163 questions with Microsoft Defender for Identity-related tags

Sort by: Updated
0 answers

How to get the impacted asset (user or client) when fetching alerts (v2) from Defender using API?

Hello, I followed this documentation to list alerts from Defender https://learn.microsoft.com/en-us/graph/api/security-list-alerts_v2?view=graph-rest-beta&tabs=http While I am getting the output, it is very different from when I fetch the alerts…

Microsoft Graph
Microsoft Graph
A Microsoft programmability model that exposes REST APIs and client libraries to access data on Microsoft 365 services.
10,911 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,228 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
163 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
113 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
22 questions
asked 2024-05-30T13:30:38.1333333+00:00
Rawad BASSIL 0 Reputation points
2 answers

A Microsoft Intune license was not found

I'm trying to enable defender for endpoint and I'm getting this error. I already have E3 license assigned to me. How to fix this?

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
163 questions
asked 2023-08-16T15:30:08.98+00:00
Rishineken Pongen 166 Reputation points
commented 2024-05-29T19:09:54.4633333+00:00
Hamed, Ali 0 Reputation points
1 answer

Microsoft 365 Defender - How to get more meaningful email alerting?

How can I get more meaningful email alerts using the Microsoft 365 Defender? Because every time I get the email alert, the email is not as informative like the below: Microsoft 365 Defender has detected a security threat in your environment View incident…

Microsoft Graph
Microsoft Graph
A Microsoft programmability model that exposes REST APIs and client libraries to access data on Microsoft 365 services.
10,911 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,228 questions
PowerShell
PowerShell
A family of Microsoft task automation and configuration management frameworks consisting of a command-line shell and associated scripting language.
2,185 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
163 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,947 questions
asked 2024-05-27T13:00:44.4566667+00:00
EnterpriseArchitect 4,896 Reputation points
answered 2024-05-28T15:31:10.0266667+00:00
Rich Matheisen 45,186 Reputation points
0 answers

Please allow subscriptions on new Alerts API (/alerts_v2)

Hi, To automate the remediation of high-level alerts, we have set up Powerautomate flows for : revoke sessions and block a user concerned by a High alert in cases of phishings or abnormal connections (UserEvidence) isolate workstations in cases of…

Microsoft Graph
Microsoft Graph
A Microsoft programmability model that exposes REST APIs and client libraries to access data on Microsoft 365 services.
10,911 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
163 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
22 questions
asked 2024-05-28T14:04:05.0833333+00:00
Roch AUBURTIN 0 Reputation points
0 answers

Microsoft Endpoint DLP

If I want to Deploy Microsoft Endpoint DLP in my organization? What kind of licenses do I required. I already have Business basic & Business Standard licenses with me will that work?

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
163 questions
asked 2024-05-28T08:38:33.7666667+00:00
Vinod Tembe 0 Reputation points
2 answers

Not allowing to connect Sentinel Data connector with Defender XDR

Hello, I was trying to connect the "Microsoft Defender XDR" connector with "Microsoft Sentinel", but I am facing the below error. I am not sure why Sentinel is not allowing to establish the XDR connector. As I am the Owner of the…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
163 questions
asked 2024-05-08T12:07:43.2433333+00:00
Karan Bhatt 27 Reputation points
commented 2024-05-22T21:39:19.9566667+00:00
James Hamil 22,436 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

No License Found - Microsoft Defender

Hi there, I am seeing the following message when opening Microsoft Defender on a Mac (deployed via Intune). We do have Defender license assigned to user via Business Premium. We already have set section 1 set to Windows 10 and 11 in Microsoft Defender…

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,756 questions
Microsoft Intune MacOs
Microsoft Intune MacOs
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.MacOs: A family of Apple operating systems for the Apple Mac line of computers.
72 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
163 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
113 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,947 questions
asked 2024-05-17T15:46:34.9233333+00:00
Anam Ahmed 61 Reputation points
commented 2024-05-22T01:11:00.07+00:00
Xenia-MSFT 315 Reputation points Microsoft Vendor
1 answer

Visual Studio blocked by MS Defender

Microsoft defender blocked visual studio 2022 ( C#) and I can't enter windows forms, console, etc. Please help.

Visual Studio
Visual Studio
A family of Microsoft suites of integrated development tools for building applications for Windows, the web and mobile devices.
4,727 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,228 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
163 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
113 questions
asked 2024-05-18T09:09:30.3366667+00:00
Pepe 0 Reputation points
answered 2024-05-20T07:33:09.3466667+00:00
Anna Xiu-MSFT 26,731 Reputation points Microsoft Vendor
0 answers

Microsoft.Tri.Sensor.Updater.exe Sensor

Hi, How install sensor in DC server. Need to know any troubleshooting steps for Microsoft.Tri.Sensor.Updater.exe sensor if possible share the deep dive document about sensor

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
163 questions
asked 2024-05-15T13:41:37.64+00:00
Balayuvaraj M 51 Reputation points
0 answers

ImpossibleTravelActivity query filtering out "non-interactive sign-ins"

Since Microsoft disabled all useful policies like Impossible travel i created new custom rule. BehaviorInfo   | where ActionType == "ImpossibleTravelActivity" | join BehaviorEntities on BehaviorId So now the issue is that i cannot find how to…

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
163 questions
asked 2024-05-15T08:04:41.3166667+00:00
Trifonov, Vladimir 0 Reputation points
1 answer

Defender for Identity: How to resolve Health Issue "Auditing on the Configuration container is not enabled as required"?

