<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Microsoft Defender for Endpoint topics</title>
    <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/bd-p/MicrosoftDefenderATP</link>
    <description>Microsoft Defender for Endpoint topics</description>
    <pubDate>Wed, 05 Aug 2026 13:24:39 GMT</pubDate>
    <dc:creator>MicrosoftDefenderATP</dc:creator>
    <dc:date>2026-08-05T13:24:39Z</dc:date>
    <item>
      <title>EnableConvertWarnToBlock will not enable - stays False</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/enableconvertwarntoblock-will-not-enable-stays-false/m-p/4543965#M6912</link>
      <description>&lt;P&gt;We have a GPO applied to Windows 11 Pro machine - fully patched and onboarded to MDE. The GPO enables "EnableConvertWarnToBlock" as follows:&lt;/P&gt;&lt;img /&gt;&lt;P&gt;The GPO is applied to the machine and the following registry key is populated:&lt;/P&gt;&lt;img /&gt;&lt;P&gt;But when I check the status on the client - it will not enable:&lt;/P&gt;&lt;img /&gt;&lt;P&gt;I have enabled troubleshooting mode and disabled tamper protection in case this is blocking but nothing seems to work. Its as if MDAV/MDE is not even looking/reading that registry key.&lt;/P&gt;&lt;P&gt;Anyone else have the same issue or ideas on resolution?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2026 16:27:15 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/enableconvertwarntoblock-will-not-enable-stays-false/m-p/4543965#M6912</guid>
      <dc:creator>Warren212</dc:creator>
      <dc:date>2026-08-04T16:27:15Z</dc:date>
    </item>
    <item>
      <title>Location of Defender for Identity Entry in Defender Tables</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/location-of-defender-for-identity-entry-in-defender-tables/m-p/4543592#M6911</link>
      <description>&lt;P&gt;Our GRC group wants an automated report on windows servers and workstations over 7 days old not onboarded for Defender for Endpoint. A change in our environment (not sure if it was MS or us) has caused an additional entry in a column named "DiscoverySources" for Defender for Identity. It's my understanding that D4I is only used on domain controllers, but we get entries on non-DCs as well.&amp;nbsp; This identifier does not appear on the device dashboard, nor can I add it in with the custom column tab. Furthermore, if a machine requires onboarding for D4E, it will show them both in the same column, it separates them with a comma in the same field.&lt;/P&gt;&lt;P&gt;Right now, I have to do this process manually and with the overhead involved, it takes me about 30 minutes to run the reports, filter out the false positives and forward them to the appropriate staff.&amp;nbsp; They want this every day, and I can't do this operationally. I'd welcome the opportunity to create a Logic App based on a query to perform this function and route it.&lt;/P&gt;&lt;P&gt;Can someone point me in the direction of the table which contains the DiscoverSources column? I haven't been able to find it. That would help me to perform the necessary KQL and Logic App to automate this process.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Long time listener. First time publisher. Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2026 18:39:16 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/location-of-defender-for-identity-entry-in-defender-tables/m-p/4543592#M6911</guid>
      <dc:creator>MichaelMichalko</dc:creator>
      <dc:date>2026-08-03T18:39:16Z</dc:date>
    </item>
    <item>
      <title>Defender Device Groups</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/defender-device-groups/m-p/4542535#M6908</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;I need some help creating a device group in Defender. I can't find anything related to Groups inside Microsoft Security. I'd read that it's possible to create one inside the Permissions tab, but I can't figure out how.&lt;/P&gt;&lt;P&gt;Someone can explain what's the process?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2026 20:59:40 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/defender-device-groups/m-p/4542535#M6908</guid>
      <dc:creator>alexcolombari</dc:creator>
      <dc:date>2026-07-30T20:59:40Z</dc:date>
    </item>
    <item>
