File path: C:\windows\system32\svchost.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;UDP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;7680&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any address&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any remote port&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any address&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Core Networking - DHCP (DHCP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Service name: Dhcp&lt;/P&gt;
&lt;P&gt;File path: C:\windows\system32\svchost.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;UDP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;68&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any address&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;67&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any address&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Core Networking - DHCP for IPv6 (DHCPV6-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Service name: Dhcp&lt;/P&gt;
&lt;P&gt;File path: C:\windows\system32\svchost.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;UDP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;546&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any address&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;547&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any address&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Core Networking - DNS (TCP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Service name: Dnscache&lt;/P&gt;
&lt;P&gt;File path: C:\windows\system32\svchost.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any address&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;53&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;DNS&lt;BR /&gt;6.6.0.0-6.6.255.255&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Core Networking - DNS (UDP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Service name: Dnscache&lt;/P&gt;
&lt;P&gt;File path: C:\windows\system32\svchost.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;UDP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any address&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;53&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;DNS&lt;BR /&gt;6.6.0.0-6.6.255.255&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Windows Time (UDP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Service name: W32Time&lt;/P&gt;
&lt;P&gt;File path: C:\windows\system32\svchost.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;UDP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any address&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;123&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any address&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;NCSI Probe (HTTP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Service name: NlaSvc&lt;/P&gt;
&lt;P&gt;File path: C:\windows\system32\svchost.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any address&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;80&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any address&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 10.00%" /&gt;&lt;col style="width: 10.00%" /&gt;&lt;col style="width: 10.00%" /&gt;&lt;col style="width: 10.00%" /&gt;&lt;col style="width: 10.00%" /&gt;&lt;col style="width: 10.00%" /&gt;&lt;col style="width: 10.00%" /&gt;&lt;col style="width: 10.00%" /&gt;&lt;col style="width: 10.00%" /&gt;&lt;col style="width: 10.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;H5&gt;&lt;SPAN class="lia-text-color-15"&gt;Firewall rules for Global Secure Access&lt;/SPAN&gt;&lt;/H5&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-border-style-solid" border="1" style="width: 2314px; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Name&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Action&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Network Types&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Direction&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Service / File / App Id&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Protocols&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Local Ports&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Local Address Ranges&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Remote Ports&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Remote Address Ranges&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;GSA Client - Tray App (TCP-Out)​&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;File path: &lt;BR /&gt;%ProgramFiles%\Global Secure Access Client\TrayApp\GlobalSecureAccessClient.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any address&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;80, 443, 6543&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any address&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;GSA Client - Mgmt Service (TCP-Out)​&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;File path:&lt;BR /&gt;%ProgramFiles%\Global Secure Access Client\GlobalSecureAccessClientManagerService.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any address&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;80, 443&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any address&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;GSA Client - Tunneling Service (TCP-Out)​&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;File path:&lt;BR /&gt;%ProgramFiles%\global secure access client\globalsecureaccesstunnelingservice.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any address&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;80, 443&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any address&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;GSA Client - Advanced Diagnostics (TCP-Out)​&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;File path:&lt;BR /&gt;%ProgramFiles%\global secure access client\advanceddiagnostics\globalsecureaccessclientadvanceddiagnostics.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any address&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any address&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;GSA Client - Forwarding Profile Service (TCP-Out)​&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;File path:&lt;BR /&gt;%ProgramFiles%\Global Secure Access Client\GlobalSecureAccessForwardingProfileService.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any address&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;80, 443&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any address&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;GSA Client - Engine Service (TCP-Out)​&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;File path:&lt;BR /&gt;%ProgramFiles%\Global Secure Access Client\GlobalSecureAccessEngineService.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any address&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;80, 443&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any address&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 10.00%" /&gt;&lt;col style="width: 10.00%" /&gt;&lt;col style="width: 10.00%" /&gt;&lt;col style="width: 10.00%" /&gt;&lt;col style="width: 10.00%" /&gt;&lt;col style="width: 10.00%" /&gt;&lt;col style="width: 10.00%" /&gt;&lt;col style="width: 10.00%" /&gt;&lt;col style="width: 10.00%" /&gt;&lt;col style="width: 10.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;H5&gt;&lt;SPAN class="lia-text-color-15"&gt;Firewall rules for critical Windows processes and services&lt;/SPAN&gt;&lt;/H5&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-border-style-solid" border="1" style="width: 2314px; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Name&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Action&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Network Types&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Direction&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Service / File / App Id&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Protocols&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Local Ports&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Local Address Ranges&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Remote Ports&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Remote Address Ranges&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Microsoft Defender Antivirus Network Inspection Service (TCP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Service: WdNisSvc&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;80, 443&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Microsoft Defender Core Service (TCP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Service: MDCoreSvc&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;443&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Windows Defender Advanced Threat Protection Service (TCP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Service: Sense&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;80, 443&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Microsoft Defender Antivirus Service (TCP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Service: WinDefend&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;443&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Microsoft Intune Management Extension (TCP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;File path: C:\Program Files (x86)\Microsoft Intune Management Extension\Microsoft.Management.Services.IntuneWindowsAgent.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;80, 443&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Runtimebroker (TCP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;File path: C:\windows\system32\runtimebroker.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;443&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Windows Push Notifications System Service (TCP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Service: WpnService&lt;/P&gt;
&lt;P&gt;File path: C:\windows\system32\svchost.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;443&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Host Process for OMA-DM Client (TCP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;File path: C:\Windows\System32\omadmclient.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;80, 443&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Microsoft Edge Update (TCP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;File path: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;443&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Network List Service (TCP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Service: netprofm&lt;/P&gt;
&lt;P&gt;File path: C:\WINDOWS\System32\svchost.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;80&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Microsoft Health Attestation Client Agent (TCP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;File path: C:\Windows\System32\HealthAttestationClient\HealthAttestationClientAgent.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;80, 443&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Windows Defender Advanced Threat Protection IMDSCollector module (TCP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;File path: C:\Program Files\Windows Defender Advanced Threat Protection\SenseImdsCollector.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;80, 443&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;API for MDM Enrollment (TCP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;File path: C:\Windows\System32\DeviceEnroller.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;443&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Windows Defender SmartScreen (TCP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;File path: C:\Windows\System32\smartscreen.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;443&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Windows Update (TCP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Service: wuauserv&lt;/P&gt;
&lt;P&gt;File path: C:\WINDOWS\System32\svchost.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;80, 443&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Device Management Enrollment Service (TCP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Service: DmEnrollmentSvc&lt;/P&gt;
&lt;P&gt;File path: C:\WINDOWS\System32\svchost.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;443&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Delivery Optimization (TCP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Service: DoSvc&lt;/P&gt;
&lt;P&gt;File path: C:\WINDOWS\System32\svchost.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;80, 443&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Company Portal (TCP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;App Id: Microsoft.CompanyPortal_8wekyb3d8bbwe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;80, 443&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;LSASS.exe (TCP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;File path: C:\Windows\system32\lsass.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;443&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Windows License Manager Service&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Service: LicenseManager&lt;/P&gt;
&lt;P&gt;File path: C:\WINDOWS\System32\svchost.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;443&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Background Intelligent Transfer Service (TCP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Service: BITS&lt;/P&gt;
&lt;P&gt;File path: C:\WINDOWS\System32\svchost.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;80&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Microsoft Intune ClientHealthEval (TCP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;File path: c:\program files (x86)\microsoft intune management extension\clienthealtheval.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;443&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Microsoft Intune AgentExecutor (TCP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;File path: c:\program files (x86)\microsoft intune management extension\agentexecutor.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;80, 443&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;BitLocker Drive Encryption Service (TCP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Service: BDESVC&lt;/P&gt;
&lt;P&gt;File path: C:\WINDOWS\System32\svchost.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;443&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Microsoft Intune ClientCertCheck (TCP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;File path: c:\program files (x86)\microsoft intune management extension\clientcertcheck.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;443&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Cryptographic Services (TCP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Service: CryptSvc&lt;/P&gt;
&lt;P&gt;File path: C:\WINDOWS\System32\svchost.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;80, 443&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Microsoft Malware Protection Command Line Utility (TCP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;File path: c:\program files\windows defender\mpcmdrun.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;443&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Microsoft EPM Agent Service (TCP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;File path: C:\Program Files\Microsoft EPM Agent\EPMService\EpmService.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;443&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Microsoft Store Install Service (TCP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Service: InstallService&lt;/P&gt;
&lt;P&gt;File path: C:\WINDOWS\System32\svchost.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;80, 443&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Update Orchestrator Service (TCP-Out)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Allow&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;All&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Outbound&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Service: UsoSvc&lt;/P&gt;
&lt;P&gt;File path: C:\WINDOWS\System32\svchost.exe&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;TCP&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;80, 443&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 10.00%" /&gt;&lt;col style="width: 10.00%" /&gt;&lt;col style="width: 10.00%" /&gt;&lt;col style="width: 10.00%" /&gt;&lt;col style="width: 10.00%" /&gt;&lt;col style="width: 10.00%" /&gt;&lt;col style="width: 10.00%" /&gt;&lt;col style="width: 10.00%" /&gt;&lt;col style="width: 10.00%" /&gt;&lt;col style="width: 10.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-background-color-16" border="1" style="width: 100%; border-width: 1px;"&gt;&lt;colgroup&gt;&lt;col style="width: 99.9074%" /&gt;&lt;/colgroup&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt; List of mandatory programs &amp;amp; services is not a 100% complete list. We are still discovering additional exclusions.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H3&gt;&lt;SPAN class="lia-text-color-15"&gt;Microsoft Intune Reusable Settings&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;As mentioned in the section before, several endpoint categories are being used as part of the Public "World Wide Web Services (HTTP &amp;amp; HTTPS Out)" Firewall rule. As part of this blog post, we cannot publish a one-size fits all list of FQDNs, since the actual list of FQDNs highly depends on the actual configuration, scenario or environment and are subject to change (as usual when it comes to endpoints). In our scenario it was important that PAW devices, when not connected to GSA, are able to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Perform authentication against Microsoft Entra ID,&lt;/LI&gt;
&lt;LI&gt;Remains fully managed by the MDM, in our case Microsoft Intune,&lt;/LI&gt;
&lt;LI&gt;Receive updates for the operating system (Windows 11 Enterprise) and the XDR solution (Defender for Endpoint), and&lt;/LI&gt;
&lt;LI&gt;Are able to connect to Microsoft Global Secure Access edge services.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Based on the requirements we leveraged several publicly available endpoint lists, which include the following, to create our Reusable Settings configuration:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;GSA Edge Endpoints - &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/global-secure-access/reference-points-of-presence#fqdn-and-ip-addresses-where-the-global-secure-access-service-receives-traffic" target="_blank" rel="noopener"&gt;FQDN and IP addresses where the Global Secure Access service receives traffic&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Microsoft 365 -&amp;nbsp;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges?view=o365-worldwide" target="_blank" rel="noopener"&gt;Microsoft 365 URLs and IP address ranges&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Windows 11 - &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/windows/privacy/manage-windows-11-endpoints" target="_blank" rel="noopener"&gt;Connection endpoints for Windows 11 Enterprise&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Intune &amp;amp; Autopilot - &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/fundamentals/endpoints" target="_blank" rel="noopener"&gt;Network endpoints for Microsoft Intune&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Defender for Endpoint - &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/defender-endpoint/streamlined-device-connectivity-urls-commercial?tabs=Windows" target="_blank" rel="noopener"&gt;Microsoft Defender for Endpoint streamlined connectivity URLs&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H5&gt;&lt;SPAN class="lia-text-color-15"&gt;Create Reusable Settings objects&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;Attached to this blog post you will find several CSV files (&lt;EM&gt;GlobalSecureAccessEdgeEndpoints.csv, DefenderforEndpoint.csv, IntuneAutopilot.csv, Microsoft365Common.csv, Microsoft365encryptionchains.csv, Windows11.csv&lt;/EM&gt;) which include the lists of FQDNs we are using as part of our deployments.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-background-color-2" border="1" style="width: 100%; border-width: 1px;"&gt;&lt;colgroup&gt;&lt;col style="width: 99.9074%" /&gt;&lt;/colgroup&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;Disclaimer:&lt;/STRONG&gt; We are sharing those Reusable Settings lists with you AS IS without warranty. Keep in mind that the config might require modifications to match to your scenario or environment.&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The following code example can be used to create the Reusable Settings Object in Intune via Graph API. The code example doesn't include any error handling, since it should give you an idea how to perform the import, based on a CV file.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Code example for Reusable Settings import via CSV:&lt;/STRONG&gt;&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;$csvFile = Get-Item 'C:\temp\GlobalSecureAccessEdgeEndpoints.csv'

$definitionId = 'vendor_msft_firewall_mdmstore_dynamickeywords_addresses_{id}'

$values = Import-Csv -LiteralPath $csvFile.FullName | ForEach-Object {
    $row = $_
    $autoResolve = [bool]::Parse($row.AutoResolve)
    $autoResolveValue = $autoResolve.ToString().ToLowerInvariant()

    $choiceChildren = if (-not $autoResolve) {
        @{
            '@odata.type'                    = '#microsoft.graph.deviceManagementConfigurationSimpleSettingCollectionInstance'
