accessibility
11 TopicsASR Rule Blocking ms-teams.exe
Hi, We have seen the ASR Rule for, 'Block Office communication application from creating child processes' start to block ms-teams.exe, this morning which is causing quite a lot of issues in the estate. The current workaround is to set the ASR Rule of, 'Block Office communication application from creating child processes', to Audit Mode instead of Block Mode. This has also been mentioned by a couple of people now on Twitter, so is MS aware of this issue and do you know when a fix may be in place for this, so I can safely move the ASR Rule back to Block Mode2.1KViews0likes7CommentsDefender RBAC - Grant at least priviliged for Quarantine handling NOT WORKING
Hi everyone, I've already deployed new Defender RBAC permission. I want to assign permission for quarantine message handling WITHOUT Preview Message option. I,ve configured Defender RBAC in follow settings: I've assgined only Security Basic (read) NOT Quarantine handle and NOT Quarantine RAW Contect permission Effect (in production!) I can't assign at-least permission. Currently everyone who has at least permission in Defender RBAC can read all email content for everyone user in organization!! Anyone can help with this case? Follow Defender RBAC docs this user should not have any permission for reading other mails! -- Kind Regards1.2KViews1like7CommentsExcluded Microsoft 365 Defender
I want from the Microsoft 365 Defender panel to create exceptions on one or more computers, that is, so that the antivirus does not scan elements that have been excluded in the exclusion list, but I cannot find that option or if it is possible I want from the Microsoft 365 Defender panel to create exceptions on one or more computers, that is, so that the antivirus does not scan elements that have been excluded in the exclusion list, but I cannot find that option or if it is possible733Views0likes1CommentHow can I share hunting query results with non-security persons in my org?
Advanced hunting logs have rich data that can be helpful to my orgs help desk for figuring out things like machines that are causing account lockouts for failed logon events and such. I'd like to share query results with them but not give up the access that security reader or even basic defender data reader custom role gives access to (needed for using the 'share query' feature). Has anyone tried piping results of a query into power bi or some other place in 365 for making the results data available to non-security users to search?1.2KViews0likes3CommentsM365 Defender integration with Azure Expressroute
Hi Community, One of the customer referring the below documentation: https://docs.microsoft.com/en-us/microsoft-365/security/defender/microsoft-365-defender?view=o365-worldwide Statement : " Microsoft Defender for Endpoint does not provide integration with Azure ExpressRoute. While this does not stop customers from defining ExpressRoute rules that enable connectivity from a private network to Microsoft Defender for Endpoint cloud services, it is up to the customer to maintain rules as the service or cloud infrastructure evolves. " Question: Is there apossibility to route the defender alert/data/etc back to ms365 defender backend through Azure Expressroute? and if yes, what isthe required approach? Many thanks in advance!2.3KViews0likes0Comments