      <title>Inconsistent Microsoft Defender Behaviour</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/inconsistent-microsoft-defender-behaviour/m-p/4538802#M6904</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;We have an issue whereby across several intune managed devices with identical defender AV policy, signature version, and platform version, we've found inconsistent detection/remediation behaviour.&lt;/P&gt;&lt;P&gt;Some devices block malicious files instantly on download (expected and correct). Others only detect on open rather than on write, or log a successful detection/remediation action without the file actually being removed from disk, it remains fully accessible indefinitely.&lt;/P&gt;&lt;P&gt;Since this occurs despite identical config, we're concerned this is a genuine gap in automatic remediation reliability that could affect real threats, not just our test files.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Troubleshooting completed, issue persists:&lt;/P&gt;&lt;P&gt;- Ruled out exclusions (path/extension/process)&lt;/P&gt;&lt;P&gt;- Confirmed PUA protection, real-time protection, tamper protection, and all granular protection flags enabled/healthy&lt;/P&gt;&lt;P&gt;- Removed orphaned third-party AV registrations from WSC (previously caused Defender to show as "snoozed")&lt;/P&gt;&lt;P&gt;- Confirmed filter driver (WdFilter) loaded correctly, no conflicts&lt;/P&gt;&lt;P&gt;- Cleared stuck "detected but not remediated" threat entries&lt;/P&gt;&lt;P&gt;- Ruled out file locks preventing remediation&lt;/P&gt;&lt;P&gt;- Cleared cached signature state, forced fresh signature pull&lt;/P&gt;&lt;P&gt;- Attempted full platform reset&lt;/P&gt;&lt;P&gt;- Confirmed cloud protection/MAPS enabled and reachable&lt;/P&gt;&lt;P&gt;- Increased CloudBlockLevel to test enforcement aggressiveness&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone have any idea what could be happening here?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2026 07:54:38 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/inconsistent-microsoft-defender-behaviour/m-p/4538802#M6904</guid>
      <dc:creator>OllieHay1</dc:creator>
      <dc:date>2026-07-20T07:54:38Z</dc:date>
    </item>
    <item>
      <title>MDVM - Patch Publication Date</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/mdvm-patch-publication-date/m-p/4537884#M6902</link>
      <description>&lt;P&gt;Dear Microsoft MDVM Development Team,&lt;/P&gt;&lt;P&gt;Please could you as quickly as possible implement the "Patch Publication Date" for the vulnerabilities you report on. Any major Vulnerability management platform has this simple field/record please advise you are implementing this and the timeframe for it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;&lt;P&gt;Graeme&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2026 14:54:25 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/mdvm-patch-publication-date/m-p/4537884#M6902</guid>
      <dc:creator>cipherdell</dc:creator>
      <dc:date>2026-07-16T14:54:25Z</dc:date>
    </item>
    <item>
      <title>DVM Certificate Inventory Shows No Data Despite Healthy Endpoints in Defender for Endpoint</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/dvm-certificate-inventory-shows-no-data-despite-healthy/m-p/4534494#M6897</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;I'm testing Microsoft Defender Vulnerability Management.&lt;/P&gt;&lt;P&gt;Current status:&lt;/P&gt;&lt;P&gt;- Defender Vulnerability Management Add-on enabled&lt;/P&gt;&lt;P&gt;- Certificates inventory tab is visible&lt;/P&gt;&lt;P&gt;- Software Inventory populated&lt;/P&gt;&lt;P&gt;- Security Recommendations populated&lt;/P&gt;&lt;P&gt;- Windows and Linux devices onboarded&lt;/P&gt;&lt;P&gt;- Linux mdatp health = healthy:true, licensed:true, cloud_enabled:true&lt;/P&gt;&lt;P&gt;- Devices have local certificates installed&lt;/P&gt;&lt;P&gt;- Certificate Inventory page shows "No data"&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;The DVM Add-on was enabled more than 36 hours ago.&lt;/P&gt;&lt;P&gt;Has anyone experienced a delay in Certificate Inventory population or are there additional prerequisites beyond DVM licensing and device onboarding?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2026 12:54:31 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/dvm-certificate-inventory-shows-no-data-despite-healthy/m-p/4534494#M6897</guid>
