User Profile
WimVClapdurp
Copper Contributor
Joined 2 years ago
User Widgets
Recent Discussions
Re: High upload by user, user does not know why
@modencloud1 This is probably the case that Jarno86 looked in the MCAS dashboard and there it is listed as a user with high upload. So you start to investigate why this user is uploading so much. Then when you dive deeper you see that it is e-mail related. Next steps is to ask the user (director) why this is. As the user did not have a valid reason why this is. You start digging deeper. So they found out the profile sync was out of sync. Why this is is to much to remediate -> so solution is to scratch the profile and rebuild it. Then you see in the MCAS the user is syncing regular and all is ok. The MCAS dashboard shows a lot of valuable information about users in you tenant. Be aware to respect privacy matters especially in Europe GDPR. If you have a DPO consult together from this portal as it might contain sensitive information's.1.2KViews0likes0CommentsRe: MS Defender mixed licensing
Helloaleks32 Have you enabled mixed license mode also in Ms Defender for Endpoint? In defender portal (security.microsoft.com) go to settings -> endpoints -> licenses. Subscription state -> manage subscription Here you need to select the option to mixed mode. Choose what devices get plan 1 the rest will get P2 automatically. you need to create a device tag (for example MDE P1 License. Hope this can help you. Kind regards, Wim2.7KViews0likes2CommentsI need to deploy DFI for a couple of users
Hi community. I need to deploy Defender for Identity for a couple of users in de organization. But the business does not want to buy an E5 license for everyone. As I can read on the DFI tech pages: How can the service be applied only to users in the tenant who are licensed for the service? Microsoft Defender for Identity services are currently not capable of limiting capabilities to specific users. Efforts should be taken to limit the service benefits to licensed users. So, how can I restrict only to the C-level or admin users/high sensitive users? And how many license do I need to assign to only use the feature for my high sensitive users? What effort can I take?Solved793Views0likes1CommentHow to capture logon events from a centralized winevent log instead of the security log
Hi community, I would like to hear or find how I can get logon events from a centralize WEC (event collector server) in a winevent log. When the Sentinel AMA agent is installed it captures the security events from the WEC server security log. But I want to capture the logon events from multiple subscriptions in a defined Winevent log. So not from the security log itself from the collector server. How can I define the new log?601Views0likes0Comments
Groups
Recent Blog Articles
No content to show