159 questions with Microsoft Defender for Identity-related tags

Sort by: Updated
2 answers One of the answers was accepted by the question author.

Defender XDR - Broswer extension

Hello, We have the all Defender P1/P2 plan, etc. We had in the past few months in the device page the software inventory->Browser extension. Now, we can received the Data from there and would like to know if something change in the platform or if i…

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,747 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
asked 2024-03-05T19:16:51.87+00:00
Étienne Fiset 45 Reputation points
accepted 2024-03-12T13:20:13.8733333+00:00
Étienne Fiset 45 Reputation points
1 answer One of the answers was accepted by the question author.

suspicious log in defender for endpoint

Hi everyone, I stumbled upon these logs from a machine, they seem very suspicious and not normal, should I be worried? Thanks.

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
asked 2024-02-14T08:51:02.35+00:00
Loïc 60 Reputation points
accepted 2024-03-11T08:56:30.63+00:00
Loïc 60 Reputation points
2 answers One of the answers was accepted by the question author.

Windows Defender Protection History Deletion Issue

Dear Microsoft Support Team, I hope this finds you well. I am writing to seek your assistance in resolving an issue I am facing related to Windows Defender Protection History. I wish to delete the history for security and privacy reasons; however, I am…

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,776 questions
Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
8,369 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
asked 2023-07-18T21:18:08.9966667+00:00
Asma Muzzamil 25 Reputation points
accepted 2024-03-10T16:38:16.5966667+00:00
Asma Muzzamil 25 Reputation points
1 answer

About Authenticator app

I had to change my instagram password and during login I can't find instagram on authenticator app. Kindly help

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,211 questions
Microsoft Configuration Manager
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2024-03-07T01:12:03.1+00:00
Aligeti, Divya 0 Reputation points
commented 2024-03-07T13:54:59.92+00:00
Aligeti, Divya 0 Reputation points
1 answer

How to export payload domains and sender addresses from Attack simulation portal from M365 security defender? Is there way to get all those domains and sender addresses so that we can use for attack simulations based on our choice?

How to export payload domains and sender addresses from Attack simulation portal from M365 security defender? Is there way to get all those domains and sender addresses so that we can use for attack simulations based on our choice and know that its the…

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
3,916 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,211 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-05-05T17:13:40.5433333+00:00
Vinod Survase 4,706 Reputation points
commented 2024-03-07T10:18:34.8133333+00:00
Vinod Survase 4,706 Reputation points
1 answer One of the answers was accepted by the question author.

Blocking Personal Devices While Allowing MFA for Specific Applications

Hello team, Could you please send me steps on how I can block personal devices but allow MFA access for specific applications like Citrix. Thank you for your help

Microsoft Identity Manager
Microsoft Identity Manager
A family of Microsoft products that manage a user's digital identity using identity synchronization, certificate management, and user provisioning.
623 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,454 questions
Microsoft Configuration Manager
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,770 questions
asked 2024-02-27T04:50:46.33+00:00
J-3804 1,516 Reputation points
edited the question 2024-03-07T08:13:27.6533333+00:00
Simon Ren-MSFT 30,676 Reputation points Microsoft Vendor
1 answer

Using KQL in Microsoft Defender to Query files on user computers

Hello, can anyone help me with querying all computers (Windows 10 and 11) in our organization to find the location of files with a specific extension *.ref using KQL in Advanced Hunting? Is it possible to base this query on the Organizational Unit (OU)…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,211 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2024-02-19T13:58:57.79+00:00
APTOS 221 Reputation points
commented 2024-03-01T08:10:59.6833333+00:00
Givary-MSFT 28,571 Reputation points Microsoft Employee
1 answer

User reports Microsoft Authenticator prompt 'ROJMP' - Logging does not show any attempts

Hi all, We recently got a call from a user who said he got a Microsoft Authenticator authentication prompt for something called 'ROJMP'. He did not know what it was for so he declined the prompt and, to be safe, he changed his passwords. He only uses his…

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
349 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
asked 2023-05-22T08:33:29.9633333+00:00
80463912 0 Reputation points
answered 2024-02-24T17:32:08.57+00:00
Fiona Matu 81 Reputation points Microsoft Employee
0 answers

API Advanced Hunting IdentityLogonEvents error

Hi everyone, I'm trying to get the Identitylogonevents result from the API, and I get a forbidden error message, I gave all rights, read all Microsoft documentation and article I found nothing. i have test all this API : #$url =…

Microsoft Identity Manager
Microsoft Identity Manager
A family of Microsoft products that manage a user's digital identity using identity synchronization, certificate management, and user provisioning.
623 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-05-02T13:29:07.31+00:00
mehdi dakhama 336 Reputation points MVP
commented 2024-02-22T09:27:19.62+00:00
Fiona Matu 81 Reputation points Microsoft Employee
1 answer

How to block *.pdf.msi in Microsoft Defender

I was reading through security news and came across this article https://www.bleepingcomputer.com/news/security/microsoft-teams-phishing-pushes-darkgate-malware-via-group-chats/  There is a known file type of .pdf.msi that we as a company are wanting to…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,211 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
asked 2024-02-02T20:45:10.25+00:00
Rubida, Kody 0 Reputation points
commented 2024-02-22T07:49:38.5+00:00
Catherine Kyalo 650 Reputation points Microsoft Employee
0 answers

Windows Defender MpCmdRun.exe Custom Scan Automation Job Failing intermittently in Production Environment using TeamCity Tool

Hello Microsoft Community, We are currently facing an issue with our TeamCity build automation, specifically related to the custom virus scan using the MpCmdRun.exe command-line utility. Our setup involves executing the command: MpCmdRun.exe -Scan…

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,491 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,240 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,211 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2024-02-05T02:04:28.9966667+00:00
Vamshi Krishna 0 Reputation points
commented 2024-02-21T11:51:39.01+00:00
Givary-MSFT 28,571 Reputation points Microsoft Employee
1 answer

Deploying MDI to multiple On-premise DC for monitoring purposes

Hello Team, When deploying MDI to all my on-premise domain controllers for monitoring purposes. Do I need to add new sensors for each dc? or can I use the package and access key from one sensor to all my dc's? Thank you!