      <dc:creator>vijaysethiya</dc:creator>
      <dc:date>2026-07-07T12:54:31Z</dc:date>
    </item>
    <item>
      <title>Microsoft Defender false positive and WDSI submission details page bug</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/microsoft-defender-false-positive-and-wdsi-submission-details/m-p/4530787#M6892</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am the developer and publisher of Pulse Launcher, a legitimate signed Windows application / Minecraft mod launcher.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I already submitted this through Microsoft Security Intelligence and also opened a Microsoft Q&amp;amp;A thread, but I am posting here because the WDSI submission portal itself appears to be broken for these submissions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Related Microsoft Q&amp;amp;A thread:&lt;/P&gt;&lt;P&gt;https://learn.microsoft.com/en-us/answers/questions/5929545/microsoft-defender-false-positive-and-wdsi-submiss&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are two related issues:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Microsoft Defender cloud ML false positives keep appearing on public multi-engine scan results for the same signed application/product family. The Microsoft detection name changes across rescans and equivalent builds, including:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- PUA:Win32/Puwaders.C!ml&lt;/P&gt;&lt;P&gt;- Program:Win32/Wacapew.C!ml&lt;/P&gt;&lt;P&gt;- Trojan:Win32/Wacatac.B!ml&lt;/P&gt;&lt;P&gt;- Trojan:Win32/Wacatac.C!ml&lt;/P&gt;&lt;P&gt;- Trojan:Win32/Sabsik.EN.A!ml&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. Microsoft Security Intelligence submissions are visible in Submission history and show status "In progress", but opening the submission details page returns:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"The details for the submission were not found or the submission has expired."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Affected submission IDs:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- dd476efa-fc04-4f13-82cf-631bbfd145a6&lt;/P&gt;&lt;P&gt;- efc6514c-d700-4d6a-a7e2-67a9a83334a2&lt;/P&gt;&lt;P&gt;- ff8d04b7-c5fc-4a05-bd53-ee7ac5981284&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;File details:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- File name: pulse_launcher.exe&lt;/P&gt;&lt;P&gt;- SHA-256: def6059c07c3e1f4a8c5649a1bbf190d4f355ee8e8b88c55c5b404edee99ecc8&lt;/P&gt;&lt;P&gt;- Signer: FOP Haponiuk Mykola Viktorovych&lt;/P&gt;&lt;P&gt;- Certificate: GlobalSign EV Code Signing certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The executable is not VMProtect-packed or obfuscated. It is EV-signed. A previous Microsoft analyst response stated that the file did not meet Microsoft criteria for malware or PUA, but Microsoft cloud detections continue to appear.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could someone route this to Microsoft Defender Security Intelligence / malware analysis, or advise how to escalate WDSI submissions that exist in history but whose details endpoint returns "not found or expired"?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2026 02:56:05 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/microsoft-defender-false-positive-and-wdsi-submission-details/m-p/4530787#M6892</guid>
      <dc:creator>MykolaHaponiuk</dc:creator>
      <dc:date>2026-06-25T02:56:05Z</dc:date>
    </item>
    <item>
      <title>Microsoft Defender for Endpoint and WDAC audit logs not include kernel audit/blocks</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/microsoft-defender-for-endpoint-and-wdac-audit-logs-not-include/m-p/4527862#M6885</link>