            settingDefinitionId              = "${definitionId}_addresses"
            settingInstanceTemplateReference = $null
            simpleSettingCollectionValue     = @(
                $row.Addresses -split ';' |
                    Where-Object { -not [string]::IsNullOrWhiteSpace($_) } |
                    ForEach-Object {
                        @{
                            '@odata.type'                 = '#microsoft.graph.deviceManagementConfigurationStringSettingValue'
                            settingValueTemplateReference = $null
                            value                         = $_.Trim()
                        }
                    }
            )
        }
    }

    @{
        '@odata.type'                 = '#microsoft.graph.deviceManagementConfigurationGroupSettingValue'
        settingValueTemplateReference = $null
        children                      = @(
            @{
                '@odata.type'                    = '#microsoft.graph.deviceManagementConfigurationSimpleSettingInstance'
                settingDefinitionId              = "${definitionId}_id"
                settingInstanceTemplateReference = $null
                simpleSettingValue               = @{
                    '@odata.type'                 = '#microsoft.graph.deviceManagementConfigurationStringSettingValue'
                    settingValueTemplateReference = $null
                    value                         = "{$([guid]::NewGuid())}"
                }
            }
            @{
                '@odata.type'                    = '#microsoft.graph.deviceManagementConfigurationChoiceSettingInstance'
                settingDefinitionId              = "${definitionId}_autoresolve"
                settingInstanceTemplateReference = $null
                choiceSettingValue               = @{
                    '@odata.type'                 = '#microsoft.graph.deviceManagementConfigurationChoiceSettingValue'
                    settingValueTemplateReference = $null
                    value                         = "${definitionId}_autoresolve_$autoResolveValue"
                    children                      = @($choiceChildren)
                }
            }
            @{
                '@odata.type'                    = '#microsoft.graph.deviceManagementConfigurationSimpleSettingInstance'
                settingDefinitionId              = "${definitionId}_keyword"
                settingInstanceTemplateReference = $null
                simpleSettingValue               = @{
                    '@odata.type'                 = '#microsoft.graph.deviceManagementConfigurationStringSettingValue'
                    settingValueTemplateReference = $null
                    value                         = $row.Keyword
                }
            }
        )
    }
}

$body = @{
    '@odata.type'       = '#microsoft.graph.deviceManagementReusablePolicySetting'
    displayName         = $csvFile.BaseName
    description         = ''
    settingDefinitionId = $definitionId
    settingInstance     = @{
        '@odata.type'                    = '#microsoft.graph.deviceManagementConfigurationGroupSettingCollectionInstance'
        settingDefinitionId              = $definitionId
        settingInstanceTemplateReference = $null
        groupSettingCollectionValue      = @($values)
    }
}

Connect-MgGraph -Scopes 'DeviceManagementConfiguration.ReadWrite.All'

Invoke-MgGraphRequest `
    -Method POST `
    -Uri 'https://graph.microsoft.com/beta/deviceManagement/reusablePolicySettings' `
    -Body ($body | ConvertTo-Json -Depth 20) `
    -ContentType 'application/json'&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-background-color-2" border="1" style="width: 100%; border-width: 1px;"&gt;&lt;colgroup&gt;&lt;col style="width: 99.9074%" /&gt;&lt;/colgroup&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;Important:&lt;/STRONG&gt; A maximum of 100 properties can be stored in a single reusable settings group object. Therefore, it might be required to split a endpoint category into multiple Reusable Settings Group objects.&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H3&gt;&lt;SPAN class="lia-text-color-15"&gt;Intune Win32 app package&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;Besides the deployment of the actual Global Secure Access client, a dedicated application package will be used to deploy the local components (Scheduled Tasks and PowerShell scripts) for the fail-close approach. To react on the two different states (normal and failure), two Scheduled Tasks need to be deployed to the PAW device. The Scheduled Task creation can be simplified by using exported XML files, which can also include the event trigger itself (examples listed in the sections&amp;nbsp;&lt;A class="lia-internal-link" href="#community--1-NormalState" target="_blank" rel="noopener" data-lia-auto-title="Normal State" data-lia-auto-title-active="0"&gt;Normal State&lt;/A&gt; and &lt;A class="lia-internal-link" href="#community--1-FailureState" target="_blank" rel="noopener" data-lia-auto-title="Failure State" data-lia-auto-title-active="0"&gt;Failure State&lt;/A&gt;). Please note, the creation of Scheduled Tasks with event log based triggers require that the actual event log already exists on the device. So it might be worth creating a dependency between the different application packages.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Example code to register exported Scheduled Tasks via PowerShell:&lt;/STRONG&gt;&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;Register-ScheduledTask -Xml (Get-Content "$PSScriptRoot\GSA-Connected.xml" | Out-String) -TaskName 'GSA-Connected'

Register-ScheduledTask -Xml (Get-Content "$PSScriptRoot\GSA-Disconnected.xml" | Out-String) -TaskName 'GSA-Disconnected'&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;XML Sample Scheduled Task export GSA-Connected:&lt;/STRONG&gt;&lt;/P&gt;
&lt;LI-CODE lang="xml"&gt;&amp;lt;?xml version="1.0" encoding="UTF-16"?&amp;gt;
&amp;lt;Task version="1.4" xmlns="http://schemas.microsoft.com/windows/2004/02/mit/task"&amp;gt;
  &amp;lt;RegistrationInfo&amp;gt;
    &amp;lt;Date&amp;gt;2026-09-10T17:46:11.8914414&amp;lt;/Date&amp;gt;
    &amp;lt;Author&amp;gt;ChristianFriedel-Jain&amp;lt;/Author&amp;gt;
    &amp;lt;URI&amp;gt;\GSA-Connected&amp;lt;/URI&amp;gt;
  &amp;lt;/RegistrationInfo&amp;gt;
  &amp;lt;Triggers&amp;gt;
    &amp;lt;EventTrigger&amp;gt;
      &amp;lt;Enabled&amp;gt;true&amp;lt;/Enabled&amp;gt;
      &amp;lt;Subscription&amp;gt;&amp;lt;QueryList&amp;gt;&amp;lt;Query Id="0" Path="Microsoft-Windows-Global Secure Access Client-Operational"&amp;gt;&amp;lt;Select Path="Microsoft-Windows-Global Secure Access Client-Operational"&amp;gt;
      *[System[(EventID=142)]]
      and
      *[EventData[Data[@Name='Channel Name'] and (Data='Internet')]]
    &amp;lt;/Select&amp;gt;&amp;lt;/Query&amp;gt;&amp;lt;/QueryList&amp;gt;&amp;lt;/Subscription&amp;gt;
    &amp;lt;/EventTrigger&amp;gt;
  &amp;lt;/Triggers&amp;gt;
  &amp;lt;Principals&amp;gt;
    &amp;lt;Principal id="Author"&amp;gt;
      &amp;lt;UserId&amp;gt;S-1-5-18&amp;lt;/UserId&amp;gt;
      &amp;lt;RunLevel&amp;gt;HighestAvailable&amp;lt;/RunLevel&amp;gt;
    &amp;lt;/Principal&amp;gt;
  &amp;lt;/Principals&amp;gt;
  &amp;lt;Settings&amp;gt;
    &amp;lt;MultipleInstancesPolicy&amp;gt;IgnoreNew&amp;lt;/MultipleInstancesPolicy&amp;gt;
    &amp;lt;DisallowStartIfOnBatteries&amp;gt;false&amp;lt;/DisallowStartIfOnBatteries&amp;gt;
    &amp;lt;StopIfGoingOnBatteries&amp;gt;false&amp;lt;/StopIfGoingOnBatteries&amp;gt;
    &amp;lt;AllowHardTerminate&amp;gt;true&amp;lt;/AllowHardTerminate&amp;gt;
    &amp;lt;StartWhenAvailable&amp;gt;false&amp;lt;/StartWhenAvailable&amp;gt;
    &amp;lt;RunOnlyIfNetworkAvailable&amp;gt;false&amp;lt;/RunOnlyIfNetworkAvailable&amp;gt;
    &amp;lt;IdleSettings&amp;gt;
      &amp;lt;StopOnIdleEnd&amp;gt;true&amp;lt;/StopOnIdleEnd&amp;gt;
      &amp;lt;RestartOnIdle&amp;gt;false&amp;lt;/RestartOnIdle&amp;gt;
    &amp;lt;/IdleSettings&amp;gt;
    &amp;lt;AllowStartOnDemand&amp;gt;true&amp;lt;/AllowStartOnDemand&amp;gt;
    &amp;lt;Enabled&amp;gt;true&amp;lt;/Enabled&amp;gt;
    &amp;lt;Hidden&amp;gt;false&amp;lt;/Hidden&amp;gt;
    &amp;lt;RunOnlyIfIdle&amp;gt;false&amp;lt;/RunOnlyIfIdle&amp;gt;
    &amp;lt;DisallowStartOnRemoteAppSession&amp;gt;false&amp;lt;/DisallowStartOnRemoteAppSession&amp;gt;
    &amp;lt;UseUnifiedSchedulingEngine&amp;gt;true&amp;lt;/UseUnifiedSchedulingEngine&amp;gt;
    &amp;lt;WakeToRun&amp;gt;false&amp;lt;/WakeToRun&amp;gt;
    &amp;lt;ExecutionTimeLimit&amp;gt;PT1H&amp;lt;/ExecutionTimeLimit&amp;gt;
    &amp;lt;Priority&amp;gt;7&amp;lt;/Priority&amp;gt;
  &amp;lt;/Settings&amp;gt;
  &amp;lt;Actions Context="Author"&amp;gt;
    &amp;lt;Exec&amp;gt;
      &amp;lt;Command&amp;gt;"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"&amp;lt;/Command&amp;gt;
      &amp;lt;Arguments&amp;gt;-NoProfile -ExecutionPolicy Bypass -File "C:\Progra~1\GSA-NetDetection\Set-NetworkPrivate.ps1"&amp;lt;/Arguments&amp;gt;
    &amp;lt;/Exec&amp;gt;
  &amp;lt;/Actions&amp;gt;
&amp;lt;/Task&amp;gt;&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Sample XML Scheduled Task export GSA-Disconnected:&lt;/STRONG&gt;&lt;/P&gt;
&lt;LI-CODE lang="xml"&gt;&amp;lt;?xml version="1.0" encoding="UTF-16"?&amp;gt;
&amp;lt;Task version="1.4" xmlns="http://schemas.microsoft.com/windows/2004/02/mit/task"&amp;gt;
  &amp;lt;RegistrationInfo&amp;gt;
    &amp;lt;Date&amp;gt;2026-09-10T17:46:11.8914414&amp;lt;/Date&amp;gt;
    &amp;lt;Author&amp;gt;ChristianFriedel-Jain&amp;lt;/Author&amp;gt;
    &amp;lt;URI&amp;gt;\GSA-Disconnected&amp;lt;/URI&amp;gt;
  &amp;lt;/RegistrationInfo&amp;gt;
  &amp;lt;Triggers&amp;gt;
    &amp;lt;EventTrigger&amp;gt;
      &amp;lt;Enabled&amp;gt;true&amp;lt;/Enabled&amp;gt;
      &amp;lt;Subscription&amp;gt;&amp;lt;QueryList&amp;gt;&amp;lt;Query Id="0" Path="Microsoft-Windows-Global Secure Access Client-Operational"&amp;gt;&amp;lt;Select Path="Microsoft-Windows-Global Secure Access Client-Operational"&amp;gt;
      *[System[(EventID=141)]]
      and
      *[EventData[Data[@Name='Channel Name'] and (Data='Entra')]]
    &amp;lt;/Select&amp;gt;&amp;lt;/Query&amp;gt;&amp;lt;/QueryList&amp;gt;&amp;lt;/Subscription&amp;gt;
    &amp;lt;/EventTrigger&amp;gt;
    &amp;lt;EventTrigger&amp;gt;
      &amp;lt;Enabled&amp;gt;true&amp;lt;/Enabled&amp;gt;
      &amp;lt;Subscription&amp;gt;&amp;lt;QueryList&amp;gt;&amp;lt;Query Id="0" Path="Microsoft-Windows-Global Secure Access Client-Operational"&amp;gt;&amp;lt;Select Path="Microsoft-Windows-Global Secure Access Client-Operational"&amp;gt;
      *[System[(EventID=141)]]
      and
      *[EventData[Data[@Name='Channel Name'] and (Data='Internet')]]
    &amp;lt;/Select&amp;gt;&amp;lt;/Query&amp;gt;&amp;lt;/QueryList&amp;gt;&amp;lt;/Subscription&amp;gt;
    &amp;lt;/EventTrigger&amp;gt;
    &amp;lt;EventTrigger&amp;gt;
      &amp;lt;Enabled&amp;gt;true&amp;lt;/Enabled&amp;gt;
      &amp;lt;Subscription&amp;gt;&amp;lt;QueryList&amp;gt;&amp;lt;Query Id="0" Path="Microsoft-Windows-Global Secure Access Client-Operational"&amp;gt;&amp;lt;Select Path="Microsoft-Windows-Global Secure Access Client-Operational"&amp;gt;*[System[Provider[@Name='Microsoft-Windows-Global Secure Access Client'] and EventID=106]]&amp;lt;/Select&amp;gt;&amp;lt;/Query&amp;gt;&amp;lt;/QueryList&amp;gt;&amp;lt;/Subscription&amp;gt;
    &amp;lt;/EventTrigger&amp;gt;
    &amp;lt;EventTrigger&amp;gt;
      &amp;lt;Enabled&amp;gt;true&amp;lt;/Enabled&amp;gt;
      &amp;lt;Subscription&amp;gt;&amp;lt;QueryList&amp;gt;&amp;lt;Query Id="0" Path="Microsoft-Windows-Global Secure Access Client-Operational"&amp;gt;&amp;lt;Select Path="Microsoft-Windows-Global Secure Access Client-Operational"&amp;gt;*[System[Provider[@Name='Microsoft-Windows-Global Secure Access Client'] and EventID=206]]&amp;lt;/Select&amp;gt;&amp;lt;/Query&amp;gt;&amp;lt;/QueryList&amp;gt;&amp;lt;/Subscription&amp;gt;
    &amp;lt;/EventTrigger&amp;gt;
    &amp;lt;EventTrigger&amp;gt;
      &amp;lt;Enabled&amp;gt;true&amp;lt;/Enabled&amp;gt;
      &amp;lt;Subscription&amp;gt;&amp;lt;QueryList&amp;gt;&amp;lt;Query Id="0" Path="Microsoft-Windows-Global Secure Access Client-Operational"&amp;gt;&amp;lt;Select Path="Microsoft-Windows-Global Secure Access Client-Operational"&amp;gt;*[System[Provider[@Name='Microsoft-Windows-Global Secure Access Client'] and EventID=406]]&amp;lt;/Select&amp;gt;&amp;lt;/Query&amp;gt;&amp;lt;/QueryList&amp;gt;&amp;lt;/Subscription&amp;gt;
    &amp;lt;/EventTrigger&amp;gt;
    &amp;lt;EventTrigger&amp;gt;
      &amp;lt;Enabled&amp;gt;true&amp;lt;/Enabled&amp;gt;
      &amp;lt;Subscription&amp;gt;&amp;lt;QueryList&amp;gt;&amp;lt;Query Id="0" Path="Microsoft-Windows-Global Secure Access Client-Operational"&amp;gt;&amp;lt;Select Path="Microsoft-Windows-Global Secure Access Client-Operational"&amp;gt;*[System[Provider[@Name='Microsoft-Windows-Global Secure Access Client'] and EventID=705]]&amp;lt;/Select&amp;gt;&amp;lt;/Query&amp;gt;&amp;lt;/QueryList&amp;gt;&amp;lt;/Subscription&amp;gt;
    &amp;lt;/EventTrigger&amp;gt;
    &amp;lt;EventTrigger&amp;gt;
      &amp;lt;Enabled&amp;gt;true&amp;lt;/Enabled&amp;gt;
      &amp;lt;Subscription&amp;gt;&amp;lt;QueryList&amp;gt;&amp;lt;Query Id="0" Path="Microsoft-Windows-Global Secure Access Client-Operational"&amp;gt;&amp;lt;Select Path="Microsoft-Windows-Global Secure Access Client-Operational"&amp;gt;*[System[Provider[@Name='Microsoft-Windows-Global Secure Access Client'] and EventID=638]]&amp;lt;/Select&amp;gt;&amp;lt;/Query&amp;gt;&amp;lt;/QueryList&amp;gt;&amp;lt;/Subscription&amp;gt;
    &amp;lt;/EventTrigger&amp;gt;
      &amp;lt;EventTrigger&amp;gt;
      &amp;lt;Enabled&amp;gt;true&amp;lt;/Enabled&amp;gt;
      &amp;lt;Subscription&amp;gt;&amp;lt;QueryList&amp;gt;&amp;lt;Query Id="0" Path="Microsoft-Windows-Global Secure Access Client-Operational"&amp;gt;&amp;lt;Select Path="Microsoft-Windows-Global Secure Access Client-Operational"&amp;gt;*[System[Provider[@Name='Microsoft-Windows-Global Secure Access Client'] and EventID=701]]&amp;lt;/Select&amp;gt;&amp;lt;/Query&amp;gt;&amp;lt;/QueryList&amp;gt;&amp;lt;/Subscription&amp;gt;
    &amp;lt;/EventTrigger&amp;gt;
  &amp;lt;/Triggers&amp;gt;
  &amp;lt;Principals&amp;gt;
    &amp;lt;Principal id="Author"&amp;gt;
      &amp;lt;UserId&amp;gt;S-1-5-18&amp;lt;/UserId&amp;gt;
      &amp;lt;RunLevel&amp;gt;HighestAvailable&amp;lt;/RunLevel&amp;gt;
    &amp;lt;/Principal&amp;gt;
  &amp;lt;/Principals&amp;gt;
  &amp;lt;Settings&amp;gt;
    &amp;lt;MultipleInstancesPolicy&amp;gt;IgnoreNew&amp;lt;/MultipleInstancesPolicy&amp;gt;
    &amp;lt;DisallowStartIfOnBatteries&amp;gt;false&amp;lt;/DisallowStartIfOnBatteries&amp;gt;
    &amp;lt;StopIfGoingOnBatteries&amp;gt;false&amp;lt;/StopIfGoingOnBatteries&amp;gt;
    &amp;lt;AllowHardTerminate&amp;gt;true&amp;lt;/AllowHardTerminate&amp;gt;
    &amp;lt;StartWhenAvailable&amp;gt;false&amp;lt;/StartWhenAvailable&amp;gt;
    &amp;lt;RunOnlyIfNetworkAvailable&amp;gt;false&amp;lt;/RunOnlyIfNetworkAvailable&amp;gt;
    &amp;lt;IdleSettings&amp;gt;
      &amp;lt;StopOnIdleEnd&amp;gt;true&amp;lt;/StopOnIdleEnd&amp;gt;
      &amp;lt;RestartOnIdle&amp;gt;false&amp;lt;/RestartOnIdle&amp;gt;
    &amp;lt;/IdleSettings&amp;gt;
    &amp;lt;AllowStartOnDemand&amp;gt;true&amp;lt;/AllowStartOnDemand&amp;gt;
    &amp;lt;Enabled&amp;gt;true&amp;lt;/Enabled&amp;gt;
    &amp;lt;Hidden&amp;gt;false&amp;lt;/Hidden&amp;gt;
    &amp;lt;RunOnlyIfIdle&amp;gt;false&amp;lt;/RunOnlyIfIdle&amp;gt;
    &amp;lt;DisallowStartOnRemoteAppSession&amp;gt;false&amp;lt;/DisallowStartOnRemoteAppSession&amp;gt;
    &amp;lt;UseUnifiedSchedulingEngine&amp;gt;true&amp;lt;/UseUnifiedSchedulingEngine&amp;gt;
    &amp;lt;WakeToRun&amp;gt;false&amp;lt;/WakeToRun&amp;gt;
    &amp;lt;ExecutionTimeLimit&amp;gt;PT1H&amp;lt;/ExecutionTimeLimit&amp;gt;
    &amp;lt;Priority&amp;gt;7&amp;lt;/Priority&amp;gt;
  &amp;lt;/Settings&amp;gt;
  &amp;lt;Actions Context="Author"&amp;gt;
    &amp;lt;Exec&amp;gt;
      &amp;lt;Command&amp;gt;"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"&amp;lt;/Command&amp;gt;
      &amp;lt;Arguments&amp;gt;-NoProfile -ExecutionPolicy Bypass -File "C:\Progra~1\GSA-NetDetection\Set-NetworkPublic.ps1"&amp;lt;/Arguments&amp;gt;
    &amp;lt;/Exec&amp;gt;
  &amp;lt;/Actions&amp;gt;
&amp;lt;/Task&amp;gt;&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As soon as one of the Scheduled Tasks has been triggered, the corresponding PowerShell script (Set-NetworkPrivate.ps1 or Set-NetworkPublic.ps1) will be executed.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Example content of Set-NetworkPrivate.ps1&lt;/STRONG&gt;&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;$NetworkName = (Get-NetConnectionProfile).Name
Set-NetConnectionProfile -Name $NetworkName -NetworkCategory Private&lt;/LI-CODE&gt;
&lt;P&gt;&lt;STRONG&gt;Example content of Set-NetworkPublic.ps1&lt;/STRONG&gt;&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;$NetworkName = (Get-NetConnectionProfile).Name
Set-NetConnectionProfile -Name $NetworkName -NetworkCategory Public&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN class="lia-text-color-15"&gt;Platform scripts&lt;/SPAN&gt;&lt;/H3&gt;
&lt;H5&gt;&lt;SPAN class="lia-text-color-15"&gt;Install Microsoft Defender Antivirus updates during the device enrollment&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;To leverage the AutoResolve dynamic keyword feature, Microsoft Defender Antivirus must be turned on and running with platform version 4.18.2209.7 or later (see reference here&amp;nbsp;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/windows/security/operating-system-security/network-security/windows-firewall/dynamic-keywords#fqdn-feature-requirements" target="_blank" rel="noopener"&gt;FQDN Feature requirements&lt;/A&gt;). Since the required version is not natively included in Windows yet, a Platform script is being used to install the required Defender updates (&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/defender-endpoint/command-line-arguments-microsoft-defender-antivirus" target="_blank" rel="noopener"&gt;Use the command line to manage Microsoft Defender Antivirus&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Example command to trigger Defender update:&lt;/STRONG&gt;&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;$MpCmdRun = "C:\Program Files\Windows Defender\MpCmdRun.exe"
&amp;amp; $MpCmdRun -SignatureUpdate -MMPC&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN class="lia-text-color-15"&gt;Switch Defender Firewall profile to private during enrollment phase&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;To avoid issues during the device enrollment phase, the Defender Firewall profile is being switched from the default Public profile to the unrestricted Private profile by using another Platform Script.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Example code to switched the Firewall profile:&lt;/STRONG&gt;&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;$NetworkName = (Get-NetConnectionProfile).Name
Set-NetConnectionProfile -Name $NetworkName -NetworkCategory Private&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN class="lia-text-color-15"&gt;Custom device compliance check&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;A custom device compliance check is being used to validate if GSA is installed and if the services are running on the device. A custom device compliance check requires an underlying script to gather the required information.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Example custom compliance script:&lt;/STRONG&gt;&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;# GSA services to check
$Services = @(
    "GlobalSecureAccessClientManagerService"
    "GlobalSecureAccessEngineService"
    "GlobalSecureAccessForwardingProfileService"
    "GlobalSecureAccessTunnelingService"
)

$GSAInstalled = $false
$RunningGSAServices = 0

# Validate that all Services are present (GSA installed)
if ((Get-Service $Services[0] -ErrorAction SilentlyContinue) -and 
        (Get-Service $Services[1] -ErrorAction SilentlyContinue) -and 
        (Get-Service $Services[2] -ErrorAction SilentlyContinue) -and 
        (Get-Service $Services[3] -ErrorAction SilentlyContinue)) {
    $GSAInstalled = $true
}
else {
    $GSAInstalled = $false
}

# Validate Service State
foreach ($Service in $Services) {
    if ((Get-Service -Name $Service -ErrorAction SilentlyContinue).Status -eq 'Running' ) {
        # Service running - increase number of running services by 1
        $RunningGSAServices += 1
    }
    else {
        # Service not running - will not increase number of running services
        $RunningGSAServices += 0    
    }
}

if (($RunningGSAServices -ne 4) -or ($GSAInstalled -eq $false)) {
	Set-NetConnectionProfile -NetworkCategory Public
}

# Create a hashtable with the collected data
$hash = @{ 
    "GSAinstalled" = $GSAInstalled
    "GSArunning" = $RunningGSAServices
}

return $hash | ConvertTo-Json -Compress&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The result of the custom compliance script will be evaluated against the custom compliance policy, which requires the custom compliance settings in a JSON format.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Example custom compliance settings JSON:&lt;/STRONG&gt;&lt;/P&gt;
&lt;LI-CODE lang="json"&gt;{
  "Rules": [
    {
      "SettingName": "GSAinstalled",
      "Operator": "IsEquals",
      "DataType": "Boolean",
      "Operand": "true",
      "MoreInfoUrl": "https://learn.microsoft.com/en-us/entra/global-secure-access/overview-what-is-global-secure-access",
      "RemediationStrings": [
        {
          "Language": "en_US",
          "Title": "Global Secure Access not detected",
          "Description": "Global Secure Access service not found on the device."