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
3,916 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
asked 2024-02-15T04:54:24.4166667+00:00
Bry Ozark 0 Reputation points
commented 2024-02-20T19:07:15.0366667+00:00
JamesTran-MSFT 36,466 Reputation points Microsoft Employee
0 answers

Unable to install Nov 23 patch KB5032189 - curlx.exe has been quarantined by Defender

We have a lot of machine that is currently pending to be install with Nov23 patch KB5032189 . we identified based on the CBS logs that curl.exe has been corrupted. Based on Threat and Virus Protection, Defender has quarantined the mentioned file.…

Windows 10
Windows 10
A Microsoft operating system that runs on personal computers and tablets.
10,759 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
asked 2024-01-31T00:40:22.4833333+00:00
jammerNTFS 0 Reputation points
commented 2024-02-20T11:18:44.4933333+00:00
Catherine Kyalo 650 Reputation points Microsoft Employee
0 answers

Azure Active Directory Identity Protections Risk Detections not all integrate into 365 Defender for indentity

Hi, We have enabled "User report suspicious activities" in the Azure AD Multi-Factor Authentication settings. We do have a user report fraud via authenticator. And Azure Active Directory Identity Protections Risk Detections triggered…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
996 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
asked 2023-08-10T01:27:42.7566667+00:00
Ao(Jonas) Sun 0 Reputation points
commented 2024-02-18T12:42:13.6466667+00:00
Fiona Matu 81 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

Microsoft Defender for Identity vs. Entra ID Protection differences?

Hi Folks, What are the differences between Microsoft Defender for Identity vs. Entra ID Protection? My Environment is already on Entra ID Premium P2, and some of my users already have M365 E5 license According to this article:…

Microsoft Graph
Microsoft Graph
A Microsoft programmability model that exposes REST APIs and client libraries to access data on Microsoft 365 services.
10,772 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,770 questions
asked 2024-02-14T06:11:36.26+00:00
EnterpriseArchitect 4,866 Reputation points
commented 2024-02-16T04:50:45.02+00:00
EnterpriseArchitect 4,866 Reputation points
1 answer One of the answers was accepted by the question author.

How to determine if the Application or Service Principal can be safely deleted in Entra ID?

Folks, I require some assistance and explanation before deleting the App registrations or Enterprise applications based on the below indication:   Owners: empty. Users and groups: empty. Sign-in Logs: no activity in the past 30 days (maximum…

Microsoft Identity Manager
Microsoft Identity Manager
A family of Microsoft products that manage a user's digital identity using identity synchronization, certificate management, and user provisioning.
623 questions
Microsoft Graph
Microsoft Graph
A Microsoft programmability model that exposes REST APIs and client libraries to access data on Microsoft 365 services.
10,772 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
Microsoft Entra
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,770 questions
asked 2024-02-15T10:08:22.84+00:00
EnterpriseArchitect 4,866 Reputation points
commented 2024-02-15T23:12:17.9466667+00:00
EnterpriseArchitect 4,866 Reputation points
3 answers

The recyle Bin on C:\ is corrupted. Do you want to empty Recyle Bin for this drive?

The recyle Bin on C:\ is corrupted. Do you want to empty Recyle Bin for this drive? I say NO!!!!! it seem that when I choose yes the windows system drive, window apps, vital programing is deleted by choosing Yes. please help fixing this problem. It seem…

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
asked 2024-01-31T21:19:30.6433333+00:00
Officedoor.us 0 Reputation points
commented 2024-02-15T23:09:26.9433333+00:00
Officedoor.us 0 Reputation points
1 answer One of the answers was accepted by the question author.

How to leverage Defender for Identity for Azure Domain Services

Is there a way to install sensor for Azure DS? we are fully cloud based, however there are some legacy apps that are still accessing some vms which are joined to azure DS, so can we use / install the sensor to look at those identities?

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
asked 2024-02-02T06:46:04.56+00:00
Rizwan Assad 321 Reputation points
accepted 2024-02-15T07:06:59.7033333+00:00
Rizwan Assad 321 Reputation points
1 answer

Microsoft Defender for Identity (ATP) Pricing

Hi, I was reviewing my cost consumption when I saw that Advanced Threat Protection increased. For the last few months ATP was +-$109 but for the last month ATP was $618. I don`t have any sensors. Could you help with Microsoft Defender for Identity…

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
asked 2023-10-03T11:18:20.89+00:00
Vitalii Liashuk 150 Reputation points
answered 2024-02-14T09:01:22.5166667+00:00
Catherine Kyalo 650 Reputation points Microsoft Employee
1 answer

Monitor one on-premise group and alert one user.

I have an on-premises group that is sensitive and needs to be monitored not just by IT but also the Devs that manage the project. So, when a user gets dropped into the group they want to be notified. I set up a custom rule in D4ID but it only goes to IT,…

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
asked 2023-10-03T21:59:55.05+00:00
LeifDavisson 41 Reputation points
answered 2024-02-13T14:36:11.64+00:00
Fiona Matu 81 Reputation points Microsoft Employee