      <description>&lt;P&gt;While testing WDAC on a fully patched Win11 pro machine - I noticed that kernel audit/block events do not get collected by MDE in the advanced hunting portal, only user mode audit/blocks are collected. Can anyone confirm they see this too and is this by design?&lt;/P&gt;&lt;P&gt;My test case is to use a Strict Kernel Mode WDAC policy (as per:&lt;/P&gt;&lt;P&gt;https://github.com/HotCakeX/Harden-Windows-Security/wiki/WDAC-policy-for-BYOVD-Kernel-mode-only-protection) which is active, using the global secure access client as my test, when the machine boots, the below event is generated locally on the machine:&amp;nbsp;&lt;/P&gt;&lt;img /&gt;&lt;img /&gt;&lt;img /&gt;&lt;P&gt;This event is never shown on the MDE advanced hunting portal, though user events do show. Examples of events that are coming through:&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not receiving these events centrally for auditing would make deploying a kernel mode wdac control impossible. Would be amazing if Microsoft product team could look into this and resolve as these alerts should be captured as well please to facilitate deployment of more secure controls.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2026 13:35:02 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/microsoft-defender-for-endpoint-and-wdac-audit-logs-not-include/m-p/4527862#M6885</guid>
      <dc:creator>Warren212</dc:creator>
      <dc:date>2026-06-12T13:35:02Z</dc:date>
    </item>
    <item>
      <title>Ways to fetch quarantine files</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/ways-to-fetch-quarantine-files/m-p/4526637#M6884</link>
      <description>&lt;P&gt;We are working with quarantine files and have a few questions:&lt;/P&gt;&lt;P&gt;1. Is there a public API available to retrieve quarantined files from Microsoft Defender for Endpoint?&lt;/P&gt;&lt;P&gt;2. Is there a documented method to map an alert or a file SHA-1/SHA-256 hash to the corresponding object in the Defender quarantine store?&lt;/P&gt;&lt;P&gt;3. Is there a way to retrieve quarantined files other than using a PowerShell script through the Live Response API?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2026 05:36:57 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/ways-to-fetch-quarantine-files/m-p/4526637#M6884</guid>
      <dc:creator>Dhwani_Shah</dc:creator>
      <dc:date>2026-06-09T05:36:57Z</dc:date>
    </item>
    <item>
      <title>Understanding AI workloads on Linux</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/understanding-ai-workloads-on-linux/m-p/4524856#M6883</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;I’m a PM working on security for Linux environments and trying to better understand how AI workloads are actually showing up in production today.&lt;/P&gt;
&lt;P&gt;Would appreciate hearing from folks here:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Are you running any AI workloads on Linux today? Or actively exploring?&lt;/LI&gt;
&lt;LI&gt;What does your deployment/setup look like — e.g., model training/inference, agents, MCP servers, data pipelines, etc.?&lt;/LI&gt;
&lt;LI&gt;How are you thinking about securing this stack, if at all?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If you’re open to a quick &lt;STRONG&gt;30-min chat&lt;/STRONG&gt;, I’d love to learn more from your experience as well.&lt;/P&gt;
&lt;P&gt;Thanks in advance — this will directly help shape where we invest next.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2026 15:01:12 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/understanding-ai-workloads-on-linux/m-p/4524856#M6883</guid>
      <dc:creator>tejaskashyap</dc:creator>
      <dc:date>2026-06-02T15:01:12Z</dc:date>
    </item>
    <item>
      <title>Larac2shell: Turning MDE Live Response into a near real-time shell We are the EDR!</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/larac2shell-turning-mde-live-response-into-a-near-real-time/m-p/4517733#M6878</link>
      <description>&lt;P&gt;&lt;A class="lia-external-url" href="https://github.com/akefallonitis/larac2shell" target="_blank"&gt;https://github.com/akefallonitis/larac2shell&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Turning MDE live response into a near real time interactive shell beta version out&lt;/P&gt;&lt;P&gt;Features:&lt;/P&gt;&lt;P&gt;- Internal (Thanks to&amp;nbsp;&lt;A href="https://www.linkedin.com/in/fabianbader/" target="_blank"&gt;Fabian Bader&lt;/A&gt;&amp;nbsp;-&amp;nbsp;&lt;A href="https://www.linkedin.com/in/nathanmcnulty/" target="_blank"&gt;Nathan McNulty&lt;/A&gt;&amp;nbsp;and xdrinternals research ) vs External api authentication&lt;BR /&gt;- Arbitrary command execution via pre-uploaded base64 wrapper script&lt;BR /&gt;- Cross-OS support&lt;/P&gt;&lt;P&gt;PS Two MSRC bugs reported for direct command execution bypass waiting for Microsoft Response in order to publish them&lt;/P&gt;&lt;P&gt;Coming SOON TM&lt;/P&gt;&lt;P&gt;Full LaraC2 Post Exploitation OST framework over MDE as C2/C3 Channel - We are the EDR / No external Infra / Onboarding to your controlled tenant silencing MDE&lt;/P&gt;&lt;P&gt;Happy testing 🥳 🎉&lt;/P&gt;</description>