        }
      ]
    },
    {
      "SettingName": "GSArunning",
      "Operator": "IsEquals",
      "DataType": "Int64",
      "Operand": "4",
      "MoreInfoUrl": "https://learn.microsoft.com/en-us/entra/global-secure-access/overview-what-is-global-secure-access",
      "RemediationStrings": [
        {
          "Language": "en_US",
          "Title": "Global Secure Access services not running",
          "Description": "One or more Global Secure Access service is not running on the device."
        }
      ]
    }
  ]
}&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H1&gt;&lt;SPAN class="lia-text-color-15"&gt;Validating and monitoring&lt;/SPAN&gt;&lt;/H1&gt;
&lt;P&gt;How did we work out which rules and events mattered — and how do we confirm the solution keeps working? Two sources did the heavy lifting:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The local security event log on the device, which is essential during enrollment and reset scenarios when the profile-switching lifecycle is first established; and&lt;/LI&gt;
&lt;LI&gt;Microsoft Defender advanced hunting, to surface blocked connection attempts while the device is in its restricted, fail-close state.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example, this advanced hunting query surfaces outbound connections from the PAW that were blocked while it was failing closed:&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;LI-CODE lang="kusto"&gt;DeviceNetworkEvents
| where DeviceName == "paw" 
| where LocalIPType == "Private" and RemoteIPType == "Public" 
| where ActionType == "ConnectionFailed" 
| sort by Timestamp desc&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;Reviewing these "ConnectionFailed" events tells you whether the restricted rule set is too tight (legitimate management traffic being blocked and needing an exemption) or working exactly as intended (unexpected destinations being denied while the device is locked down).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H1&gt;&lt;SPAN class="lia-text-color-15"&gt;Key takeaways&lt;/SPAN&gt;&lt;/H1&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-background-color-16" border="1" style="width: 100%; border-width: 1px;"&gt;&lt;colgroup&gt;&lt;col style="width: 99.9074%" /&gt;&lt;/colgroup&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;UL&gt;
&lt;LI&gt;Global Secure Access is the right tool for controlling PAW internet access — but its currently default fail-open behavior is unacceptable for a privileged workstation.&lt;/LI&gt;
&lt;LI&gt;You don’t need a new GSA client to fix it. Windows Defender Firewall network profiles, driven by GSA’s own event log, give you a reliable fail-close backstop.&lt;/LI&gt;
&lt;LI&gt;Defender Dynamic Keywords keep the locked-down state both minimal and maintainable, replacing brittle, unscalable allow-lists.&lt;/LI&gt;
&lt;LI&gt;Enforcement runs at two independent layers — network (Defender Firewall profiles) and identity (Intune custom compliance plus Conditional Access) — so a failure that evades one is still caught by the other. The compliance check specifically covers the case the firewall cannot see: GSA not installed or its services not running.&lt;/LI&gt;
&lt;LI&gt;The whole solution deploys through Intune — Win32 app, firewall profile and rules, and a custom compliance check — and is observable through the event log and Defender advanced hunting.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Fail-Close solution turns a gap into a safe default: the instant Global Secure Access stops protecting the workstation, the privileged access workstation stops trusting the internet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We hope this article gives you a practical pattern to harden your own privileged endpoints — and if you’d like to hear more about how we design and implement our Secure Privileged Access (SPA) strategy (for instance leveraging Global Secure Access to secure on-Premises management, secure access and management of Azure private resources, what Entra ID identity controls we are using to protect privileged access, or how we leverage Identity Governance to simplify governance for privileged users), feel free to reach out to us and stay tuned for more articles.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd like to thank&amp;nbsp;&lt;a href="javascript:void(0)" data-lia-user-mentions="" data-lia-user-uid="259504" data-lia-user-login="DagmarHeidecker" class="lia-mention lia-mention-user"&gt;DagmarHeidecker​&lt;/a&gt; for her review and help in getting my first blog post created. As well as, &lt;a href="javascript:void(0)" data-lia-user-mentions="" data-lia-user-uid="3598125" data-lia-user-login="JamesNoyce" class="lia-mention lia-mention-user"&gt;JamesNoyce​&lt;/a&gt; who came up with the initial base concept which I built upon.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Disclaimer&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;The sample scripts are not supported under any Microsoft standard support program or service. The sample scripts are provided AS IS without warranty of any kind. Microsoft further disclaims all implied warranties including, without limitation, any implied warranties of merchantability or of fitness for a particular purpose. The entire risk arising out of the use or performance of the sample scripts and documentation remains with you. In no event shall Microsoft, its authors, or anyone else involved in the creation, production, or delivery of the scripts be liable for any damages whatsoever (including, without limitation, damages for loss of business profits, business interruption, loss of business information, or other pecuniary loss) arising out of the use of or inability to use the sample scripts or documentation, even if Microsoft has been advised of the possibility of such damages.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2026 08:38:19 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/locking-down-paws-internet-access-when-gsa-drops/ba-p/4553963</guid>
      <dc:creator>ChristianFriedel-Jain</dc:creator>
      <dc:date>2026-09-14T08:38:19Z</dc:date>
    </item>
    <item>
      <title>Microsoft defender is not catching threats before they are put into download folder.</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-experts/microsoft-defender-is-not-catching-threats-before-they-are-put/m-p/4555986#M72</link>
      <description>&lt;P&gt;Before I post this, please note that I’m a security researcher trained to investigate malware and other application bugs. my complaint is the following and it's a serious one that should be fixed by Microsoft as soon as possible.&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I downloaded several malicious EXE files, Microsoft Defender didn't block or quarantine them during the download. Instead, Defender only detected them after I actually ran or executed the files. I also noticed that online platforms showed Microsoft Defender detecting the threats, so the files were clearly being recognized as malicious by Defender's engine. Has Microsoft changed the way Defender detects malware? Does it now require a malicious file to be executed before it detects it, similar to how some behavioral detection works in Malwarebytes? Or should Defender still be detecting and blocking known malicious EXE files before they are executed/downloaded because it's not at this current time and this is a clean installed system.&amp;nbsp;&lt;/P&gt;&lt;P&gt;My system is clean, and I even performed a clean installation of Windows. I also used ConfigureDefender with the settings configured to High, and all of the relevant protection settings appeared to be enabled.I'm trying to understand whether this is normal behavior with the current version of Microsoft Defender or if something might be misconfigured on my system. Before, Microsoft Defender would detect and block malicious files while they were being downloaded, before I had a chance to run or execute them. Now, however, it seems like Defender is allowing the files to finish downloading and only detects them after I execute them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Windows Defender isn't detecting EICAR test files? Mine doesn’t seem to detect them automatically, as shown in my proof. It only detects the file when I right-click it and select “Scan with Microsoft Defender.” Is this normal? It seems pretty crazy that it doesn’t detect the file immediately. it allowed them all to download. It's not even blocking Eicar test files when i bypass edges warning to download it just allows it to download no problem. edge detects it but Microsoft security does not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please have Microsoft’s threat team investigate why Windows Defender isn’t detecting malicious files when downloaded through Microsoft Edge. When Edge warns about a malicious or suspicious download and those warnings are bypassed, the files aren’t caught or blocked by Defender and end up being saved to the system. This is extremely dangerous and needs to be replicated to confirm the issue.&lt;/P&gt;&lt;img /&gt;&lt;img /&gt;&lt;img /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 13 Sep 2026 11:12:38 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-experts/microsoft-defender-is-not-catching-threats-before-they-are-put/m-p/4555986#M72</guid>
      <dc:creator>brad03</dc:creator>
      <dc:date>2026-09-13T11:12:38Z</dc:date>
    </item>
    <item>
      <title>Trojan;Win32 Threat Found- how to get rid of</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-experts/trojan-win32-threat-found-how-to-get-rid-of/m-p/4555489#M70</link>
      <description>&lt;P&gt;I've noticed that I've been getting this same threat consistently since yesterday and even when I "remove" the threat, it just comes back. Can someone tell me what this means and what it might be from so I can remove he problem. I already did a full scan and it didn't find any other threats&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Sep 2026 23:48:02 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-experts/trojan-win32-threat-found-how-to-get-rid-of/m-p/4555489#M70</guid>
      <dc:creator>cdarling52</dc:creator>
      <dc:date>2026-09-10T23:48:02Z</dc:date>
    </item>
    <item>
      <title>Age Signals administrative control</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/age-signals-administrative-control/m-p/4555431#M10447</link>
      <description>&lt;P&gt;Hi.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;There has been discussion that starting January 2027 discussion age signal responses will be required during the Windows 11 Out of Box Experience and when a Microsoft account is created; personal accounts I am assuming.&amp;nbsp; &amp;nbsp; But what about Enterprise Entra ID accounts and the OOBE experience using Intune and Autopilot?&amp;nbsp; In the Microsof article, it states that Administrative Control will be an option.&amp;nbsp; When will these fields be available in Entra ID accounts and be controlled via Intune policies to send a default value for all users if requested?&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Link to the full document is below.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://learn.microsoft.com/en-us/windows/apps/develop/security/age-signals/" target="_blank"&gt;Age signals overview for Windows developers - Windows apps | Microsoft Learn&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Sep 2026 18:22:19 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/age-signals-administrative-control/m-p/4555431#M10447</guid>
      <dc:creator>JDBaggs</dc:creator>
      <dc:date>2026-09-10T18:22:19Z</dc:date>
    </item>
    <item>
      <title>The Hidden Reason Your Sentinel Playbook Won't Show Up in Automation Rules (It's Not RBAC)</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-sentinel/the-hidden-reason-your-sentinel-playbook-won-t-show-up-in/m-p/4555416#M12973</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;P&gt;If a Logic App using the native Microsoft Sentinel incident trigger doesn't show up in the "Run playbook" picker of an Automation Rule — even though permissions, region, and connection are all correct — check the internal &lt;STRONG&gt;action name&lt;/STRONG&gt; of the trigger in the JSON code view. If the Logic App was created while the Azure portal was set to a non-English language, the designer may generate a localized action name instead of the expected &lt;EM&gt;Microsoft_Sentinel_incident&lt;/EM&gt;, and the playbook won't be picked up.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;H3&gt;Environment&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;Microsoft Sentinel (Log Analytics workspace)&lt;/LI&gt;&lt;LI&gt;Logic Apps (Consumption plan)&lt;/LI&gt;&lt;LI&gt;Trigger: native &lt;STRONG&gt;Microsoft Sentinel&lt;/STRONG&gt; connector, "Incident" trigger (&lt;EM&gt;/incident-creation&lt;/EM&gt; path)&lt;/LI&gt;&lt;LI&gt;Authentication: system-assigned Managed Identity&lt;/LI&gt;&lt;LI&gt;Same subscription, resource group, and region as the Sentinel workspace&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;Problem&lt;/H3&gt;&lt;P&gt;Two Logic Apps, both triggered by the native Microsoft Sentinel incident trigger, both using a system-assigned managed identity with the &lt;STRONG&gt;Microsoft Sentinel Responder&lt;/STRONG&gt; role granted on the workspace. Same subscription, same resource group, same region.&lt;/P&gt;&lt;P&gt;Only one of the two appeared in the &lt;STRONG&gt;"Run playbook"&lt;/STRONG&gt; dropdown when configuring an Automation Rule in Sentinel. The other was simply absent — no error message, no warning, nothing in the run history to explain it.&lt;/P&gt;&lt;H3&gt;Investigation&lt;/H3&gt;&lt;P&gt;The usual suspects were checked and ruled out one by one:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;API connection health&lt;/STRONG&gt; — one &lt;EM&gt;azuresentinel&lt;/EM&gt; connection was indeed in an "Error" state, but it turned out not to be the one referenced by the affected trigger.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Managed identity RBAC&lt;/STRONG&gt; — the &lt;EM&gt;Microsoft Sentinel Responder&lt;/EM&gt; role was correctly assigned to the Logic App's managed identity on the Sentinel workspace.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;User's own RBAC/PIM role&lt;/STRONG&gt; — the &lt;EM&gt;Logic App Contributor&lt;/EM&gt; role (required for the account configuring the Automation Rule to even see the resource) was active via PIM at the time of testing.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Region/subscription/resource group&lt;/STRONG&gt; — identical for both Logic Apps.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Trigger type&lt;/STRONG&gt; — both used the native "Incident in Microsoft Sentinel" trigger added through the visual designer, not a generic HTTP trigger or a deprecated connector.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Every documented requirement was met. The playbook was still invisible.&lt;/P&gt;&lt;H3&gt;Root Cause&lt;/H3&gt;&lt;P&gt;Comparing the raw JSON (&lt;STRONG&gt;Logic app &amp;gt; Development tools &amp;gt; Code view&lt;/STRONG&gt;) revealed the actual difference.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Working Logic App (visible in the picker):&lt;/STRONG&gt;&lt;/P&gt;&lt;PRE&gt;"triggers": {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;"Microsoft_Sentinel_incident": {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"type": "ApiConnectionWebhook",&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"inputs": {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"body": { "callback_url": "@{listCallbackUrl()}" },&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"path": "/incident-creation"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;}&lt;BR /&gt;&amp;nbsp;&amp;nbsp;}&lt;BR /&gt;}&lt;/PRE&gt;&lt;P&gt;&lt;STRONG&gt;Broken Logic App (invisible in the picker):&lt;/STRONG&gt;&lt;/P&gt;&lt;PRE&gt;"triggers": {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;"Incident_dans_Microsoft_Sentinel": {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"type": "ApiConnectionWebhook",&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"inputs": {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"body": { "callback_url": "@listCallbackUrl()" },&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"path": "/incident-creation"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;}&lt;BR /&gt;&amp;nbsp;&amp;nbsp;}&lt;BR /&gt;}&lt;/PRE&gt;&lt;P&gt;The connector type and the path (&lt;EM&gt;/incident-creation&lt;/EM&gt;) are identical. The one meaningful structural difference is the &lt;STRONG&gt;trigger's action name&lt;/STRONG&gt;: &lt;EM&gt;Microsoft_Sentinel_incident&lt;/EM&gt; versus &lt;EM&gt;Incident_dans_Microsoft_Sentinel&lt;/EM&gt;.&lt;/P&gt;&lt;P&gt;The second Logic App's trigger had been added while the Azure portal was set to &lt;STRONG&gt;French&lt;/STRONG&gt;. The designer generated a localized action name instead of the canonical English one.&lt;/P&gt;&lt;P&gt;Everything points to Sentinel's playbook discovery mechanism scanning Logic App definitions for that &lt;STRONG&gt;exact canonical action name&lt;/STRONG&gt; (&lt;EM&gt;Microsoft_Sentinel_incident&lt;/EM&gt;) to identify a resource as a valid Sentinel playbook — rather than relying solely on the connector type or the webhook path, as one would reasonably expect.&lt;/P&gt;&lt;H2&gt;Fix&lt;/H2&gt;&lt;P&gt;Renaming the trigger's action key in the JSON to the canonical name was enough:&lt;/P&gt;&lt;PRE&gt;"triggers": {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;"Microsoft_Sentinel_incident": {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;...&lt;BR /&gt;&amp;nbsp;&amp;nbsp;}&lt;BR /&gt;}&lt;/PRE&gt;&lt;P&gt;No permission, connection, or region change was required — only this rename.&lt;/P&gt;&lt;H2&gt;Takeaways&lt;/H2&gt;&lt;OL&gt;&lt;LI&gt;The Sentinel Automation Rule playbook picker appears to depend on the &lt;STRONG&gt;exact trigger action name&lt;/STRONG&gt;, not just its type or functional behavior — a dependency that isn't documented anywhere in the official Microsoft docs as of this writing.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;The Azure portal's display language at the time a trigger is added has a direct impact&lt;/STRONG&gt; on that Logic App's compatibility with Sentinel Automation Rules.&lt;/LI&gt;&lt;LI&gt;A playbook can be &lt;STRONG&gt;fully functional&lt;/STRONG&gt; (running without errors when triggered manually or through an older automation mechanism) while still being invisible in the newer Automation Rule selector — which makes this particular issue easy to miss, since nothing explicitly flags it.&lt;/LI&gt;&lt;/OL&gt;&lt;H2&gt;Recommendations&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Temporarily switch the Azure portal to English&lt;/STRONG&gt; (Portal settings &amp;gt; Language and region) before adding a Sentinel trigger to a Logic App, if your team usually works in another language.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;If an existing Logic App won't show up&lt;/STRONG&gt; despite an otherwise correct configuration, check the trigger's action name in the JSON code view first — it's a 30-second check that can save hours of RBAC/connection troubleshooting.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Document this in your internal runbooks&lt;/STRONG&gt; if your team works in a localized portal — this kind of detail is easy to lose and can cost significant troubleshooting time down the line.&lt;/LI&gt;&lt;/UL&gt;&lt;HR /&gt;&lt;P&gt;&lt;EM&gt;Has anyone else run into similar localization-related quirks in Sentinel or Logic Apps? Would be curious to hear about other cases in the comments.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Sep 2026 17:14:52 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-sentinel/the-hidden-reason-your-sentinel-playbook-won-t-show-up-in/m-p/4555416#M12973</guid>
