User Profile
AnuragSrivastava
Iron Contributor
Joined 6 years ago
User Widgets
Recent Discussions
Re: Microsoft 365 Defender ZAP for Exchange Online
flaphead - Yes it should as the job of ZAP is to continually monitoring updates to the spam and malware signatures and find and remove such emails that are already present in user's mailbox. It can take action on both read and unread emails.3.4KViews0likes1CommentRe: Defender options with M365 A3 licensing
Dan-Hudkins - you will get the following capabilities for Defender for Endpoint plan 1 as it a part of Microsoft 365 E3/A3. - Next-generation protection that includes industry-leading, robust antimalware and antivirus protection - Manual response actions, such as sending a file to quarantine, that your security team can take on devices or files when threats are detected - Attack surface reduction capabilities that harden devices, prevent zero-day attacks, and offer granular control over endpoint access and behaviors - Centralized configuration and management with the Microsoft 365 Defender portal and integration with Microsoft Endpoint Manager - Protection for a variety of platforms, including Windows, macOS, iOS, and Android devices6.4KViews0likes0CommentsRe: Defender for Endpoint P1
fatshark_2k - here is the answer to your question: - if we have E3 licenses we access to security.microsoft.com but according to the above P1 features we are NOT allowed to use the TVM dashboard/security recommendations/weakness etc? - TVM is not allowed - we are not allowed to enable EDR in block mode? - EDR is not allowed - the default in DFE is 'full automated remediation and repsonse' so do we have to create a device group and set AIR to not configured? - AIR not available with P1 (E3 License) - which settings in 'settings' are we not allowed to enable as per P1 license? - refer the article for complete details, see the section with heading "Compare Flexible purchase options" - https://www.microsoft.com/en-in/security/business/threat-protection/endpoint-defender - are we allowed to use the MEM/Intune Security Baseline for Defender for Endpoint for our clients cause some settings in this baseline are not P1? - Allowed to use1.5KViews0likes2CommentsRe: No active antivirus provider
Trideep_Dutta you can try this, it worked for me - The issue was due to 'DisableAntiSpyware' registry key under HKLM:\SOFTWARE\Policies\Microsoft\Windows Defender which was set to 1. Now we have the changed the value to 0 and we can see the Microsoft Defender as the active antivirus.63KViews0likes0CommentsRe: Defender Antivirus - how to solve these errors?
John Matrix If Microsoft Defender Antivirus did not download protection updates for a specified period, you can set it up to automatically check and download the latest update at the next log on. Refer the article - https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/manage-outdated-endpoints-microsoft-defender-antivirus?view=o365-worldwide#set-up-catch-up-protection-updates-for-endpoints-that-havent-updated-for-a-while784Views0likes0CommentsRe: KQL for Public Facing CVE-2021-44228 Hosts
Missed one parameter, please try the below DeviceTvmSoftwareVulnerabilities | where CveId in ("CVE-2021-44228") | join kind = inner(DeviceEvents | distinct LocalIP, DeviceName, DeviceId) on $left.DeviceId == $right.DeviceId | distinct DeviceName, LocalIP2.6KViews0likes0CommentsRe: Deploy MDE to mobile device without Intune/MEM?
ahfu285 I am afraid if this can be done without Intune. Microsoft official documentation has listed Intune to be a pre-requisite for using Microsoft Defender - https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/microsoft-defender-endpoint-android?view=o365-worldwide#prerequisites2.9KViews0likes0CommentsRe: Help with machine is using out of date antimalware client version in the organization script
AmjadGov Please see if the below query works: DeviceProcessEvents |where FileName == "MsMpEng.exe" |where FolderPath contains @"C:\ProgramData\Microsoft\Windows Defender\Platform\" |where AccountDomain contains "contoso" |extend PlatformVersion=tostring(split(FolderPath, "\\", 5)) |project DeviceName, PlatformVersion // check which machine is using legacy platformVersion | where AccountDomain contains "bp") on PlatformVersion |summarize dcount(DeviceName) by PlatformVersion // check how many machines are using which platformVersion |order by PlatformVersion desc1KViews0likes3Comments
Recent Blog Articles
No content to show