
Philip K
260 posts

Philip K
@KronheimK
IT Specialist #Windows10 #ConfigMgr #Intune #EMS #SCCM
Germany Katılım Aralık 2015
279 Takip Edilen90 Takipçiler
Philip K retweetledi

In the last months, I have collected some awesome new #KQL sources, and this 🧵lists them.
Are you using Defender For Endpoint, Sentinel, Intune or do you want to learn KQL then have a look!
#MDE #Sentinel #Intune #Detection #ThreatHunting
English
Philip K retweetledi

MDE - Visualizing ASR Rule Detections with KQL github.com/LearningKijo/K…
#MustLearnKQL #KQL #MicrosoftDefender #Security #MicrosoftSecurity #Cybersecurity #M365D
English
Philip K retweetledi

This @Microsoft #EntraID tweet blew up, so here is some #KQL to go along with it...
I removed Per-user MFA from all but one user (you got to have a control!); checking the impact of that change:
Colours are hard to make out, but only one user impacted post-change!
#Result

Jonathan Bourke@jonathanbourke
Quick @Microsoft #EntraID tip: Getting excessive MFA prompts? Use the "Authentication Prompts Analysis" workbook under Entra ID > Identity > Monitoring & Health > Workbooks and look for "Authentication prompts by policy"
English
Philip K retweetledi
Philip K retweetledi

Just released my latest analysis of Defender for Endpoint features by OS.
Targeted at folks deploying MDE to understand what can be used and where; what capabilities you might have missed; or potential customers evaluating options.
Blog + download: campbell.scot/mde-comparison…

English
Philip K retweetledi
Philip K retweetledi

I've always thought that in order for Defenders to be truly effective, it is vital they know where the telemetry they are leveraging is coming from.
Today I am releasing a project called TelemetrySource that is meant to support that cause.
Blog: posts.specterops.io/uncovering-win…
English
Philip K retweetledi

This short and sweet video explains the Microsoft Defender for Endpoint architecture. Thanks @HeikeRitter
youtube.com/watch?v=C0ato8…

YouTube

English
Philip K retweetledi
Philip K retweetledi

Security Settings Management in Microsoft Defender for Endpoint is now generally available: Security Settings Management in Microsoft Defender for Endpoint is now generally available (3 min.)
Preventing data breaches and… bit.ly/3FFJUVV #MDATP #Security #MEM

English
Philip K retweetledi
![Damien Van Robaeys [MVP]](https://pbs.twimg.com/profile_images/1686796527799332894/JWEicRmW.jpg)
📢 All sessions from the Modern Endpoint Management Summit 2022 are now available on YouTube
#MSIntune #Intune #MEMPowered
youtu.be/Xuh4ZPUUulY

YouTube
English
Philip K retweetledi
Philip K retweetledi
Philip K retweetledi

#AzureAD #ConditionalAccess needs to be carefully monitored and you need to act on any insecure configuration changes. I decided to create a Conditional Access analytic rules pack for #MicrosoftSentinel, and here it is!! danielchronlund.com/2022/04/13/mon…

English
Philip K retweetledi

➡️Intune Audit Logs Track Who Created Updated Device Compliance Policy – anoopcnair.com/intune-audit-l…

English
Philip K retweetledi
![Damien Van Robaeys [MVP]](https://pbs.twimg.com/profile_images/1686796527799332894/JWEicRmW.jpg)
Just updated my BSOD remediation script to:
- Automatically detect devices with new BSOD
- Automatically send logs on SharePoint
- Automatically create a new notif on Teams
#MEMPowered #MSIntune #Intune #SharePoint
![Damien Van Robaeys [MVP] tweet media](https://pbs.twimg.com/media/FNK0tj6WUAIf1lQ.jpg)
Damien Van Robaeys [MVP]@syst_and_deploy
Proactive Remediation: detect devices with recent BSOD and automatically upload log files to SharePoint #MEMPowered #MSIntune #Intune #SharePoint #PowerShell @Hoorge @DeploymentMX @TheAviPrasad @IntuneSuppTeam @MSIntune @tekman2300 @Bitc0inTech systanddeploy.com/2022/03/proact…
English
Philip K retweetledi
![Damien Van Robaeys [MVP]](https://pbs.twimg.com/profile_images/1686796527799332894/JWEicRmW.jpg)
Working on a new Proactive Remediation to inform user their Azure AD password will soon expire
#MEMPowered #MSIntune #Intune
![Damien Van Robaeys [MVP] tweet media](https://pbs.twimg.com/media/FNAhM7OXwAAH6LQ.png)
English
Philip K retweetledi

#ProTip If you check the following paths on the device & don't see the #WindowsUpdate policy you've "set"- you haven't set it.
GP: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate
CSP: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\current\device\Update

English
Philip K retweetledi
![Damien Van Robaeys [MVP]](https://pbs.twimg.com/profile_images/1686796527799332894/JWEicRmW.jpg)
A quick Proactive Remediation script for low disk space to:
- Display a toast notif warning
- Display an HTML report of larger content on disk (larger folders in C:\Users and C:\, larger files in C:\, folder redirection status...)
systanddeploy.com/2022/01/proact…
#MEMPowered #MSIntune
![Damien Van Robaeys [MVP] tweet media](https://pbs.twimg.com/media/FIQoxVGWYAsOEA2.png)
![Damien Van Robaeys [MVP] tweet media](https://pbs.twimg.com/media/FIQozs0XEAE6s_P.png)
English
Philip K retweetledi

Evolving Autopilot Manager
...learn about the latest enhancements and how you might benefit from it.
#MSIntune #WindowsAutopilot #Autopilot #Microsoft #MEM #AutopilotManager #Windows
oliverkieselbach.com/2021/12/21/evo…
English