      <dc:creator>Blackfoundry</dc:creator>
      <dc:date>2026-09-10T17:14:52Z</dc:date>
    </item>
    <item>
      <title>The Hidden Reason Your Sentinel Playbook Won't Show Up in Automation Rules (It's Not RBAC)</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-sentinel/the-hidden-reason-your-sentinel-playbook-won-t-show-up-in/m-p/4555399#M12972</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;P&gt;If a Logic App using the native Microsoft Sentinel incident trigger doesn't show up in the "Run playbook" picker of an Automation Rule — even though permissions, region, and connection are all correct — check the internal &lt;STRONG&gt;action name&lt;/STRONG&gt; of the trigger in the JSON code view. If the Logic App was created while the Azure portal was set to a non-English language, the designer may generate a localized action name instead of the expected &lt;EM&gt;Microsoft_Sentinel_incident&lt;/EM&gt;, and the playbook won't be picked up.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;H3&gt;Environment&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;Microsoft Sentinel (Log Analytics workspace)&lt;/LI&gt;&lt;LI&gt;Logic Apps (Consumption plan)&lt;/LI&gt;&lt;LI&gt;Trigger: native &lt;STRONG&gt;Microsoft Sentinel&lt;/STRONG&gt; connector, "Incident" trigger (&lt;EM&gt;/incident-creation&lt;/EM&gt; path)&lt;/LI&gt;&lt;LI&gt;Authentication: system-assigned Managed Identity&lt;/LI&gt;&lt;LI&gt;Same subscription, resource group, and region as the Sentinel workspace&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;Problem&lt;/H3&gt;&lt;P&gt;Two Logic Apps, both triggered by the native Microsoft Sentinel incident trigger, both using a system-assigned managed identity with the &lt;STRONG&gt;Microsoft Sentinel Responder&lt;/STRONG&gt; role granted on the workspace. Same subscription, same resource group, same region.&lt;/P&gt;&lt;P&gt;Only one of the two appeared in the &lt;STRONG&gt;"Run playbook"&lt;/STRONG&gt; dropdown when configuring an Automation Rule in Sentinel. The other was simply absent — no error message, no warning, nothing in the run history to explain it.&lt;/P&gt;&lt;H3&gt;Investigation&lt;/H3&gt;&lt;P&gt;The usual suspects were checked and ruled out one by one:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;API connection health&lt;/STRONG&gt; — one &lt;EM&gt;azuresentinel&lt;/EM&gt; connection was indeed in an "Error" state, but it turned out not to be the one referenced by the affected trigger.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Managed identity RBAC&lt;/STRONG&gt; — the &lt;EM&gt;Microsoft Sentinel Responder&lt;/EM&gt; role was correctly assigned to the Logic App's managed identity on the Sentinel workspace.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;User's own RBAC/PIM role&lt;/STRONG&gt; — the &lt;EM&gt;Logic App Contributor&lt;/EM&gt; role (required for the account configuring the Automation Rule to even see the resource) was active via PIM at the time of testing.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Region/subscription/resource group&lt;/STRONG&gt; — identical for both Logic Apps.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Trigger type&lt;/STRONG&gt; — both used the native "Incident in Microsoft Sentinel" trigger added through the visual designer, not a generic HTTP trigger or a deprecated connector.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Every documented requirement was met. The playbook was still invisible.&lt;/P&gt;&lt;H3&gt;Root Cause&lt;/H3&gt;&lt;P&gt;Comparing the raw JSON (&lt;STRONG&gt;Logic app &amp;gt; Development tools &amp;gt; Code view&lt;/STRONG&gt;) revealed the actual difference.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Working Logic App (visible in the picker):&lt;/STRONG&gt;&lt;/P&gt;&lt;PRE&gt;"triggers": {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;"Microsoft_Sentinel_incident": {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"type": "ApiConnectionWebhook",&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"inputs": {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"body": { "callback_url": "@{listCallbackUrl()}" },&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"path": "/incident-creation"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;}&lt;BR /&gt;&amp;nbsp;&amp;nbsp;}&lt;BR /&gt;}&lt;/PRE&gt;&lt;P&gt;&lt;STRONG&gt;Broken Logic App (invisible in the picker):&lt;/STRONG&gt;&lt;/P&gt;&lt;PRE&gt;"triggers": {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;"Incident_dans_Microsoft_Sentinel": {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"type": "ApiConnectionWebhook",&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"inputs": {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"body": { "callback_url": "@listCallbackUrl()" },&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"path": "/incident-creation"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;}&lt;BR /&gt;&amp;nbsp;&amp;nbsp;}&lt;BR /&gt;}&lt;/PRE&gt;&lt;P&gt;The connector type and the path (&lt;EM&gt;/incident-creation&lt;/EM&gt;) are&lt;/P&gt;</description>
      <pubDate>Thu, 10 Sep 2026 16:18:38 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-sentinel/the-hidden-reason-your-sentinel-playbook-won-t-show-up-in/m-p/4555399#M12972</guid>
      <dc:creator>Blackfoundry</dc:creator>
      <dc:date>2026-09-10T16:18:38Z</dc:date>
    </item>
    <item>
      <title>MDE endpoint to Purview onboarding</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-purview/mde-endpoint-to-purview-onboarding/m-p/4554345#M2934</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I have Microsoft defender endpoint plan 2 onboarded endpoints in my organisation, as a new dlp functionality i need to test purview DLP functionality for few of my endpoints but i see that it needs to be enabled the device onboarding in microsoft purview under settings, and it also says that all MDE endpoints will populate automatically here and onboarded since they alreay have MDE, now my worry is, if i enable this and all endpoints start onboarding under purview automatically and if we start facing any difficulty with enspoints how to stop or rollback that since no. of endpoints are more than 500. although i have checked there are no DLP settings or policies configured in the purview. is there any way to include only few endpoints to purview and test before enabling the tenant level button?&lt;/P&gt;&lt;P&gt;is there a way we can disable the button if we enable it and we start encountring any issues with endpoints?&lt;/P&gt;&lt;P&gt;Appreciate help on this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Vipin&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2026 10:33:49 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-purview/mde-endpoint-to-purview-onboarding/m-p/4554345#M2934</guid>
      <dc:creator>vipinjain</dc:creator>
      <dc:date>2026-09-08T10:33:49Z</dc:date>
    </item>
    <item>
      <title>Securing Your Certification Authorities (Practical PKI Part 4)</title>
      <link>https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/securing-your-certification-authorities-practical-pki-part-4/ba-p/4549029</link>
      <description>&lt;P&gt;My name is Ron Arestia, and I am a Security Researcher with Microsoft’s Detection and Response Team (DART). We respond to customer cybersecurity incidents to assist with containment and recovery from threat actors. In this blog post, we work to enhance the security position of PKI by focusing on the most vital component first: your Certification Authorities (CAs). This is part 4 of a series on practical PKI implementation based on my experience with customer interactions working as a Microsoft engineer.&lt;/P&gt;
&lt;P&gt;Feel free to catch up on previous blog posts or jump right into this one&lt;/P&gt;
&lt;P&gt;&lt;A href="https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/secure-configuration-and-hardening-of-active-directory-certificate-services/4463240" target="_blank" rel="noopener"&gt;Secure Configuration and Hardening of Active Directory Certificate Services&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/implementing-and-managing-an-adcs-offline-root-certificate-authority-part-1/4468175" target="_blank" rel="noopener"&gt;Implementing and Managing an ADCS Offline Root Certificate Authority (Practical PKI Part 1)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/crl--aia-publishing-guidance-practical-pki-part-2/4485713" target="_blank" rel="noopener"&gt;CRL &amp;amp; AIA Publishing Guidance (Practical PKI Part 2)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/purpose-for-your-pki-practical-pki-part-3/4512518" target="_blank" rel="noopener"&gt;Purpose For Your PKI (Practical PKI Part 3)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Before you start down this path, review &lt;A href="https://docs.specterops.io/ghostpack-docs/Certify.wik-mdx/overview" target="_blank" rel="noopener"&gt;SpecterOps Exploitation of Certificate Services framework&lt;/A&gt;. This is the de facto standard against which you should secure your PKI. If you cannot protect against misconfigurations, threat actors are going to leverage them against you.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Please note: I will &lt;EM&gt;not &lt;/EM&gt;be demonstrating any red team/hacking tools in this blog out of an abundance of caution. There are myriad guides on how to leverage these tools against an ADCS PKI. My goal with this series is to provide best practice guidance and learn to think like a defensive security professional specific to PKI. &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Throughout this and future blog posts, I am going to reference the Exploitation of Certificate Services framework as ESC and reference specific ESC exploits. Take a moment to cross-reference what is written here with the finding to understand how misconfigurations can be abused.&lt;/P&gt;
&lt;H1&gt;Root CA Security&lt;/H1&gt;
&lt;P&gt;I would advise anyone jumping into this blog series at this point to go back and review previous posts about root CA security and best practices. So much has already been written about this, so I will be brief in this section to focus on downstream security concepts.&lt;/P&gt;
&lt;P&gt;If a root CA is truly offline and protected by an HSM, the risk of compromise is exceptionally low albeit not zero. While I do not know of any specific anecdotal evidence of an offline root CA compromise, I am sure Hollywood could produce some Mission Impossible-level script. In reality, most threat actors are maneuvering around an enterprise via the identity plane, and the PKI infrastructure is the icing on a very scrumptious cake once they have achieved domain dominance. The idea of air-gapping your root CA does not mean your enterprise is insulated from a PKI attack, but the root of trust for your organization is sufficiently protected that rebuilding the subordinate infrastructure is much quicker than having to perform a greenfield deployment of your PKI.&lt;/P&gt;
&lt;P&gt;Recall that your root CA, as with all root CAs, leverages a self-signed certificate. That certificate is not by itself very remarkable except that it signs all of the subordinate/issuing/registration authorities AND all of the certificate revocation lists (CRLs). If a threat actor cannot compromise the root CA, in the case of a cybersecurity incident involving the subordinate infrastructure, the impacted organization can simply revoke all of the subordinate infrastructure certificates which will then be added to the CRL. That will subsequently invalidate any and all certificates issued by those subordinate CAs, but securely rebuilding the subordinate infrastructure means that an organization only needs to hydrate their issuance/registration infrastructure while the root remains trusted by the entire organization. This reduces the recovery time significantly since the root infrastructure is still trusted across the enterprise.&lt;/P&gt;
&lt;P&gt;If your root CA is NOT offline, it needs to be. There is no way to adequately mitigate risk against your PKI if the root CA is enterprise-joined. If your root CA is also your primary issuer, you should migrate to a two-tier PKI hierarchy after assessing need and impact. Threat actors are attracted to the highest branch in your organization’s technical hierarchy. If the root CA is online, they will find it, and chances are good that they will figure out how to exploit it.&lt;/P&gt;
&lt;H1&gt;Enterprise CA Security&lt;/H1&gt;
&lt;P&gt;One piece of advice throughout this entire process: &lt;STRONG&gt;take your time&lt;/STRONG&gt;. There is no reason for you to rush this process or otherwise expedite your PKI into production. “Haste makes waste,” as goes the old proverb. While it is absolutely possible to stand up a servicing infrastructure in a brief period of time, you will miss critical security controls that will put your organization at risk. Take pains to document exhaustively your desired PKI configuration: CA names, supported encryption types, minimum key sizes, certificate and CRL validity periods, template types and purposes, and groups and users used across the PKI for management of the CA, templates, and issuance. Documentation of your PKI should be the overwhelming majority of the time spent building it. Every other component falls into place with a proper framework established in advance.&lt;/P&gt;
&lt;P&gt;Your issuers are going to be front and center to most of your PKI operations. &lt;STRONG&gt;Do not co-locate services on your issuing CAs&lt;/STRONG&gt;. Your issuing CAs have a single purpose: as an enterprise issuing certificate authority. The only service installed on these systems should be the ADCS Certification Authority role. &lt;STRONG&gt;Do not install the CA role on a domain controller.&lt;/STRONG&gt; (I cannot stress this enough!) Do not install any other Windows role or feature, even those under the ADCS role. Every additional role you install on your issuing CA increases its risk footprint and your administrative burden. Keep third party tools, agents, services, APIs, etc. to the bare minimum. If this is installed in Tier 0 of a properly tiered security environment, the risk should be much lower. &lt;STRONG&gt;PKI is a Tier 0 system!&lt;/STRONG&gt; It should be treated with the same level of security as your domain controllers.&lt;/P&gt;
&lt;P&gt;For both (Offline) Root and Issuing CAs, the theft of a private key is considered a domain persistence technique, and the CA should be considered compromised even if there is no evidence of exfiltration.&lt;/P&gt;
&lt;H2&gt;Proper CA Rights Management&lt;/H2&gt;
&lt;P&gt;Before you get started with your PKI implementation, you should create a handful of new security groups in Active Directory to directly manage your CAs, templates, and issuance. By default, ADCS assumes Domain Admins and Enterprise Admins are administering your PKI. &lt;STRONG&gt;Do not leave this configuration in place.&lt;/STRONG&gt; This does not comply with any least privilege guidance, and it leaves your PKI in a position where it can be compromised either directly or indirectly through lateral account movement once either of those groups is compromised by a threat actor.&lt;/P&gt;