Hi, I have tried to resolve this MDI Health Issue "Auditing on the Configuration container is not enabled as required" for over a week now, but sadly without sucess. I have followed the instructions posted here…

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
163 questions
asked 2024-05-06T15:46:41.1666667+00:00
RobertGrafKlosterer-1076 0 Reputation points
edited an answer 2024-05-15T05:34:15.54+00:00
RobertGrafKlosterer-1076 0 Reputation points
2 answers

Security Recommendations for LAPS are outdated

These recommendations in the Microsoft Secure Score seems to be ignoring the new Windows LAPS and looking at the old LAPS. When we changed over to the Windows LAPS, these recommendations started getting flagged. I thought Microsoft would eventually…

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,881 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,340 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
163 questions
asked 2023-06-28T10:54:09.08+00:00
ADM-Griffin2, Jay 121 Reputation points
answered 2024-05-10T12:25:02.1766667+00:00
Thomas Starkey 0 Reputation points
1 answer

How to secure my network from getting exploit

@Anonymous I have purchased Defender for Endpoint P2 license i want to block hackers to exploit in my network as i dont have firewall installed in my network. Is there any feature in plan 1 or plan 2 which helps in blocking and provide network…

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
163 questions
Microsoft Endpoint Manager Training
Microsoft Endpoint Manager Training
Microsoft Endpoint Manager: A Microsoft endpoint management platform that incorporates System Center Configuration Manager and Intune and provides endpoint security, device management, and intelligent cloud actions.Training: Instruction to develop new skills.
7 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
22 questions
asked 2024-05-06T12:42:01.6933333+00:00
Ravi Sharma 20 Reputation points
commented 2024-05-10T03:57:22.48+00:00
Akshay-MSFT 16,676 Reputation points Microsoft Employee
1 answer

laptop is protected and cant format/reset it

i have an Asus laptop that was joined to domain and also added on Defender , after sometime i disjoined the laptop and now i want to format this laptop but i cant access the USB on it it shows "Access denied" and i have tried to do Reset from…

Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,509 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
163 questions
asked 2024-04-28T14:00:45.4133333+00:00
Van M 0 Reputation points
commented 2024-05-08T02:53:50.53+00:00
Crystal-MSFT 44,506 Reputation points Microsoft Vendor
7 answers

OpenSSL vulnerabilities showing in Defender Dashboard

We have multiple devices showing up with OpenSSL vulnerabilities. It is detecting two dll files that it is flagging. Which they are libssl-3-x64.dll and libcrypto-3-x64.dll. It is flagging this for multiple different applications through out multiple…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,228 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
163 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
113 questions
asked 2023-09-22T20:14:57.2433333+00:00
Jeff Thorne 40 Reputation points
edited an answer 2024-05-04T10:02:05.8366667+00:00
Erik Moreau 406 Reputation points MVP
3 answers

Microsoft Defender Device Inventory Export not downloading.

when we try and do an export we get the error shown. Tried edge and chrome and firefox and cant download it. Is there something i can check to see why it wont download?

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
163 questions
asked 2024-05-02T04:43:37.45+00:00
NP 416 Reputation points
answered 2024-05-03T07:38:31.5433333+00:00
NP 416 Reputation points
1 answer

Can you please provide me the API details for this?

I want to get the Microsoft Message encryption report and Alerts from Microsoft Compliance programatically using API. Manually I do the process in the following way: Message Encryption Report: Link:…

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
3,998 questions
Microsoft Purview
Microsoft Purview
A Microsoft data governance service that helps manage and govern on-premises, multicloud, and software-as-a-service data. Previously known as Azure Purview.
974 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
163 questions
asked 2024-04-30T07:14:56.3566667+00:00
Priyansu Nayak 0 Reputation points
answered 2024-04-30T19:54:34.9666667+00:00
BhargavaGunnam-MSFT 27,976 Reputation points Microsoft Employee
0 answers

How to change incorrect classification of PaladinVPN by Microsoft Defender? How to contact the team by email?

We are writing to bring to your attention a matter regarding the classification of PaladinVPN by Microsoft Defender. We have noticed that PaladinVPN has been classified in a manner that we believe to be incorrect. The details of this classification can…

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
3,998 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
163 questions
asked 2024-04-24T14:02:49.81+00:00
PaladinVPN Team 0 Reputation points
0 answers

odbc oledb Vulnerability fix in Microsoft defender for endpoint.

We have Win 10 devices onboarded in Defender for endpoint. There are vulnerabilities showing up for for ODBC and OLE DB. We installed version Microsoft OLE DB Driver 18.6.6 and Microsoft OLE DB Driver 18.6.6 still these are reflecting in the…

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
163 questions
asked 2024-03-28T14:51:08.1966667+00:00
Ajaz Khan 266 Reputation points
commented 2024-04-20T09:28:13.6066667+00:00
Mahesh Goud Juvvadi 910 Reputation points Microsoft Vendor
5 answers

Translation dosen't work in Microsoft 365 (Document Translation Failed .Please Try again)

Hello , When i try to translate a word document i get the message Bellow : My Office version is : we used E5 licences and the windows version is windows 11 23H2 I have tried many things but still encounter the error up to now. I attempted to…

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
3,998 questions
Word
Word
A family of Microsoft word processing software products for creating web, email, and print documents.
700 questions
Microsoft Office Online Server
Microsoft Office Online Server
Microsoft on-premises server product that runs Office Online. Previously known as Office Web Apps Server.
599 questions
Outlook
Outlook
A family of Microsoft email and calendar products.
3,142 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
163 questions
asked 2023-12-20T15:58:09.3233333+00:00
APTOS 221 Reputation points
commented 2024-04-18T15:48:37.6333333+00:00
Amit Cohen 0 Reputation points