      <pubDate>Fri, 08 May 2026 08:25:12 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/larac2shell-turning-mde-live-response-into-a-near-real-time/m-p/4517733#M6878</guid>
      <dc:creator>alkefallonitis</dc:creator>
      <dc:date>2026-05-08T08:25:12Z</dc:date>
    </item>
    <item>
      <title>runHuntingQuery API and 'evaluate pivot'</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/runhuntingquery-api-and-evaluate-pivot/m-p/4516423#M6876</link>
      <description>&lt;P&gt;Seem to have a problem where any request to the&amp;nbsp; runHuntingQuery API with 'evaluate pivot' fails with&amp;nbsp;&lt;/P&gt;&lt;P&gt;error": {&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; "code": "UnknownError",&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; "message": "",&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this just a 'feature' ?&amp;nbsp; The query happily runs trough the website/XDR portal. :-(&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to simulate a pivot (easily) in powerapps ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 May 2026 09:26:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/runhuntingquery-api-and-evaluate-pivot/m-p/4516423#M6876</guid>
      <dc:creator>Tim4</dc:creator>
      <dc:date>2026-05-01T09:26:00Z</dc:date>
    </item>
    <item>
      <title>Defender for Business - No alert after process lock out ?</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/defender-for-business-no-alert-after-process-lock-out/m-p/4489725#M6859</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A few days ago, I have setup Defender for business server on a Windows Server 2019.&lt;/P&gt;&lt;P&gt;I can see that server in the Microsoft security portail devices list.&lt;/P&gt;&lt;P&gt;I have also tested the "suspicious" powershell command provided by Microsoft and it went all good. Powershell blocked, alert escaladed as incident in the security portal, email received, ...&lt;/P&gt;&lt;P&gt;But the next day, I tried to install a service on that server that got blocked by Virus &amp;amp; Thread Protection because it was attempting to modify a lot of files. That was a good point for Defender (it was not a real thread and was later added as exception).&lt;/P&gt;&lt;P&gt;My worry is that it was never escaladed to the security portal, I didn't received a alert email, .. The system blocked that "thread" multiple times during my attempt to deploy it and no incident were throw.&lt;BR /&gt;&lt;BR /&gt;What could be wrong ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jan 2026 11:43:15 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/defender-for-business-no-alert-after-process-lock-out/m-p/4489725#M6859</guid>
      <dc:creator>karnalta</dc:creator>
      <dc:date>2026-01-27T11:43:15Z</dc:date>
    </item>
    <item>
      <title>Save the date - January 26, 2026 - AMA: Secure your endpoints with policy and Microsoft Defender</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/save-the-date-january-26-2026-ama-secure-your-endpoints-with/m-p/4487926#M6855</link>
      <description>&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Save the date for &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-occasion" href="https://techcommunity.microsoft.com/event/microsoftintuneevents/ama-secure-your-endpoints-with-policy-and-microsoft-defender/4485786" target="_blank" rel="noopener" data-lia-auto-title="January 26 at 8:00 AM PT" data-lia-auto-title-active="0"&gt;January 26 at 8:00 AM PT&lt;/A&gt;! Have questions about using Microsoft Intune to enforce device compliance? Curious how to configure devices to help prevent security breaches and limit the impact of threats? Ask Microsoft Anything (AMA) about integrating Microsoft Defender for Endpoint with Microsoft Intune at Tech Community Live! &lt;BR /&gt;&lt;BR /&gt;Product teams will be answering your questions live and in chat. Get tips using policy to onboard devices, define risk level, block non-compliant devices from accessing corporate resources, and more.&lt;BR /&gt;&lt;BR /&gt;Go to&amp;nbsp;&lt;A href="https://aka.ms/AMA/SecureEndpoints" target="_blank" rel="noopener"&gt;aka.ms/AMA/SecureEndpoints&lt;/A&gt; to save the date and add this event to your calendar!&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jan 2026 22:13:25 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/save-the-date-january-26-2026-ama-secure-your-endpoints-with/m-p/4487926#M6855</guid>