&lt;P&gt;To manage your issuing CA, create a security group named “CA Admins” or something similar that meets your organizational naming standards or needs. CA Admins have the sole responsibility of managing the CAs themselves. These are the admins who will open the Certification Authority management console (MMC), modify the CA configuration, when necessary, perform signing operations (e.g., manual CRL issuance), revoke certificates, perform backups, and maintain the overall health of the PKI. (Figure 1)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;Figure 1&lt;/P&gt;
&lt;P&gt;To manage certificate issuance for your enterprise, create a security group named “Certificate Managers” or something similar. Certificate Managers have the responsibility of scrutinizing certificates pending issuance. This should be a small group of trusted admins who are trained to review certificate requests and perform issuance based on security and risk standards established for your enterprise. (Figure 2)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;Figure 2&lt;/P&gt;
&lt;P&gt;Each of these groups will be configured in the ADCS certification authority MMC with their respective rights. Each one of these groups is single-purpose. None of them should have the ability to request certificates, and ideally, the membership of these groups should never overlap. The purpose here is to provide role separation. No one should be able to request a certificate and approve their own request, for example.&lt;/P&gt;
&lt;P&gt;To manage certificate templates for your enterprise, create a security group named “Certificate Template Managers” or something similar. Certificate Template Managers are responsible for creation, management, and maintenance of all certificate templates in the enterprise. These individuals should have a comprehensive understanding of certificate template creation, purposeful provisioning of new templates, and management of access control lists (ACLs) on templates. These individuals are your first line of defense against misconfiguration of certificate templates that lead to compromise through many of the Exploitation of Certificate Services (ESC) methods. Note: this requires manipulation of a container in the Active Directory Configuration partition and may not be explicitly necessary if Certificate Managers is properly constrained. (Figure 3)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;Figure 3&lt;/P&gt;
&lt;P&gt;These configurations made during inception of the PKI should cover you against exploitation of ESC7 specifically and require a very narrowly-scoped attack path for a threat actor to leverage it. I want to caution that this is not foolproof and does not account for exploitation of the administrative accounts themselves. If a threat actor gains control of one of the administrative accounts, they will have exploitation capability of whatever administrative function(s) is/are in scope for that user. This is why role separation is such an important concept for PKI management. In a true cybersecurity incident, the threat actor would have to gain access to multiple accounts to take full advantage of the enterprise PKI.&lt;/P&gt;
&lt;H2&gt;Configure Role Separation at the CA&lt;/H2&gt;
&lt;P&gt;In addition to proper assignment of roles, you can enforce strict role separation by implementing the role separation registry setting for ADCS (Figure 4):&lt;/P&gt;
&lt;LI-CODE lang=""&gt;Certutil -setreg CA\RoleSeparationEnabled 1&lt;/LI-CODE&gt;&lt;img /&gt;
&lt;P class="lia-align-center"&gt;Figure 4&lt;/P&gt;
&lt;P&gt;Before you do this, one caution: &lt;STRONG&gt;this will force ADCS to only allow one role per account&lt;/STRONG&gt;. If, for example, you have a user who is both a CA Admin and a Certificate Manager, with role separation enabled, they will not be able to perform &lt;EM&gt;either&lt;/EM&gt; action. ADCS role separation role sets and only permits them to hold one. While this configuration is exceptionally strong at preventing misuse of the PKI, &lt;STRONG&gt;it can lock out your admins from administering the PKI at all! &lt;/STRONG&gt;As such, you should have high confidence that your roles are properly assigned prior to changing this configuration setting. This setting is global meaning that it applies to any and all roles assigned to the PKI, not just the privileged roles.&lt;/P&gt;
&lt;P&gt;Good news, however, is that if this happens during your testing, you can log into the CA directly and remove the role separation registry configuration. This will allow you to go back to proper configuration to resolve the overlapping identities or avoid this setting going forward but be aware of service interruption as a result.&lt;/P&gt;
&lt;P&gt;It is possible to manage a secure PKI without this setting, however. It is one of many tools at your disposal.&lt;/P&gt;
&lt;H2&gt;Disable Request Attribute SAN (EDITF_ATTRIBUTESUBJECTALTNAME2)&lt;/H2&gt;
&lt;P&gt;Microsoft introduced strong certificate mapping limitations as part of &lt;A href="https://support.microsoft.com/en-US/servicing/os/windows-server/2022/05/kb5014754-certificate-based-authentication-changes-on-windows-domain-controllers" target="_blank" rel="noopener"&gt;KB5014754&lt;/A&gt; in response to a number of CVEs that surfaced back in 2022 (&lt;A href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-34691" target="_blank" rel="noopener"&gt;CVE-2022-34691,&lt;/A&gt;&lt;A href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26931" target="_blank" rel="noopener"&gt;CVE-2022-26931&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26923" target="_blank" rel="noopener"&gt;CVE-2022-26923&lt;/A&gt;). This protection makes exploitation of ESC6 difficult but not impossible. In concert with ESC9 or ESC16, this could still be exploited even with properly-patched domain controllers.&lt;/P&gt;
&lt;P&gt;This misconfiguration (Figure 5) allows a requester to submit any subject alternative name (SAN) they want against a certificate template, even if the template does not allow it. To harden your CAs against this attack, you can make a registry change to disallow this behavior:&lt;/P&gt;
&lt;LI-CODE lang=""&gt;Certutil -setreg policy\EditFlags -EDITF_ATTRIBUTESUBJECTALTNAME2&lt;/LI-CODE&gt;&lt;img /&gt;
&lt;P class="lia-align-center"&gt;Figure 5&lt;/P&gt;
&lt;P&gt;It is important to note that if any other CA administrative escalation vulnerabilities exist, a threat actor can remove this attribute without difficulty. It does require a restart of the service, so monitoring your ADCS service health can help to identify unwanted changes.&lt;/P&gt;
&lt;H2&gt;Protect the ICertPassage RPC Interface&lt;/H2&gt;
&lt;P&gt;ESC11 is a more recent exploitation that allows relaying of NTLM authentication to RPC on a vulnerable CA. This could allow an attacker to request certificates on behalf of other domain principals. (Figure 6)&lt;/P&gt;
&lt;P&gt;To harden your CAs against this attack, you can make a registry change to disallow this behavior:&lt;/P&gt;
&lt;LI-CODE lang=""&gt;Certutil -setreg CA\InterfaceFlags +IF_ENFORCEENCRYPTICERTREQUEST&lt;/LI-CODE&gt;&lt;img /&gt;
&lt;P class="lia-align-center"&gt;Figure 6&lt;/P&gt;
&lt;P&gt;Note that this will force the CA to accept only RPC connections that are both signed and encrypted.&lt;/P&gt;
&lt;H2&gt;Check the CA Policy Module for Disabled Extensions&lt;/H2&gt;
&lt;P&gt;ESC16 covers another CA misconfiguration where a specific OID (1.3.6.1.4.1.311.25.2) is disabled in the CA Policy Module. This extension (szOID_NTDS_CA_SECURITY_EXT) will force the CA to omit a SID security extension in issued certificates which allows for exploitation of ESC6 and/or ESC7. This is functionally similar to ESC9, but this is a global setting whereas ESC9 is template-specific. (Figure 7)&lt;/P&gt;
&lt;P&gt;To harden your CAs against this attack, review the disabled extension list on your CA:&lt;/P&gt;
&lt;LI-CODE lang=""&gt;Certutil -getreg policy\DisableExtensionList&lt;/LI-CODE&gt;&lt;img /&gt;
&lt;P class="lia-align-center"&gt;Figure 7&lt;/P&gt;
&lt;P class="lia-align-center"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this specific OID (1.3.6.1.4.1.311.25.2) is in the disabled extension list (Figure 8), remove it:&lt;/P&gt;
&lt;LI-CODE lang=""&gt;Certutil -setreg policy\DisableExtensionList -1.3.6.1.4.1.311.25.2&lt;/LI-CODE&gt;&lt;img /&gt;
&lt;P class="lia-align-center"&gt;Figure 8&lt;/P&gt;
&lt;P class="lia-align-center"&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;Figure 9&lt;/P&gt;
&lt;H2&gt;Wrapping Up&lt;/H2&gt;
&lt;P&gt;As I said at the beginning of this post, take your time setting up your CAs. If you configure them with proper protections from the word “go,” you will harden your PKI sufficiently to confound even the most determined adversaries.&lt;/P&gt;
&lt;P&gt;Of the sixteen published ESC vulnerabilities, five of them are directly attributed to CA security misconfigurations (ESC 6, 7, 8, 11, &amp;amp; 16). In this blog post, we provided guidance for all of these except ESC8 which deals with Certification Authority Web Enrollment (CAWE), Certificate Enrollment Service (CES), Certificate Enrollment Policy (CEP), and Network Device Enrollment Service (NDES). In my introduction, I reinforced that your Certification Authority should be &lt;EM&gt;single-purpose&lt;/EM&gt;. Do NOT install other ADCS roles on your CA. You introduce risks to which the CA itself should not be exposed. If you follow this guidance, ESC8 will not present a problem, but we will cover it in more detail in a future blog post.&lt;/P&gt;
&lt;P&gt;In Part 5, we will dive deep into the configuration of your certificate templates to address a multitude of vulnerabilities that are present from oftentimes simple misconfigurations that can lead to big headaches.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2026 10:57:56 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/securing-your-certification-authorities-practical-pki-part-4/ba-p/4549029</guid>
      <dc:creator>RonArestia</dc:creator>
      <dc:date>2026-09-07T10:57:56Z</dc:date>
    </item>
    <item>
      <title>How can I unlock my account?</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/how-can-i-unlock-my-account/m-p/4553778#M10027</link>
      <description>&lt;P&gt;I've tried contacting support several times, both through the form and live chat, but neither resolved anything. On the form, they either stopped responding or started giving lame excuses, and on the live chat they even told me to create another account and buy what I had on the lost account. Is there another way to contact a human at Microsoft, or am I just going to waste my time talking to bots and receiving excuses?&lt;/P&gt;</description>
      <pubDate>Sun, 06 Sep 2026 19:40:56 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/how-can-i-unlock-my-account/m-p/4553778#M10027</guid>
      <dc:creator>PadreShrek</dc:creator>
      <dc:date>2026-09-06T19:40:56Z</dc:date>
    </item>
    <item>
      <title>Monitoring work from home</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-sentinel/monitoring-work-from-home/m-p/4553713#M12971</link>
      <description>&lt;P&gt;My boss has asked me if there is a way to see just how "busy" people who are working from home are.&amp;nbsp; I have this data in Sentinel:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Entra sign-in logs&lt;/P&gt;&lt;P&gt;Defender for Endpoint logs&lt;/P&gt;&lt;P&gt;Office 365 logs&lt;/P&gt;&lt;P&gt;Most, if not all, on premise AD login events&lt;/P&gt;&lt;P&gt;Netskope (current ZTNA solution) logs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have my known office location IPs so i could just exclude those and look for activity from other IPs however many times people will work in the morning or on the way to work appearing from a non corporate IP, come into the office appearing to come from a corporate IP, and then from home again in the evening.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I need a way to query Sentinel looking for people who appear to be working but not coming from Corp IP.&amp;nbsp; If they came from different IPs on the same day including Corp check to see if those non Corp are before and after business hours and exclude those.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone know of a good query to achieve this?&amp;nbsp; Or maybe a tool that can extract and generate a report?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 06 Sep 2026 03:34:27 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-sentinel/monitoring-work-from-home/m-p/4553713#M12971</guid>
      <dc:creator>lfk73</dc:creator>
      <dc:date>2026-09-06T03:34:27Z</dc:date>
    </item>
    <item>
      <title>Check This Out! (CTO!) Guide (September 2026)</title>
      <link>https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/check-this-out-cto-guide-september-2026/ba-p/4553591</link>
      <description>&lt;P&gt;&lt;A href="https://techcommunity.microsoft.com/users/tysonpaul/322025" data-lia-auto-title="Member: TysonPaul | Microsoft Community Hub" data-lia-auto-title-active="0" target="_blank"&gt;Member: TysonPaul | Microsoft Community Hub&lt;/A&gt;&lt;/P&gt;
&lt;DIV class="card"&gt;
&lt;H2&gt;&lt;A href="https://techcommunity.microsoft.com/blog/azurehighperformancecomputingblog/retirement-of-microsoft-hpc-pack/4550183" target="_blank" rel="noopener noreferrer"&gt;Retirement of Microsoft HPC Pack&lt;/A&gt;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Team Blog:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/category/azure/blog/azurehighperformancecomputingblog" target="_blank" rel="noopener noreferrer"&gt;Azure High Performance Computing (HPC)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Author:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/users/xinxin/1593644" target="_blank" rel="noopener noreferrer"&gt;XinXin&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Published:&lt;/STRONG&gt; 08/25/2026&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; Microsoft HPC Pack, a Windows-based HPC scheduler, will be retired, with support ending August 27, 2027. No new updates, features, or enhancements will be provided after this date, and only limited security support is available during the retirement period. Customers are advised to migrate to Azure Batch or other Azure services for HPC workloads. Existing deployments will not be forcibly disabled but will be unsupported after the retirement date. Microsoft encourages early migration planning and feedback to facilitate a smooth transition and address customer concerns.&lt;/P&gt;
&lt;IMG style="max-width: 10%; height: auto;" src="data:image/jpeg;base64,iVBORw0KGgoAAAANSUhEUgAAAEsAAABLCAMAAAAPkIrYAAAAAXNSR0IB2cksfwAAAAlwSFlzAAALEwAACxMBAJqcGAAAAHtQTFRFAAAA8lAi8lAi8lAi8lAif7oAf7oAf7oAf7oA8lAi8lAi8lAif7oAf7oAf7oA8lAi8lAif7oAf7oA8lAif7oAAaTvAaTvAaTvAaTv/7kB/7kB/7kB/7kBAaTvAaTvAaTv/7kB/7kB/7kBAaTvAaTv/7kB/7kBAaTv/7kBfMz9mwAAACl0Uk5TADt7ag4Oans7/90eHt3/wBoawAMDDh4aAwMaHg5q3cDA3Wp7//97OzspjeVtAAAAlElEQVR4nO3WqwqAQBSEYY+uWiyCBm/J4Pu/jRhMBi8IFsHLCoZ9gCkbRGby8OVfHHuTD1sCQBHtw89hLDdE1h4h6zxp0aJFixYtWrT+bXnA8mWL5QbWZSyFLG9NHmTd9hszhY05ZrAxB2NVsEWnPECf3lg1+F3HXAQKWB0tWrRo0aJFi9a/rUYjaymR5bb2G/OL1guM9e5M8yBd4gAAAABJRU5ErkJggg==" alt="Embedded Image" /&gt;&lt;/DIV&gt;
&lt;DIV class="card"&gt;
&lt;H2&gt;&lt;A href="https://techcommunity.microsoft.com/blog/azurenetworkingblog/azure-dns--traffic-manager-linked-records/4548221" target="_blank" rel="noopener noreferrer"&gt;Azure DNS + Traffic Manager linked records&lt;/A&gt;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Team Blog:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/category/azure/blog/azurenetworkingblog" target="_blank" rel="noopener noreferrer"&gt;Azure Networking&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Author:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/users/atiy/3601757" target="_blank" rel="noopener noreferrer"&gt;atiy&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Published:&lt;/STRONG&gt; 08/26/2026&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; Azure DNS Traffic Manager linked records allow direct, managed integration between Azure DNS and Traffic Manager profiles, enabling endpoint IP addresses to be returned without an intermediate CNAME. This improves DNS responses, supports zone-apex routing, and enhances DNSSEC compatibility while preserving Traffic Manager’s routing intelligence, health monitoring, and failover. The article provides a practical guide for configuring, validating, and testing this feature, currently in public preview, using a multi-region Contoso scenario. The feature simplifies DNS architecture and client experience, making global routing more seamless and secure, especially for root domains.&lt;/P&gt;
&lt;IMG style="max-width: 10%; height: auto;" src="data:image/jpeg;base64,iVBORw0KGgoAAAANSUhEUgAAAEsAAABLCAMAAAAPkIrYAAAAAXNSR0IB2cksfwAAAAlwSFlzAAALEwAACxMBAJqcGAAAAHtQTFRFAAAA8lAi8lAi8lAi8lAif7oAf7oAf7oAf7oA8lAi8lAi8lAif7oAf7oAf7oA8lAi8lAif7oAf7oA8lAif7oAAaTvAaTvAaTvAaTv/7kB/7kB/7kB/7kBAaTvAaTvAaTv/7kB/7kB/7kBAaTvAaTv/7kB/7kBAaTv/7kBfMz9mwAAACl0Uk5TADt7ag4Oans7/90eHt3/wBoawAMDDh4aAwMaHg5q3cDA3Wp7//97OzspjeVtAAAAlElEQVR4nO3WqwqAQBSEYY+uWiyCBm/J4Pu/jRhMBi8IFsHLCoZ9gCkbRGby8OVfHHuTD1sCQBHtw89hLDdE1h4h6zxp0aJFixYtWrT+bXnA8mWL5QbWZSyFLG9NHmTd9hszhY05ZrAxB2NVsEWnPECf3lg1+F3HXAQKWB0tWrRo0aJFi9a/rUYjaymR5bb2G/OL1guM9e5M8yBd4gAAAABJRU5ErkJggg==" alt="Embedded Image" /&gt;&lt;/DIV&gt;
&lt;DIV class="card"&gt;
&lt;H2&gt;&lt;A href="https://techcommunity.microsoft.com/blog/azurenetworkingblog/azure-virtual-network-routing-appliance-is-now-generally-available/4543616" target="_blank" rel="noopener noreferrer"&gt;Azure Virtual Network routing appliance is now generally available&lt;/A&gt;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Team Blog:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/category/azure/blog/azurenetworkingblog" target="_blank" rel="noopener noreferrer"&gt;Azure Networking&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Author:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/users/anshu_verma/2767305" target="_blank" rel="noopener noreferrer"&gt;Anshu_Verma&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Published:&lt;/STRONG&gt; 08/04/2026&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; Azure Virtual Network routing appliance is now generally available, offering a managed, platform-native routing service for high-performance connectivity across Azure virtual networks. Designed for modern cloud demands—including AI, private connectivity, IPv6 adoption, and multi-region architectures—it enables scalable hub-and-spoke and private network models, simplifies operations, and supports both IPv4 and IPv6. With built-in resiliency, Azure-native management, configurable bandwidth, and integrated monitoring, it helps organizations build large-scale, efficient, and innovative network infrastructures, accelerating cloud and AI initiatives while reducing operational complexity.&lt;/P&gt;
&lt;IMG style="max-width: 10%; height: auto;" src="data:image/jpeg;base64,iVBORw0KGgoAAAANSUhEUgAAAEsAAABLCAMAAAAPkIrYAAAAAXNSR0IB2cksfwAAAAlwSFlzAAALEwAACxMBAJqcGAAAAHtQTFRFAAAA8lAi8lAi8lAi8lAif7oAf7oAf7oAf7oA8lAi8lAi8lAif7oAf7oAf7oA8lAi8lAif7oAf7oA8lAif7oAAaTvAaTvAaTvAaTv/7kB/7kB/7kB/7kBAaTvAaTvAaTv/7kB/7kB/7kBAaTvAaTv/7kB/7kBAaTv/7kBfMz9mwAAACl0Uk5TADt7ag4Oans7/90eHt3/wBoawAMDDh4aAwMaHg5q3cDA3Wp7//97OzspjeVtAAAAlElEQVR4nO3WqwqAQBSEYY+uWiyCBm/J4Pu/jRhMBi8IFsHLCoZ9gCkbRGby8OVfHHuTD1sCQBHtw89hLDdE1h4h6zxp0aJFixYtWrT+bXnA8mWL5QbWZSyFLG9NHmTd9hszhY05ZrAxB2NVsEWnPECf3lg1+F3HXAQKWB0tWrRo0aJFi9a/rUYjaymR5bb2G/OL1guM9e5M8yBd4gAAAABJRU5ErkJggg==" alt="Embedded Image" /&gt;&lt;/DIV&gt;
&lt;DIV class="card"&gt;
&lt;H2&gt;&lt;A href="https://techcommunity.microsoft.com/blog/fasttrackblog/introducing-the-new-microsoft-365-setup-experience-a-personalized-dashboard-for-/4551387" target="_blank" rel="noopener noreferrer"&gt;Introducing the new Microsoft 365 Setup experience: A personalized dashboard for admins&lt;/A&gt;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Team Blog:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/category/fasttrack/blog/fasttrackblog" target="_blank" rel="noopener noreferrer"&gt;FastTrack&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Author:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/users/johnvincent/3643833" target="_blank" rel="noopener noreferrer"&gt;johnvincent&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Published:&lt;/STRONG&gt; 08/31/2026&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; Microsoft is launching a redesigned Microsoft 365 Setup experience for admins, featuring a personalized dashboard that centralizes deployment progress, onboarding, licensing, and readiness insights. The new setup offers tailored recommendations, direct product configuration, and easy access to guides and support, streamlining the deployment process. Admins can now spend less time searching and more time taking action, with integrated training, migration resources, and FastTrack support. This update aims to simplify Microsoft 365 deployments, making them more intuitive and efficient, with future enhancements planned based on admin feedback, including AI-powered insights and assistance.&lt;/P&gt;
&lt;IMG style="max-width: 10%; height: auto;" src="data:image/jpeg;base64,iVBORw0KGgoAAAANSUhEUgAAAEsAAABLCAMAAAAPkIrYAAAAAXNSR0IB2cksfwAAAAlwSFlzAAALEwAACxMBAJqcGAAAAHtQTFRFAAAA8lAi8lAi8lAi8lAif7oAf7oAf7oAf7oA8lAi8lAi8lAif7oAf7oAf7oA8lAi8lAif7oAf7oA8lAif7oAAaTvAaTvAaTvAaTv/7kB/7kB/7kB/7kBAaTvAaTvAaTv/7kB/7kB/7kBAaTvAaTv/7kB/7kBAaTv/7kBfMz9mwAAACl0Uk5TADt7ag4Oans7/90eHt3/wBoawAMDDh4aAwMaHg5q3cDA3Wp7//97OzspjeVtAAAAlElEQVR4nO3WqwqAQBSEYY+uWiyCBm/J4Pu/jRhMBi8IFsHLCoZ9gCkbRGby8OVfHHuTD1sCQBHtw89hLDdE1h4h6zxp0aJFixYtWrT+bXnA8mWL5QbWZSyFLG9NHmTd9hszhY05ZrAxB2NVsEWnPECf3lg1+F3HXAQKWB0tWrRo0aJFi9a/rUYjaymR5bb2G/OL1guM9e5M8yBd4gAAAABJRU5ErkJggg==" alt="Embedded Image" /&gt;&lt;/DIV&gt;
&lt;DIV class="card"&gt;
&lt;H2&gt;&lt;A href="https://techcommunity.microsoft.com/blog/azuretoolsblog/building-a-fully-automated-azure-landing-zone-deployment-using-azure-devops-and-/4547956" target="_blank" rel="noopener noreferrer"&gt;Building a Fully Automated Azure Landing Zone Deployment Using Azure DevOps and Terraform&lt;/A&gt;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Team Blog:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/category/azure/blog/azuretoolsblog" target="_blank" rel="noopener noreferrer"&gt;Azure Tools&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Author:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/users/rajasekharvemula/3493578" target="_blank" rel="noopener noreferrer"&gt;Rajasekharvemula&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Published:&lt;/STRONG&gt; 08/18/2026&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; The article explains how to build a fully automated Azure Landing Zone using Azure DevOps and Terraform. It outlines best practices for deploying standardized cloud environments, including structured Git workflows, automated CI pipelines, environment promotion strategies, governance integration, identity and access management, and monitoring. Storing Terraform state in Azure Storage ensures collaboration and recovery. Automation from the start enables consistent, secure, and auditable cloud foundations, reducing operational effort and improving compliance. Combining Azure DevOps and Terraform transforms cloud deployment into a scalable, governed, and enterprise-ready platform engineering practice.&lt;/P&gt;
&lt;IMG style="max-width: 10%; height: auto;" src="data:image/jpeg;base64,iVBORw0KGgoAAAANSUhEUgAAAEsAAABLCAMAAAAPkIrYAAAAAXNSR0IB2cksfwAAAAlwSFlzAAALEwAACxMBAJqcGAAAAHtQTFRFAAAA8lAi8lAi8lAi8lAif7oAf7oAf7oAf7oA8lAi8lAi8lAif7oAf7oAf7oA8lAi8lAif7oAf7oA8lAif7oAAaTvAaTvAaTvAaTv/7kB/7kB/7kB/7kBAaTvAaTvAaTv/7kB/7kB/7kBAaTvAaTv/7kB/7kBAaTv/7kBfMz9mwAAACl0Uk5TADt7ag4Oans7/90eHt3/wBoawAMDDh4aAwMaHg5q3cDA3Wp7//97OzspjeVtAAAAlElEQVR4nO3WqwqAQBSEYY+uWiyCBm/J4Pu/jRhMBi8IFsHLCoZ9gCkbRGby8OVfHHuTD1sCQBHtw89hLDdE1h4h6zxp0aJFixYtWrT+bXnA8mWL5QbWZSyFLG9NHmTd9hszhY05ZrAxB2NVsEWnPECf3lg1+F3HXAQKWB0tWrRo0aJFi9a/rUYjaymR5bb2G/OL1guM9e5M8yBd4gAAAABJRU5ErkJggg==" alt="Embedded Image" /&gt;&lt;/DIV&gt;
&lt;DIV class="card"&gt;
&lt;H2&gt;&lt;A href="https://techcommunity.microsoft.com/blog/finopsblog/cost-management-with-azure-resource-manager-mcp/4550182" target="_blank" rel="noopener noreferrer"&gt;Cost Management with Azure Resource Manager MCP&lt;/A&gt;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Team Blog:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/category/azure/blog/finopsblog" target="_blank" rel="noopener noreferrer"&gt;FinOps&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Author:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/users/demiajayi/3547892" target="_blank" rel="noopener noreferrer"&gt;demiajayi&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Published:&lt;/STRONG&gt; 08/25/2026&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; Microsoft has announced new Cost Management features in Azure Resource Manager MCP, providing default tools for AI agents to integrate cost insights into Azure workflows. These tools help with cost estimation, budget tracking, and identifying savings opportunities, while optional advanced tools enable deeper analysis, forecasting, and optimization. AI agents can query costs, analyze AKS workloads, and recommend savings, streamlining financial decision-making in cloud operations. Installation and configuration details are provided for VS Code and GitHub Copilot. Microsoft plans to expand agentic cost capabilities and invites user feedback on the new tools.&lt;/P&gt;
&lt;IMG style="max-width: 10%; height: auto;" src="data:image/jpeg;base64,iVBORw0KGgoAAAANSUhEUgAAAEsAAABLCAMAAAAPkIrYAAAAAXNSR0IB2cksfwAAAAlwSFlzAAALEwAACxMBAJqcGAAAAHtQTFRFAAAA8lAi8lAi8lAi8lAif7oAf7oAf7oAf7oA8lAi8lAi8lAif7oAf7oAf7oA8lAi8lAif7oAf7oA8lAif7oAAaTvAaTvAaTvAaTv/7kB/7kB/7kB/7kBAaTvAaTvAaTv/7kB/7kB/7kBAaTvAaTv/7kB/7kBAaTv/7kBfMz9mwAAACl0Uk5TADt7ag4Oans7/90eHt3/wBoawAMDDh4aAwMaHg5q3cDA3Wp7//97OzspjeVtAAAAlElEQVR4nO3WqwqAQBSEYY+uWiyCBm/J4Pu/jRhMBi8IFsHLCoZ9gCkbRGby8OVfHHuTD1sCQBHtw89hLDdE1h4h6zxp0aJFixYtWrT+bXnA8mWL5QbWZSyFLG9NHmTd9hszhY05ZrAxB2NVsEWnPECf3lg1+F3HXAQKWB0tWrRo0aJFi9a/rUYjaymR5bb2G/OL1guM9e5M8yBd4gAAAABJRU5ErkJggg==" alt="Embedded Image" /&gt;&lt;/DIV&gt;
&lt;DIV class="card"&gt;
&lt;H2&gt;&lt;A href="https://techcommunity.microsoft.com/blog/finopsblog/who-ordered-all-these-tokens-giving-ai-spend-a-name-in-focus/4547978" target="_blank" rel="noopener noreferrer"&gt;Who Ordered All These Tokens? Giving AI Spend a Name in FOCUS&lt;/A&gt;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Team Blog:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/category/azure/blog/finopsblog" target="_blank" rel="noopener noreferrer"&gt;FinOps&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Author:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/users/dirk_brinkmann/2425227" target="_blank" rel="noopener noreferrer"&gt;Dirk_Brinkmann&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Published:&lt;/STRONG&gt; 08/19/2026&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; The article discusses the challenge of accurately attributing AI-related costs, such as Copilot and agent spend, within enterprise billing systems. Existing cost reports scatter AI expenses across ambiguous categories, making analysis difficult. The proposed solution is to create a custom “meter map” that classifies each billing meter into meaningful attributes (like token type, provider, Copilot, or agent). This enables clear reporting and chargeback, aligning spend with business questions. The approach is flexible, ongoing, and requires ownership, but solves the gap until vendor-neutral standards evolve further.&lt;/P&gt;
&lt;IMG style="max-width: 10%; height: auto;" src="data:image/jpeg;base64,iVBORw0KGgoAAAANSUhEUgAAAEsAAABLCAMAAAAPkIrYAAAAAXNSR0IB2cksfwAAAAlwSFlzAAALEwAACxMBAJqcGAAAAHtQTFRFAAAA8lAi8lAi8lAi8lAif7oAf7oAf7oAf7oA8lAi8lAi8lAif7oAf7oAf7oA8lAi8lAif7oAf7oA8lAif7oAAaTvAaTvAaTvAaTv/7kB/7kB/7kB/7kBAaTvAaTvAaTv/7kB/7kB/7kBAaTvAaTv/7kB/7kBAaTv/7kBfMz9mwAAACl0Uk5TADt7ag4Oans7/90eHt3/wBoawAMDDh4aAwMaHg5q3cDA3Wp7//97OzspjeVtAAAAlElEQVR4nO3WqwqAQBSEYY+uWiyCBm/J4Pu/jRhMBi8IFsHLCoZ9gCkbRGby8OVfHHuTD1sCQBHtw89hLDdE1h4h6zxp0aJFixYtWrT+bXnA8mWL5QbWZSyFLG9NHmTd9hszhY05ZrAxB2NVsEWnPECf3lg1+F3HXAQKWB0tWrRo0aJFi9a/rUYjaymR5bb2G/OL1guM9e5M8yBd4gAAAABJRU5ErkJggg==" alt="Embedded Image" /&gt;&lt;/DIV&gt;
&lt;DIV class="card"&gt;
&lt;H2&gt;&lt;A href="https://techcommunity.microsoft.com/blog/itopstalkblog/zonal-resiliency-in-azure-application-centric-goals-recovery-plans-and-drills/4542514" target="_blank" rel="noopener noreferrer"&gt;Zonal Resiliency in Azure: Application-Centric Goals, Recovery Plans, and Drills&lt;/A&gt;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Team Blog:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/category/itopstalk/blog/itopstalkblog" target="_blank" rel="noopener noreferrer"&gt;ITOps Talk&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Author:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/users/pierre_roman/140097" target="_blank" rel="noopener noreferrer"&gt;Pierre_Roman&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Published:&lt;/STRONG&gt; 08/06/2026&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; The article introduces “Resiliency in Azure” (formerly Azure Business Continuity Center), a unified platform for managing and validating zonal resiliency at the application level across IaaS, PaaS, and shared services. Key features include application-centric recovery plans, tailored Azure Advisor recommendations, Copilot-guided remediation, and automated zone-down drills via Azure Chaos Studio. This approach streamlines resiliency management, supports compliance, and enables realistic failover testing, reducing manual effort and uncertainty. While not all services are supported and costs may vary, it offers a significant improvement in visibility, confidence, and operational readiness for Azure applications.&lt;/P&gt;
&lt;IMG style="max-width: 10%; height: auto;" src="data:image/jpeg;base64,iVBORw0KGgoAAAANSUhEUgAAAEsAAABLCAMAAAAPkIrYAAAAAXNSR0IB2cksfwAAAAlwSFlzAAALEwAACxMBAJqcGAAAAHtQTFRFAAAA8lAi8lAi8lAi8lAif7oAf7oAf7oAf7oA8lAi8lAi8lAif7oAf7oAf7oA8lAi8lAif7oAf7oA8lAif7oAAaTvAaTvAaTvAaTv/7kB/7kB/7kB/7kBAaTvAaTvAaTv/7kB/7kB/7kBAaTvAaTv/7kB/7kBAaTv/7kBfMz9mwAAACl0Uk5TADt7ag4Oans7/90eHt3/wBoawAMDDh4aAwMaHg5q3cDA3Wp7//97OzspjeVtAAAAlElEQVR4nO3WqwqAQBSEYY+uWiyCBm/J4Pu/jRhMBi8IFsHLCoZ9gCkbRGby8OVfHHuTD1sCQBHtw89hLDdE1h4h6zxp0aJFixYtWrT+bXnA8mWL5QbWZSyFLG9NHmTd9hszhY05ZrAxB2NVsEWnPECf3lg1+F3HXAQKWB0tWrRo0aJFi9a/rUYjaymR5bb2G/OL1guM9e5M8yBd4gAAAABJRU5ErkJggg==" alt="Embedded Image" /&gt;&lt;/DIV&gt;
&lt;DIV class="card"&gt;
&lt;H2&gt;&lt;A href="https://techcommunity.microsoft.com/blog/itopstalkblog/operating-azure-backup-at-scale-day-2-excellence-for-iaas-paas-and-storage-workl/4545638" target="_blank" rel="noopener noreferrer"&gt;Operating Azure Backup at Scale: Day-2 Excellence for IaaS, PaaS, and Storage Workloads&lt;/A&gt;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Team Blog:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/category/itopstalk/blog/itopstalkblog" target="_blank" rel="noopener noreferrer"&gt;ITOps Talk&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Author:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/users/pierre_roman/140097" target="_blank" rel="noopener noreferrer"&gt;Pierre_Roman&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Published:&lt;/STRONG&gt; 08/11/2026&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; The article summarizes advancements in Azure Backup, highlighting its unified, application-centric approach for protecting IaaS, PaaS, AKS, PostgreSQL, and storage workloads. Key features include a single vault model, built-in cyber resiliency with immutability and multi-user authorization, threat detection, agentless backups, and conversational configuration via VS Code. Azure Backup offers granular restores, compliance-friendly retention tiers, and robust protection against ransomware. Real-world scenarios and actionable steps demonstrate improved operational efficiency, security, and reliability for IT professionals managing large-scale Azure environments.&lt;/P&gt;
&lt;IMG style="max-width: 10%; height: auto;" src="data:image/jpeg;base64,iVBORw0KGgoAAAANSUhEUgAAAEsAAABLCAMAAAAPkIrYAAAAAXNSR0IB2cksfwAAAAlwSFlzAAALEwAACxMBAJqcGAAAAHtQTFRFAAAA8lAi8lAi8lAi8lAif7oAf7oAf7oAf7oA8lAi8lAi8lAif7oAf7oAf7oA8lAi8lAif7oAf7oA8lAif7oAAaTvAaTvAaTvAaTv/7kB/7kB/7kB/7kBAaTvAaTvAaTv/7kB/7kB/7kBAaTvAaTv/7kB/7kBAaTv/7kBfMz9mwAAACl0Uk5TADt7ag4Oans7/90eHt3/wBoawAMDDh4aAwMaHg5q3cDA3Wp7//97OzspjeVtAAAAlElEQVR4nO3WqwqAQBSEYY+uWiyCBm/J4Pu/jRhMBi8IFsHLCoZ9gCkbRGby8OVfHHuTD1sCQBHtw89hLDdE1h4h6zxp0aJFixYtWrT+bXnA8mWL5QbWZSyFLG9NHmTd9hszhY05ZrAxB2NVsEWnPECf3lg1+F3HXAQKWB0tWrRo0aJFi9a/rUYjaymR5bb2G/OL1guM9e5M8yBd4gAAAABJRU5ErkJggg==" alt="Embedded Image" /&gt;&lt;/DIV&gt;
&lt;DIV class="card"&gt;
&lt;H2&gt;&lt;A href="https://techcommunity.microsoft.com/blog/azurearcblog/expanding-the-azure-local-security-ecosystem-with-ibm-qradar-and-splunk/4535101" target="_blank" rel="noopener noreferrer"&gt;Expanding the Azure Local Security Ecosystem with IBM QRadar and Splunk&lt;/A&gt;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Team Blog:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/category/azure/blog/azurearcblog" target="_blank" rel="noopener noreferrer"&gt;Azure Arc&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Author:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/users/ariel%20netz/138783" target="_blank" rel="noopener noreferrer"&gt;Ariel Netz&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Published:&lt;/STRONG&gt; 08/07/2026&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; Microsoft has announced new integrations for Azure Local with IBM QRadar and Splunk, enabling organizations in regulated and sovereign environments to incorporate Azure Local security signals into their existing security operations platforms. This enhances monitoring, investigation, and compliance while preserving established tools and processes. Azure Local’s built-in security controls and audit logs now work seamlessly with these partner solutions, supporting flexible and resilient security operations. Microsoft is also working to expand its security ecosystem with additional partners in areas like endpoint detection, vulnerability management, and container security for Azure Local and Sovereign Private Cloud deployments.&lt;/P&gt;
&lt;IMG style="max-width: 10%; height: auto;" src="data:image/jpeg;base64,iVBORw0KGgoAAAANSUhEUgAAAEsAAABLCAMAAAAPkIrYAAAAAXNSR0IB2cksfwAAAAlwSFlzAAALEwAACxMBAJqcGAAAAHtQTFRFAAAA8lAi8lAi8lAi8lAif7oAf7oAf7oAf7oA8lAi8lAi8lAif7oAf7oAf7oA8lAi8lAif7oAf7oA8lAif7oAAaTvAaTvAaTvAaTv/7kB/7kB/7kB/7kBAaTvAaTvAaTv/7kB/7kB/7kBAaTvAaTv/7kB/7kBAaTv/7kBfMz9mwAAACl0Uk5TADt7ag4Oans7/90eHt3/wBoawAMDDh4aAwMaHg5q3cDA3Wp7//97OzspjeVtAAAAlElEQVR4nO3WqwqAQBSEYY+uWiyCBm/J4Pu/jRhMBi8IFsHLCoZ9gCkbRGby8OVfHHuTD1sCQBHtw89hLDdE1h4h6zxp0aJFixYtWrT+bXnA8mWL5QbWZSyFLG9NHmTd9hszhY05ZrAxB2NVsEWnPECf3lg1+F3HXAQKWB0tWrRo0aJFi9a/rUYjaymR5bb2G/OL1guM9e5M8yBd4gAAAABJRU5ErkJggg==" alt="Embedded Image" /&gt;&lt;/DIV&gt;
&lt;DIV class="card"&gt;