      <dc:creator>Pearl-Angeles</dc:creator>
      <dc:date>2026-01-20T22:13:25Z</dc:date>
    </item>
    <item>
      <title>Defender for Identity health issues</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/defender-for-identity-health-issues/m-p/4487106#M6851</link>
      <description>&lt;P&gt;When will the issues/alerts from defender for identity sensors be available to view via advanced hunting instead of the Graph API and "/security/identities/healthIssues"&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jan 2026 11:31:19 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/defender-for-identity-health-issues/m-p/4487106#M6851</guid>
      <dc:creator>zlate81</dc:creator>
      <dc:date>2026-01-19T11:31:19Z</dc:date>
    </item>
    <item>
      <title>Using MDE (Passive Mode) with Palo Alto Cortex XDR to enable Defender for IoT (Enterprise IoT)</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/using-mde-passive-mode-with-palo-alto-cortex-xdr-to-enable/m-p/4485625#M6850</link>
      <description>&lt;P&gt;Hi everyone!&lt;BR /&gt;I’m working with a customer that uses &lt;STRONG&gt;Palo Alto Cortex XDR&lt;/STRONG&gt; as their primary EDR. We want to leverage &lt;STRONG&gt;Microsoft Defender for IoT&lt;/STRONG&gt; specifically for &lt;STRONG&gt;Enterprise IoT&lt;/STRONG&gt; (not OT/ICS). I have a few questions:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;MDE in Passive Mode as a sensor:&lt;/STRONG&gt;&lt;BR /&gt;Can &lt;STRONG&gt;Microsoft Defender for Endpoint (MDE)&lt;/STRONG&gt; running in &lt;STRONG&gt;Passive mode&lt;/STRONG&gt; act as a sensor to enable Enterprise IoT discovery/monitoring for Defender for IoT? Are there any &lt;STRONG&gt;feature limitations&lt;/STRONG&gt; when MDE is not the primary EDR?&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Appliance sensor in Enterprise IT:&lt;/STRONG&gt;&lt;BR /&gt;If we cannot use the MDE agent, is it &lt;STRONG&gt;supported&lt;/STRONG&gt; to deploy the &lt;STRONG&gt;Defender for IoT appliance sensor&lt;/STRONG&gt; in an &lt;STRONG&gt;enterprise IT network&lt;/STRONG&gt; (e.g., offices/campuses) to cover &lt;STRONG&gt;Enterprise IoT&lt;/STRONG&gt; use cases?&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Coexistence / Complementary sensors:&lt;/STRONG&gt;&lt;BR /&gt;Is it possible (and recommended) to run the &lt;STRONG&gt;appliance sensor alongside MDE (sensor)&lt;/STRONG&gt; to &lt;STRONG&gt;complement coverage/features&lt;/STRONG&gt;? Any guidance on &lt;STRONG&gt;architecture&lt;/STRONG&gt;, &lt;STRONG&gt;data overlap/deduplication&lt;/STRONG&gt;, or &lt;STRONG&gt;licensing implications&lt;/STRONG&gt;?&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Wed, 14 Jan 2026 13:56:04 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/using-mde-passive-mode-with-palo-alto-cortex-xdr-to-enable/m-p/4485625#M6850</guid>
      <dc:creator>gabpereira</dc:creator>
      <dc:date>2026-01-14T13:56:04Z</dc:date>
    </item>
    <item>
      <title>Alert tuning for Custom detection rules</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/alert-tuning-for-custom-detection-rules/m-p/4485384#M6846</link>
      <description>undefined</description>
      <pubDate>Tue, 13 Jan 2026 18:40:36 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/alert-tuning-for-custom-detection-rules/m-p/4485384#M6846</guid>
      <dc:creator>mikhailf</dc:creator>
      <dc:date>2026-01-13T18:40:36Z</dc:date>
    </item>
    <item>
      <title>MS Defender setting</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/ms-defender-setting/m-p/4484770#M6844</link>
      <description>&lt;P&gt;Hello, I have a question.&lt;/P&gt;&lt;P&gt;I'm not an English-speaking country, so please understand any shortcomings.&lt;/P&gt;&lt;P&gt;I'm trying to block or alert on specific URLs in Microsoft Defender &amp;gt; Settings &amp;gt; Endpoint &amp;gt; Rules &amp;gt; Indicators. I've completed the setup, but I'd like to customize the screen that appears on the webpage when an alert is triggered.&lt;/P&gt;&lt;P&gt;Is there a way to do this?&lt;/P&gt;&lt;P&gt;Thank you in advance for your help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2026 01:19:46 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/ms-defender-setting/m-p/4484770#M6844</guid>