&lt;H2&gt;&lt;A href="https://techcommunity.microsoft.com/blog/azurearcblog/episode-1-onboarding-azure-arc-at-scale--the-azure-arc-check-in/4546441" target="_blank" rel="noopener noreferrer"&gt;Episode 1: Onboarding Azure Arc at Scale | The Azure Arc Check-In&lt;/A&gt;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Team Blog:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/category/azure/blog/azurearcblog" target="_blank" rel="noopener noreferrer"&gt;Azure Arc&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Author:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/users/mason_torres/968818" target="_blank" rel="noopener noreferrer"&gt;Mason_Torres&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Published:&lt;/STRONG&gt; 08/18/2026&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; Episode 1 of The Azure Arc Check-In discusses strategies for onboarding large fleets of Windows and Linux servers to Azure Arc at scale. It emphasizes automation and non-interactive authentication to minimize manual effort and errors. For Linux servers, Ansible with managed identity streamlines agent deployment, while Windows servers can be onboarded using Active Directory Group Policy. The episode provides step-by-step guidance for both approaches, highlighting the importance of aligning onboarding methods with existing management tools and enabling consistent configuration and governance from day one.&lt;/P&gt;
&lt;IMG style="max-width: 10%; height: auto;" src="data:image/jpeg;base64,iVBORw0KGgoAAAANSUhEUgAAAEsAAABLCAMAAAAPkIrYAAAAAXNSR0IB2cksfwAAAAlwSFlzAAALEwAACxMBAJqcGAAAAHtQTFRFAAAA8lAi8lAi8lAi8lAif7oAf7oAf7oAf7oA8lAi8lAi8lAif7oAf7oAf7oA8lAi8lAif7oAf7oA8lAif7oAAaTvAaTvAaTvAaTv/7kB/7kB/7kB/7kBAaTvAaTvAaTv/7kB/7kB/7kBAaTvAaTv/7kB/7kBAaTv/7kBfMz9mwAAACl0Uk5TADt7ag4Oans7/90eHt3/wBoawAMDDh4aAwMaHg5q3cDA3Wp7//97OzspjeVtAAAAlElEQVR4nO3WqwqAQBSEYY+uWiyCBm/J4Pu/jRhMBi8IFsHLCoZ9gCkbRGby8OVfHHuTD1sCQBHtw89hLDdE1h4h6zxp0aJFixYtWrT+bXnA8mWL5QbWZSyFLG9NHmTd9hszhY05ZrAxB2NVsEWnPECf3lg1+F3HXAQKWB0tWrRo0aJFi9a/rUYjaymR5bb2G/OL1guM9e5M8yBd4gAAAABJRU5ErkJggg==" alt="Embedded Image" /&gt;&lt;/DIV&gt;
&lt;DIV class="card"&gt;
&lt;H2&gt;&lt;A href="https://techcommunity.microsoft.com/blog/azurecompute/announcing-general-availability-of-disable-multithreading-and-configurable-const/4547908" target="_blank" rel="noopener noreferrer"&gt;Announcing General Availability of Disable Multithreading and Configurable Constrained Cores&lt;/A&gt;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Team Blog:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/category/azure/blog/azurecompute" target="_blank" rel="noopener noreferrer"&gt;Azure Compute&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Author:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/users/misha-bansal/2576478" target="_blank" rel="noopener noreferrer"&gt;misha-bansal&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Published:&lt;/STRONG&gt; 08/19/2026&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; Microsoft Azure has launched two new features: Disable Simultaneous Multithreading/Hyper-Threading (SMT/HT Off) and Configurable Constrained Cores. These allow customers to optimize VM performance and reduce software licensing costs by customizing vCPU configurations and disabling SMT/HT for improved performance and latency. Users can select specific vCPU counts without altering memory or storage, aiding compliance and cost efficiency. The features are available in all Azure regions, with no changes to VM pricing, and help customers tailor compute resources to their workloads, maintaining performance while controlling costs.&lt;/P&gt;
&lt;IMG style="max-width: 10%; height: auto;" src="data:image/jpeg;base64,iVBORw0KGgoAAAANSUhEUgAAAEsAAABLCAMAAAAPkIrYAAAAAXNSR0IB2cksfwAAAAlwSFlzAAALEwAACxMBAJqcGAAAAHtQTFRFAAAA8lAi8lAi8lAi8lAif7oAf7oAf7oAf7oA8lAi8lAi8lAif7oAf7oAf7oA8lAi8lAif7oAf7oA8lAif7oAAaTvAaTvAaTvAaTv/7kB/7kB/7kB/7kBAaTvAaTvAaTv/7kB/7kB/7kBAaTvAaTv/7kB/7kBAaTv/7kBfMz9mwAAACl0Uk5TADt7ag4Oans7/90eHt3/wBoawAMDDh4aAwMaHg5q3cDA3Wp7//97OzspjeVtAAAAlElEQVR4nO3WqwqAQBSEYY+uWiyCBm/J4Pu/jRhMBi8IFsHLCoZ9gCkbRGby8OVfHHuTD1sCQBHtw89hLDdE1h4h6zxp0aJFixYtWrT+bXnA8mWL5QbWZSyFLG9NHmTd9hszhY05ZrAxB2NVsEWnPECf3lg1+F3HXAQKWB0tWrRo0aJFi9a/rUYjaymR5bb2G/OL1guM9e5M8yBd4gAAAABJRU5ErkJggg==" alt="Embedded Image" /&gt;&lt;/DIV&gt;
&lt;DIV class="card"&gt;
&lt;H2&gt;&lt;A href="https://techcommunity.microsoft.com/blog/windowsosplatform/the-openvmm-project/4547237" target="_blank" rel="noopener noreferrer"&gt;The OpenVMM Project&lt;/A&gt;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Team Blog:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/category/windows/blog/windowsosplatform" target="_blank" rel="noopener noreferrer"&gt;Windows OS Platform&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Author:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/users/caroline_perezvargas/1777181" target="_blank" rel="noopener noreferrer"&gt;Caroline_Perezvargas&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Published:&lt;/STRONG&gt; 08/17/2026&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; OpenVMM is an open-source, cross-platform Virtual Machine Manager (VMM) written in Rust and released under the MIT license. It offers broad support for multiple architectures, host operating systems, and virtualization backends, and features a modular, flexible design. Since becoming open source in 2024, OpenVMM has grown with contributions from major industry partners, expanding device emulation, testing infrastructure, and confidential computing capabilities. Its modern security architecture leverages Rust, process sandboxing, and user-mode virtualization. OpenVMM is used in various environments, including Azure, and aims to provide secure, high-performance virtualization for diverse workloads.&lt;/P&gt;
&lt;IMG style="max-width: 10%; height: auto;" src="data:image/jpeg;base64,iVBORw0KGgoAAAANSUhEUgAAAEsAAABLCAMAAAAPkIrYAAAAAXNSR0IB2cksfwAAAAlwSFlzAAALEwAACxMBAJqcGAAAAHtQTFRFAAAA8lAi8lAi8lAi8lAif7oAf7oAf7oAf7oA8lAi8lAi8lAif7oAf7oAf7oA8lAi8lAif7oAf7oA8lAif7oAAaTvAaTvAaTvAaTv/7kB/7kB/7kB/7kBAaTvAaTvAaTv/7kB/7kB/7kBAaTvAaTv/7kB/7kBAaTv/7kBfMz9mwAAACl0Uk5TADt7ag4Oans7/90eHt3/wBoawAMDDh4aAwMaHg5q3cDA3Wp7//97OzspjeVtAAAAlElEQVR4nO3WqwqAQBSEYY+uWiyCBm/J4Pu/jRhMBi8IFsHLCoZ9gCkbRGby8OVfHHuTD1sCQBHtw89hLDdE1h4h6zxp0aJFixYtWrT+bXnA8mWL5QbWZSyFLG9NHmTd9hszhY05ZrAxB2NVsEWnPECf3lg1+F3HXAQKWB0tWrRo0aJFi9a/rUYjaymR5bb2G/OL1guM9e5M8yBd4gAAAABJRU5ErkJggg==" alt="Embedded Image" /&gt;&lt;/DIV&gt;
&lt;DIV class="card"&gt;
&lt;H2&gt;&lt;A href="https://techcommunity.microsoft.com/blog/azurepaasblog/azure-managed-redis-deployment-automation/4547874" target="_blank" rel="noopener noreferrer"&gt;Azure Managed Redis Deployment Automation&lt;/A&gt;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Team Blog:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/category/azure/blog/azurepaasblog" target="_blank" rel="noopener noreferrer"&gt;Azure PaaS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Author:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/users/luisfilipe/741199" target="_blank" rel="noopener noreferrer"&gt;LuisFilipe&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Published:&lt;/STRONG&gt; 08/21/2026&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; The article introduces a PowerShell script for automating Azure Managed Redis (AMR) deployments, especially when facing regional capacity restrictions. The script retries cache creation at random intervals, cycling through specified SKUs and configurations, and cleans up failed resources before each attempt. It supports geo-replication, clustering, high availability, and custom eviction policies. Authentication, logging, and parameter validation are included. The script is provided as-is, without support or guarantees, and users are advised to test before production use due to potential costs and risks.&lt;/P&gt;
&lt;IMG style="max-width: 10%; height: auto;" src="data:image/jpeg;base64,iVBORw0KGgoAAAANSUhEUgAAAEsAAABLCAMAAAAPkIrYAAAAAXNSR0IB2cksfwAAAAlwSFlzAAALEwAACxMBAJqcGAAAAHtQTFRFAAAA8lAi8lAi8lAi8lAif7oAf7oAf7oAf7oA8lAi8lAi8lAif7oAf7oAf7oA8lAi8lAif7oAf7oA8lAif7oAAaTvAaTvAaTvAaTv/7kB/7kB/7kB/7kBAaTvAaTvAaTv/7kB/7kB/7kBAaTvAaTv/7kB/7kBAaTv/7kBfMz9mwAAACl0Uk5TADt7ag4Oans7/90eHt3/wBoawAMDDh4aAwMaHg5q3cDA3Wp7//97OzspjeVtAAAAlElEQVR4nO3WqwqAQBSEYY+uWiyCBm/J4Pu/jRhMBi8IFsHLCoZ9gCkbRGby8OVfHHuTD1sCQBHtw89hLDdE1h4h6zxp0aJFixYtWrT+bXnA8mWL5QbWZSyFLG9NHmTd9hszhY05ZrAxB2NVsEWnPECf3lg1+F3HXAQKWB0tWrRo0aJFi9a/rUYjaymR5bb2G/OL1guM9e5M8yBd4gAAAABJRU5ErkJggg==" alt="Embedded Image" /&gt;&lt;/DIV&gt;
&lt;DIV class="card"&gt;
&lt;H2&gt;&lt;A href="https://techcommunity.microsoft.com/blog/azurepaasblog/tracking-batch-node-state-and-duration-in-log-analytics/4547582" target="_blank" rel="noopener noreferrer"&gt;Tracking Batch node state and duration in Log Analytics&lt;/A&gt;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Team Blog:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/category/azure/blog/azurepaasblog" target="_blank" rel="noopener noreferrer"&gt;Azure PaaS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Author:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/users/ahmed_khaled/1239754" target="_blank" rel="noopener noreferrer"&gt;Ahmed_Khaled&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Published:&lt;/STRONG&gt; 08/25/2026&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; The article addresses gaps in Azure Batch node monitoring, such as identifying nodes stuck in certain states and automating alerts. Since Azure Monitor lacks per-node granularity, the proposed solution uses a Python script to poll Batch REST API and ingest node-level data into Log Analytics. Custom KQL queries and alerts enable precise tracking of node state, duration, and errors. The solution supports dashboards, automated remediation, and actionable alerts, and can be deployed via Azure Functions, Container Apps, or VMs. It enhances monitoring without replacing built-in metrics, providing detailed, per-node visibility for customers.&lt;/P&gt;
&lt;IMG style="max-width: 10%; height: auto;" src="data:image/jpeg;base64,iVBORw0KGgoAAAANSUhEUgAAAEsAAABLCAMAAAAPkIrYAAAAAXNSR0IB2cksfwAAAAlwSFlzAAALEwAACxMBAJqcGAAAAHtQTFRFAAAA8lAi8lAi8lAi8lAif7oAf7oAf7oAf7oA8lAi8lAi8lAif7oAf7oAf7oA8lAi8lAif7oAf7oA8lAif7oAAaTvAaTvAaTvAaTv/7kB/7kB/7kB/7kBAaTvAaTvAaTv/7kB/7kB/7kBAaTvAaTv/7kB/7kBAaTv/7kBfMz9mwAAACl0Uk5TADt7ag4Oans7/90eHt3/wBoawAMDDh4aAwMaHg5q3cDA3Wp7//97OzspjeVtAAAAlElEQVR4nO3WqwqAQBSEYY+uWiyCBm/J4Pu/jRhMBi8IFsHLCoZ9gCkbRGby8OVfHHuTD1sCQBHtw89hLDdE1h4h6zxp0aJFixYtWrT+bXnA8mWL5QbWZSyFLG9NHmTd9hszhY05ZrAxB2NVsEWnPECf3lg1+F3HXAQKWB0tWrRo0aJFi9a/rUYjaymR5bb2G/OL1guM9e5M8yBd4gAAAABJRU5ErkJggg==" alt="Embedded Image" /&gt;&lt;/DIV&gt;
&lt;DIV class="card"&gt;
&lt;H2&gt;&lt;A href="https://techcommunity.microsoft.com/blog/azureinfrastructureblog/beyond-deployment-what-it-really-takes-to-run-github-actions-runners-on-aks/4547638" target="_blank" rel="noopener noreferrer"&gt;Beyond Deployment: What It Really Takes to Run GitHub Actions Runners on AKS&lt;/A&gt;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Team Blog:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/category/azure/blog/azureinfrastructureblog" target="_blank" rel="noopener noreferrer"&gt;Azure Infrastructure&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Author:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/users/aparnabadireddigari/2474295" target="_blank" rel="noopener noreferrer"&gt;aparnabadireddigari&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Published:&lt;/STRONG&gt; 08/17/2026&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; Deploying GitHub Actions runners on Azure Kubernetes Service (AKS) with Actions Runner Controller (ARC) is straightforward, but running it as a production platform requires much more. Key challenges involve managing authentication, network dependencies, workload isolation, image lifecycle, and observability. Production readiness demands clear ownership, validated connectivity, strong operational practices, and reliable monitoring. Naming conventions and image management become platform contracts. Ultimately, success depends on operational excellence, governance, and ownership—moving beyond a working deployment to a mature, dependable platform that reliably supports multiple teams and business-critical workflows.&lt;/P&gt;
&lt;IMG style="max-width: 10%; height: auto;" src="data:image/jpeg;base64,iVBORw0KGgoAAAANSUhEUgAAAEsAAABLCAMAAAAPkIrYAAAAAXNSR0IB2cksfwAAAAlwSFlzAAALEwAACxMBAJqcGAAAAHtQTFRFAAAA8lAi8lAi8lAi8lAif7oAf7oAf7oAf7oA8lAi8lAi8lAif7oAf7oAf7oA8lAi8lAif7oAf7oA8lAif7oAAaTvAaTvAaTvAaTv/7kB/7kB/7kB/7kBAaTvAaTvAaTv/7kB/7kB/7kBAaTvAaTv/7kB/7kBAaTv/7kBfMz9mwAAACl0Uk5TADt7ag4Oans7/90eHt3/wBoawAMDDh4aAwMaHg5q3cDA3Wp7//97OzspjeVtAAAAlElEQVR4nO3WqwqAQBSEYY+uWiyCBm/J4Pu/jRhMBi8IFsHLCoZ9gCkbRGby8OVfHHuTD1sCQBHtw89hLDdE1h4h6zxp0aJFixYtWrT+bXnA8mWL5QbWZSyFLG9NHmTd9hszhY05ZrAxB2NVsEWnPECf3lg1+F3HXAQKWB0tWrRo0aJFi9a/rUYjaymR5bb2G/OL1guM9e5M8yBd4gAAAABJRU5ErkJggg==" alt="Embedded Image" /&gt;&lt;/DIV&gt;
&lt;DIV class="card"&gt;
&lt;H2&gt;&lt;A href="https://techcommunity.microsoft.com/blog/azureinfrastructureblog/azure-copilot-introduces-direct-access-to-agents/4547932" target="_blank" rel="noopener noreferrer"&gt;Azure Copilot Introduces Direct Access to Agents&lt;/A&gt;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Team Blog:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/category/azure/blog/azureinfrastructureblog" target="_blank" rel="noopener noreferrer"&gt;Azure Infrastructure&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Author:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/users/artigulwadi/1350784" target="_blank" rel="noopener noreferrer"&gt;artigulwadi&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Published:&lt;/STRONG&gt; 08/18/2026&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; Azure Copilot now offers direct access to specialized agents for troubleshooting, deployment, optimization, and resiliency, allowing cloud operations teams to quickly engage relevant expertise. This update streamlines workflows by matching tasks with purpose-built agents, enhancing efficiency and tailored guidance. Administrators can manage agent availability flexibly, enabling incremental adoption and better governance. Pricing remains unchanged, with most agents available at no extra cost. This evolution supports agentic cloud operations, empowering teams to operate more effectively across application and infrastructure lifecycles, with future enhancements and administrative controls expected.&lt;/P&gt;
&lt;IMG style="max-width: 10%; height: auto;" src="data:image/jpeg;base64,iVBORw0KGgoAAAANSUhEUgAAAEsAAABLCAMAAAAPkIrYAAAAAXNSR0IB2cksfwAAAAlwSFlzAAALEwAACxMBAJqcGAAAAHtQTFRFAAAA8lAi8lAi8lAi8lAif7oAf7oAf7oAf7oA8lAi8lAi8lAif7oAf7oAf7oA8lAi8lAif7oAf7oA8lAif7oAAaTvAaTvAaTvAaTv/7kB/7kB/7kB/7kBAaTvAaTvAaTv/7kB/7kB/7kBAaTvAaTv/7kB/7kBAaTv/7kBfMz9mwAAACl0Uk5TADt7ag4Oans7/90eHt3/wBoawAMDDh4aAwMaHg5q3cDA3Wp7//97OzspjeVtAAAAlElEQVR4nO3WqwqAQBSEYY+uWiyCBm/J4Pu/jRhMBi8IFsHLCoZ9gCkbRGby8OVfHHuTD1sCQBHtw89hLDdE1h4h6zxp0aJFixYtWrT+bXnA8mWL5QbWZSyFLG9NHmTd9hszhY05ZrAxB2NVsEWnPECf3lg1+F3HXAQKWB0tWrRo0aJFi9a/rUYjaymR5bb2G/OL1guM9e5M8yBd4gAAAABJRU5ErkJggg==" alt="Embedded Image" /&gt;&lt;/DIV&gt;
&lt;DIV class="card"&gt;
&lt;H2&gt;&lt;A href="https://techcommunity.microsoft.com/blog/azurestorageblog/accelerate-inference-on-aks-with-azure-blob-storage-and-nvidia-dynamo/4543408" target="_blank" rel="noopener noreferrer"&gt;Accelerate Inference on AKS with Azure Blob Storage and NVIDIA Dynamo&lt;/A&gt;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Team Blog:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/category/azure/blog/azurestorageblog" target="_blank" rel="noopener noreferrer"&gt;Azure Storage&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Author:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/users/vishnu%20charan%20tj/65854" target="_blank" rel="noopener noreferrer"&gt;Vishnu Charan TJ&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Published:&lt;/STRONG&gt; 08/11/2026&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; The article details how integrating Azure Blob Storage with NVIDIA’s Dynamo stack accelerates AI inference on Azure Kubernetes Service (AKS). By using Dynamo ModelExpress and Run:ai Model Streamer, model weights are loaded up to 7.3x faster, reducing cold start latency by up to 4.6x. Offloading KV cache via NIXL to Blob Storage further lowers time-to-first-token latency by 2.8x and optimizes GPU memory use. These enhancements enable faster scaling, operational simplicity, and improved reliability for large AI models, streamlining inference workflows on AKS.&lt;/P&gt;
&lt;IMG style="max-width: 10%; height: auto;" src="data:image/jpeg;base64,iVBORw0KGgoAAAANSUhEUgAAAEsAAABLCAMAAAAPkIrYAAAAAXNSR0IB2cksfwAAAAlwSFlzAAALEwAACxMBAJqcGAAAAHtQTFRFAAAA8lAi8lAi8lAi8lAif7oAf7oAf7oAf7oA8lAi8lAi8lAif7oAf7oAf7oA8lAi8lAif7oAf7oA8lAif7oAAaTvAaTvAaTvAaTv/7kB/7kB/7kB/7kBAaTvAaTvAaTv/7kB/7kB/7kBAaTvAaTv/7kB/7kBAaTv/7kBfMz9mwAAACl0Uk5TADt7ag4Oans7/90eHt3/wBoawAMDDh4aAwMaHg5q3cDA3Wp7//97OzspjeVtAAAAlElEQVR4nO3WqwqAQBSEYY+uWiyCBm/J4Pu/jRhMBi8IFsHLCoZ9gCkbRGby8OVfHHuTD1sCQBHtw89hLDdE1h4h6zxp0aJFixYtWrT+bXnA8mWL5QbWZSyFLG9NHmTd9hszhY05ZrAxB2NVsEWnPECf3lg1+F3HXAQKWB0tWrRo0aJFi9a/rUYjaymR5bb2G/OL1guM9e5M8yBd4gAAAABJRU5ErkJggg==" alt="Embedded Image" /&gt;&lt;/DIV&gt;
&lt;DIV class="card"&gt;
&lt;H2&gt;&lt;A href="https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/unified-ai-defense-security-copilot-project-perception-and-mdash/4547124" target="_blank" rel="noopener noreferrer"&gt;Unified AI Defense: Security Copilot, Project Perception, and MDASH&lt;/A&gt;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Team Blog:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/category/cis/blog/coreinfrastructureandsecurityblog" target="_blank" rel="noopener noreferrer"&gt;Core Infrastructure and Security&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Author:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/users/edgarus71/1595015" target="_blank" rel="noopener noreferrer"&gt;edgarus71&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Published:&lt;/STRONG&gt; 08/24/2026&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; The article outlines Microsoft’s unified AI security platform, comprising Security Copilot, Project Perception, and MDASH. Security Copilot assists security analysts via AI-driven workflows and investigations. Project Perception orchestrates multi-agent defense, coordinating Red, Blue, and Green agents to proactively identify, validate, and remediate threats. MDASH specializes in code vulnerability discovery, validation, and remediation guidance, feeding findings into broader defense workflows. Each tool serves distinct roles—analyst assistance, coordinated defense, and deep application security—but together provide a comprehensive, layered AI security solution with human oversight and governance.&lt;/P&gt;
&lt;IMG style="max-width: 10%; height: auto;" src="data:image/jpeg;base64,iVBORw0KGgoAAAANSUhEUgAAAEsAAABLCAMAAAAPkIrYAAAAAXNSR0IB2cksfwAAAAlwSFlzAAALEwAACxMBAJqcGAAAAHtQTFRFAAAA8lAi8lAi8lAi8lAif7oAf7oAf7oAf7oA8lAi8lAi8lAif7oAf7oAf7oA8lAi8lAif7oAf7oA8lAif7oAAaTvAaTvAaTvAaTv/7kB/7kB/7kB/7kBAaTvAaTvAaTv/7kB/7kB/7kBAaTvAaTv/7kB/7kBAaTv/7kBfMz9mwAAACl0Uk5TADt7ag4Oans7/90eHt3/wBoawAMDDh4aAwMaHg5q3cDA3Wp7//97OzspjeVtAAAAlElEQVR4nO3WqwqAQBSEYY+uWiyCBm/J4Pu/jRhMBi8IFsHLCoZ9gCkbRGby8OVfHHuTD1sCQBHtw89hLDdE1h4h6zxp0aJFixYtWrT+bXnA8mWL5QbWZSyFLG9NHmTd9hszhY05ZrAxB2NVsEWnPECf3lg1+F3HXAQKWB0tWrRo0aJFi9a/rUYjaymR5bb2G/OL1guM9e5M8yBd4gAAAABJRU5ErkJggg==" alt="Embedded Image" /&gt;&lt;/DIV&gt;
&lt;DIV class="card"&gt;
&lt;H2&gt;&lt;A href="https://techcommunity.microsoft.com/blog/skills-hub-blog/ai-skills-navigator-is-now-available-in-microsoft-copilot/4543633" target="_blank" rel="noopener noreferrer"&gt;AI Skills Navigator is now available in Microsoft Copilot&lt;/A&gt;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Team Blog:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/category/microsoftlearn/blog/microsoftlearnblog" target="_blank" rel="noopener noreferrer"&gt;Microsoft Learn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Author:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/users/matterni/3520488" target="_blank" rel="noopener noreferrer"&gt;MattErni&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Published:&lt;/STRONG&gt; 08/27/2026&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; Microsoft has integrated AI Skills Navigator into Copilot's Learning Agent, enabling users to ask questions and receive personalized AI skill recommendations directly in their workflow. This new feature tailors training, learning paths, and credentials to individual roles and goals, streamlining skill development for both individuals and organizations. Progress is tracked automatically, and learning resources from various platforms are accessible within Copilot. This integration helps connect real work tasks to relevant learning opportunities, making AI upskilling more efficient and accessible across organizations.&lt;/P&gt;
&lt;IMG style="max-width: 10%; height: auto;" src="data:image/jpeg;base64,iVBORw0KGgoAAAANSUhEUgAAAEsAAABLCAMAAAAPkIrYAAAAAXNSR0IB2cksfwAAAAlwSFlzAAALEwAACxMBAJqcGAAAAHtQTFRFAAAA8lAi8lAi8lAi8lAif7oAf7oAf7oAf7oA8lAi8lAi8lAif7oAf7oAf7oA8lAi8lAif7oAf7oA8lAif7oAAaTvAaTvAaTvAaTv/7kB/7kB/7kB/7kBAaTvAaTvAaTv/7kB/7kB/7kBAaTvAaTv/7kB/7kBAaTv/7kBfMz9mwAAACl0Uk5TADt7ag4Oans7/90eHt3/wBoawAMDDh4aAwMaHg5q3cDA3Wp7//97OzspjeVtAAAAlElEQVR4nO3WqwqAQBSEYY+uWiyCBm/J4Pu/jRhMBi8IFsHLCoZ9gCkbRGby8OVfHHuTD1sCQBHtw89hLDdE1h4h6zxp0aJFixYtWrT+bXnA8mWL5QbWZSyFLG9NHmTd9hszhY05ZrAxB2NVsEWnPECf3lg1+F3HXAQKWB0tWrRo0aJFi9a/rUYjaymR5bb2G/OL1guM9e5M8yBd4gAAAABJRU5ErkJggg==" alt="Embedded Image" /&gt;&lt;/DIV&gt;
&lt;DIV class="card"&gt;
&lt;H2&gt;&lt;A href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/from-gpo-to-microsoft-intune-a-practical-guide-to-cloud-first-policy-management/4551946" target="_blank" rel="noopener noreferrer"&gt;From GPO to Microsoft Intune: A practical guide to cloud-first policy management&lt;/A&gt;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Team Blog:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/category/microsoftintune/blog/intunecustomersuccess" target="_blank" rel="noopener noreferrer"&gt;Intune Customer Success&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Author:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/users/intune_support_team/226779" target="_blank" rel="noopener noreferrer"&gt;Intune_Support_Team&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Published:&lt;/STRONG&gt; 08/31/2026&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; The article offers a practical guide for organizations transitioning from Group Policy Objects (GPOs) to Microsoft Intune for cloud-first policy management. It outlines three migration paths—starting fresh for cloud-native devices, selectively transitioning necessary settings, or coordinating GPO and Intune for hybrid environments. Key recommendations include assessing and rationalizing existing policies, avoiding direct lift-and-shift, leveraging security baselines, piloting changes, and coordinating targeting to prevent conflicts. The guide stresses the importance of tailoring management strategies to device populations and business needs, ensuring a streamlined, secure, and efficient move to modern policy management.&lt;/P&gt;
&lt;IMG style="max-width: 10%; height: auto;" src="data:image/jpeg;base64,iVBORw0KGgoAAAANSUhEUgAAAEsAAABLCAMAAAAPkIrYAAAAAXNSR0IB2cksfwAAAAlwSFlzAAALEwAACxMBAJqcGAAAAHtQTFRFAAAA8lAi8lAi8lAi8lAif7oAf7oAf7oAf7oA8lAi8lAi8lAif7oAf7oAf7oA8lAi8lAif7oAf7oA8lAif7oAAaTvAaTvAaTvAaTv/7kB/7kB/7kB/7kBAaTvAaTvAaTv/7kB/7kB/7kBAaTvAaTv/7kB/7kBAaTv/7kBfMz9mwAAACl0Uk5TADt7ag4Oans7/90eHt3/wBoawAMDDh4aAwMaHg5q3cDA3Wp7//97OzspjeVtAAAAlElEQVR4nO3WqwqAQBSEYY+uWiyCBm/J4Pu/jRhMBi8IFsHLCoZ9gCkbRGby8OVfHHuTD1sCQBHtw89hLDdE1h4h6zxp0aJFixYtWrT+bXnA8mWL5QbWZSyFLG9NHmTd9hszhY05ZrAxB2NVsEWnPECf3lg1+F3HXAQKWB0tWrRo0aJFi9a/rUYjaymR5bb2G/OL1guM9e5M8yBd4gAAAABJRU5ErkJggg==" alt="Embedded Image" /&gt;&lt;/DIV&gt;
&lt;DIV class="card"&gt;
&lt;H2&gt;&lt;A href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/introducing-device-association-for-windows-autopilot-device-preparation/4550603" target="_blank" rel="noopener noreferrer"&gt;Introducing device association for Windows Autopilot device preparation&lt;/A&gt;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Team Blog:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/category/microsoftintune/blog/intunecustomersuccess" target="_blank" rel="noopener noreferrer"&gt;Intune Customer Success&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Author:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/users/intune_support_team/226779" target="_blank" rel="noopener noreferrer"&gt;Intune_Support_Team&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Published:&lt;/STRONG&gt; 08/27/2026&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; Device association for Windows Autopilot device preparation enables organizations to securely bind Windows 11 devices to their tenant before enrollment, using hardware-backed attestation. This ensures devices are recognized as corporate-owned, allowing IT admins to apply targeted policies and configurations early, streamlining the out-of-box experience for users. The association persists through resets and reinstallation, supporting consistent lifecycle management. Device association integrates with existing Autopilot strategies, offering improved security, predictability, and a device-centric onboarding process, while simplifying setup for employees and enhancing control for IT teams.&lt;/P&gt;
&lt;IMG style="max-width: 10%; height: auto;" src="data:image/jpeg;base64,iVBORw0KGgoAAAANSUhEUgAAAEsAAABLCAMAAAAPkIrYAAAAAXNSR0IB2cksfwAAAAlwSFlzAAALEwAACxMBAJqcGAAAAHtQTFRFAAAA8lAi8lAi8lAi8lAif7oAf7oAf7oAf7oA8lAi8lAi8lAif7oAf7oAf7oA8lAi8lAif7oAf7oA8lAif7oAAaTvAaTvAaTvAaTv/7kB/7kB/7kB/7kBAaTvAaTvAaTv/7kB/7kB/7kBAaTvAaTv/7kB/7kBAaTv/7kBfMz9mwAAACl0Uk5TADt7ag4Oans7/90eHt3/wBoawAMDDh4aAwMaHg5q3cDA3Wp7//97OzspjeVtAAAAlElEQVR4nO3WqwqAQBSEYY+uWiyCBm/J4Pu/jRhMBi8IFsHLCoZ9gCkbRGby8OVfHHuTD1sCQBHtw89hLDdE1h4h6zxp0aJFixYtWrT+bXnA8mWL5QbWZSyFLG9NHmTd9hszhY05ZrAxB2NVsEWnPECf3lg1+F3HXAQKWB0tWrRo0aJFi9a/rUYjaymR5bb2G/OL1guM9e5M8yBd4gAAAABJRU5ErkJggg==" alt="Embedded Image" /&gt;&lt;/DIV&gt;
&lt;DIV class="card"&gt;
&lt;H2&gt;&lt;A href="https://techcommunity.microsoft.com/blog/azurearchitectureblog/from-features-to-flow-how-real-world-adoption-reshaped-the-azure-architecture-di/4546817" target="_blank" rel="noopener noreferrer"&gt;From Features to Flow: How Real-World Adoption Reshaped the Azure Architecture Diagram Builder&lt;/A&gt;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Team Blog:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/category/azure/blog/azurearchitectureblog" target="_blank" rel="noopener noreferrer"&gt;Azure Architecture&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Author:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/users/arturoqu/275153" target="_blank" rel="noopener noreferrer"&gt;arturoqu&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Published:&lt;/STRONG&gt; 08/13/2026&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; The article discusses how real-world adoption of the open-source Azure Architecture Diagram Builder led to a shift from feature-focused development to a guided, four-stage workflow: Create, Refine, Validate &amp;amp; Improve, and Share or Build. User feedback revealed the importance of preserving human edits, improving diagram integrity, and ensuring validation continuity. Adoption data showed users required more than simple diagram generation—they needed iterative refinement, validation, and artifact export. The product now emphasizes workflow coherence, human judgment, and clear boundaries between logical and physical architecture, while maintaining privacy-safe feedback and ongoing open-source development.&lt;/P&gt;
&lt;IMG style="max-width: 10%; height: auto;" src="data:image/jpeg;base64,iVBORw0KGgoAAAANSUhEUgAAAEsAAABLCAMAAAAPkIrYAAAAAXNSR0IB2cksfwAAAAlwSFlzAAALEwAACxMBAJqcGAAAAHtQTFRFAAAA8lAi8lAi8lAi8lAif7oAf7oAf7oAf7oA8lAi8lAi8lAif7oAf7oAf7oA8lAi8lAif7oAf7oA8lAif7oAAaTvAaTvAaTvAaTv/7kB/7kB/7kB/7kBAaTvAaTvAaTv/7kB/7kB/7kBAaTvAaTv/7kB/7kBAaTv/7kBfMz9mwAAACl0Uk5TADt7ag4Oans7/90eHt3/wBoawAMDDh4aAwMaHg5q3cDA3Wp7//97OzspjeVtAAAAlElEQVR4nO3WqwqAQBSEYY+uWiyCBm/J4Pu/jRhMBi8IFsHLCoZ9gCkbRGby8OVfHHuTD1sCQBHtw89hLDdE1h4h6zxp0aJFixYtWrT+bXnA8mWL5QbWZSyFLG9NHmTd9hszhY05ZrAxB2NVsEWnPECf3lg1+F3HXAQKWB0tWrRo0aJFi9a/rUYjaymR5bb2G/OL1guM9e5M8yBd4gAAAABJRU5ErkJggg==" alt="Embedded Image" /&gt;&lt;/DIV&gt;
&lt;DIV class="card"&gt;
&lt;H2&gt;&lt;A href="https://techcommunity.microsoft.com/blog/azurearchitectureblog/choosing-the-right-agent-in-microsoft-foundry/4547827" target="_blank" rel="noopener noreferrer"&gt;Choosing the Right Agent in Microsoft Foundry&lt;/A&gt;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Team Blog:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/category/azure/blog/azurearchitectureblog" target="_blank" rel="noopener noreferrer"&gt;Azure Architecture&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Author:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/users/supriyas/1136782" target="_blank" rel="noopener noreferrer"&gt;supriyas&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Published:&lt;/STRONG&gt; 08/19/2026&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; The article discusses how to choose between Prompt Agents and Hosted Agents in Microsoft Foundry Agent Service. Prompt Agents are simpler, managed by Foundry, and suitable for straightforward tasks with clear instructions. Hosted Agents offer greater control, supporting complex workflows, custom code, and orchestration logic, but require more engineering responsibility. The key decision factor is runtime control—teams should start with Prompt Agents and switch to Hosted Agents only when customization or advanced orchestration is needed. Identifying runtime requirements clarifies which agent type is appropriate, minimizing risk and operational overhead.&lt;/P&gt;
&lt;IMG style="max-width: 10%; height: auto;" src="data:image/jpeg;base64,iVBORw0KGgoAAAANSUhEUgAAAEsAAABLCAMAAAAPkIrYAAAAAXNSR0IB2cksfwAAAAlwSFlzAAALEwAACxMBAJqcGAAAAHtQTFRFAAAA8lAi8lAi8lAi8lAif7oAf7oAf7oAf7oA8lAi8lAi8lAif7oAf7oAf7oA8lAi8lAif7oAf7oA8lAif7oAAaTvAaTvAaTvAaTv/7kB/7kB/7kB/7kBAaTvAaTvAaTv/7kB/7kB/7kBAaTvAaTv/7kB/7kBAaTv/7kBfMz9mwAAACl0Uk5TADt7ag4Oans7/90eHt3/wBoawAMDDh4aAwMaHg5q3cDA3Wp7//97OzspjeVtAAAAlElEQVR4nO3WqwqAQBSEYY+uWiyCBm/J4Pu/jRhMBi8IFsHLCoZ9gCkbRGby8OVfHHuTD1sCQBHtw89hLDdE1h4h6zxp0aJFixYtWrT+bXnA8mWL5QbWZSyFLG9NHmTd9hszhY05ZrAxB2NVsEWnPECf3lg1+F3HXAQKWB0tWrRo0aJFi9a/rUYjaymR5bb2G/OL1guM9e5M8yBd4gAAAABJRU5ErkJggg==" alt="Embedded Image" /&gt;&lt;/DIV&gt;
&lt;DIV class="card"&gt;
&lt;H2&gt;&lt;A href="https://techcommunity.microsoft.com/blog/azuregovernanceandmanagementblog/now-generally-available-what-if-for-azure-deployment-stacks/4547614" target="_blank" rel="noopener noreferrer"&gt;[Now Generally Available] What-If for Azure Deployment Stacks&lt;/A&gt;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Team Blog:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/category/azure/blog/azuregovernanceandmanagementblog" target="_blank" rel="noopener noreferrer"&gt;Azure Governance and Management&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Author:&lt;/STRONG&gt; &lt;A href="https://techcommunity.microsoft.com/users/torreyt/1545508" target="_blank" rel="noopener noreferrer"&gt;torreyt&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Published:&lt;/STRONG&gt; 08/18/2026&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary:&lt;/STRONG&gt; Azure’s Stacks What-if feature is now generally available, providing detailed previews of changes before deploying Azure Deployment Stacks. It shows resource-level actions (create, modify, delete, detach), filters out false positives, and stores results as retrievable resources for use in CI pipelines. This enables safer updates by clarifying impacts, especially deletions or detachments, and supports review and approval workflows. Available across all regions and scopes via CLI, PowerShell, and SDKs, Stacks What-if addresses a top user request by enhancing deployment stack transparency and reliability.&lt;/P&gt;
&lt;IMG style="max-width: 10%; height: auto;" src="data:image/jpeg;base64,iVBORw0KGgoAAAANSUhEUgAAAEsAAABLCAMAAAAPkIrYAAAAAXNSR0IB2cksfwAAAAlwSFlzAAALEwAACxMBAJqcGAAAAHtQTFRFAAAA8lAi8lAi8lAi8lAif7oAf7oAf7oAf7oA8lAi8lAi8lAif7oAf7oAf7oA8lAi8lAif7oAf7oA8lAif7oAAaTvAaTvAaTvAaTv/7kB/7kB/7kB/7kBAaTvAaTvAaTv/7kB/7kB/7kBAaTvAaTv/7kB/7kBAaTv/7kBfMz9mwAAACl0Uk5TADt7ag4Oans7/90eHt3/wBoawAMDDh4aAwMaHg5q3cDA3Wp7//97OzspjeVtAAAAlElEQVR4nO3WqwqAQBSEYY+uWiyCBm/J4Pu/jRhMBi8IFsHLCoZ9gCkbRGby8OVfHHuTD1sCQBHtw89hLDdE1h4h6zxp0aJFixYtWrT+bXnA8mWL5QbWZSyFLG9NHmTd9hszhY05ZrAxB2NVsEWnPECf3lg1+F3HXAQKWB0tWrRo0aJFi9a/rUYjaymR5bb2G/OL1guM9e5M8yBd4gAAAABJRU5ErkJggg==" alt="Embedded Image" /&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 04 Sep 2026 20:18:34 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/check-this-out-cto-guide-september-2026/ba-p/4553591</guid>
      <dc:creator>TysonPaul</dc:creator>
      <dc:date>2026-09-04T20:18:34Z</dc:date>
    </item>
    <item>
      <title>Help Shape the Microsoft Security Practitioner Community</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/help-shape-the-microsoft-security-practitioner-community/ba-p/4553560</link>
      <description>&lt;P&gt;We want to hear from the people who configure, operate, and defend with Microsoft Security every day. Share your priorities, challenges, and where you go to learn and connect.&lt;/P&gt;
&lt;P&gt;Your feedback will help shape future technical content, hands-on experiences, events, and community programs. The survey takes just a few minutes.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Please fill out the survey here: &lt;A href="https://forms.cloud.microsoft/r/hYDWNYeBck" target="_blank"&gt;Microsoft Security Tech Community Practitioner Survey – Fill out form&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Thank you!&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2026 17:05:32 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/help-shape-the-microsoft-security-practitioner-community/ba-p/4553560</guid>
      <dc:creator>BrookeLynnWeenig</dc:creator>
      <dc:date>2026-09-04T17:05:32Z</dc:date>
    </item>
    <item>
      <title>Microsoft Purview - Insider Risk Management</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-external/microsoft-purview-insider-risk-management/m-p/4553508#M26</link>
      <description>&lt;P&gt;&lt;LI-NODE display-id="microsoft-ai-user-group-hyderabad" title="Microsoft AI User Group Hyderabad" node-type="grouphub" parent-id="usergroups"&gt;​&lt;/LI-NODE&gt;&amp;nbsp;What are the Problems statements you faced while Implementing Insider Risk Management for different clients ? Any Common Problems and Challanges which is similar to Financial Services Organization and You have used similar approach or build a Unique Solution to solve this ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Subhajit Bhuiya&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2026 11:30:02 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-external/microsoft-purview-insider-risk-management/m-p/4553508#M26</guid>
      <dc:creator>SubhajitBhuiya</dc:creator>
      <dc:date>2026-09-04T11:30:02Z</dc:date>
    </item>
  </channel>
</rss>