      <dc:creator>sangbin</dc:creator>
      <dc:date>2026-01-12T01:19:46Z</dc:date>
    </item>
    <item>
      <title>Grounds up</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/grounds-up/m-p/4483712#M6843</link>
      <description>&lt;P&gt;A business that respects others to help kis be business owners&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jan 2026 10:30:30 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/grounds-up/m-p/4483712#M6843</guid>
      <dc:creator>ozanwilliams</dc:creator>
      <dc:date>2026-01-07T10:30:30Z</dc:date>
    </item>
    <item>
      <title>Latest Threat Intelligence (December 2025)</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/latest-threat-intelligence-december-2025/m-p/4481588#M6842</link>
      <description>&lt;P&gt;Microsoft Defender for IoT has released the December 2025 Threat Intelligence package. The package is available for download from the &lt;A href="https://ms.portal.azure.com/#blade/Microsoft_Azure_IoT_Defender/IoTDefenderDashboard/Getting_Started" aria-label="Link Microsoft Defender for IoT portal" target="_blank"&gt;Microsoft Defender for IoT portal&lt;/A&gt;&amp;nbsp;(click Updates, then Download file).&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Threat Intelligence updates reflect the combined impact of proprietary research and threat intelligence carried out by Microsoft security teams.&amp;nbsp;Each package contains the latest CVEs (Common Vulnerabilities and Exposures), IOCs (Indicators of Compromise), and other indicators applicable to IoT/ICS/OT networks (published during the past month) researched and implemented by Microsoft Threat Intelligence Research - CPS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The CVE scores are aligned with the National Vulnerability Database (NVD). Starting with the August 2023 threat intelligence updates, CVSSv3 scores are shown if they are relevant; otherwise the CVSSv2 scores are shown.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Guidance&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Customers are recommended to update their systems with the latest TI package in order to detect potential exposure risks and vulnerabilities in their networks and on their devices. Threat Intelligence packages are updated every month with the most up-to-date security information available, ensuring that Microsoft Defender for IoT can identify malicious actors and behaviors on devices.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Update your system with the latest TI package&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The package is available for download from the&amp;nbsp;&lt;A href="https://ms.portal.azure.com/#blade/Microsoft_Azure_IoT_Defender/IoTDefenderDashboard/Getting_Started" aria-label="Link Microsoft Defender for IoT portal" target="_blank"&gt;Microsoft Defender for IoT portal&lt;/A&gt;&amp;nbsp;(click Updates, then Download file), for more information, please review&amp;nbsp;&lt;A href="https://docs.microsoft.com/en-us/azure/defender-for-iot/organizations/how-to-work-with-threat-intelligence-packages" aria-label="Link Update threat intelligence data | Microsoft Docs" target="_blank"&gt;Update threat intelligence data | Microsoft Docs&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MD5 Hash: 5c642a16bf56cb6d98ef8b12fdc89939&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For cloud connected sensors, Microsoft Defender for IoT can automatically update new threat intelligence packages following their release,&amp;nbsp;&lt;A href="https://docs.microsoft.com/en-us/azure/defender-for-iot/organizations/release-notes" aria-label="Link click here&amp;nbsp;" target="_blank"&gt;click here&amp;nbsp;&lt;/A&gt;for more information.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Dec 2025 07:00:11 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/latest-threat-intelligence-december-2025/m-p/4481588#M6842</guid>
      <dc:creator>Theo_Cohen</dc:creator>
      <dc:date>2025-12-29T07:00:11Z</dc:date>
    </item>
  </channel>
</rss>

