107 questions with Microsoft Defender for Cloud Apps-related tags

Sort by: Updated
1 answer

How to export payload domains and sender addresses from Attack simulation portal from M365 security defender? Is there way to get all those domains and sender addresses so that we can use for attack simulations based on our choice?

How to export payload domains and sender addresses from Attack simulation portal from M365 security defender? Is there way to get all those domains and sender addresses so that we can use for attack simulations based on our choice and know that its the…

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
3,938 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,212 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-05-05T17:13:40.5433333+00:00
Vinod Survase 4,706 Reputation points
commented 2024-03-07T10:18:34.8133333+00:00
Vinod Survase 4,706 Reputation points
1 answer One of the answers was accepted by the question author.

Defender for Endpoint blocking reddit

I added Reddit.com to my whitelist and can sort of go to Reddit. Windows notification is listing a couple sites it says it can't get to. Is there a way to setup one rule that will cover all sub-domains and such like doing reddit.com/* or such (which…

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
3,938 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,212 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2024-02-28T19:43:33.9966667+00:00
Jon Mercer 971 Reputation points
edited a comment 2024-03-06T07:09:29.99+00:00
Oleksandr Romaniuk 465 Reputation points
1 answer

Defender for Endpoint bios in the wrong place

BIOS update information should flow under Weakness node, but I still have them in Recommendations. Is this by disign like this? Empty: Reference:…

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
349 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,463 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2024-03-01T09:43:59.57+00:00
Pavel yannara Mirochnitchenko 11,961 Reputation points MVP
commented 2024-03-04T08:17:11.64+00:00
Crystal-MSFT 44,321 Reputation points Microsoft Vendor
1 answer

Using KQL in Microsoft Defender to Query files on user computers

Hello, can anyone help me with querying all computers (Windows 10 and 11) in our organization to find the location of files with a specific extension *.ref using KQL in Advanced Hunting? Is it possible to base this query on the Organizational Unit (OU)…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,212 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2024-02-19T13:58:57.79+00:00
APTOS 221 Reputation points
commented 2024-03-01T08:10:59.6833333+00:00
Givary-MSFT 28,571 Reputation points Microsoft Employee
1 answer

Anomalous Token alert of Defender

Hi all, We used to receive an Anomalous token alert on Defender, and it stopped all of a sudden. Unable to see any policy associated with it. Please help to figure it out.

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,212 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,806 questions
asked 2024-02-27T23:38:07.87+00:00
Suraj Rimal 0 Reputation points
edited the question 2024-02-28T19:48:33.9033333+00:00
JamesTran-MSFT 36,476 Reputation points Microsoft Employee
0 answers

WebDAV accessed files have error opening

we have a nextcloud server, self-hosted and when we go to open a microsoft document on the webdav networked drive it gets : "Microsoft Office has blocked access to "https:XYZ..." because the source uses a sign-in method that may be…

Office
Office
A suite of Microsoft productivity software that supports common business tasks, including word processing, email, presentations, and data management and analysis.
1,349 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2024-02-27T22:46:34.5933333+00:00
Adam Graves 0 Reputation points
0 answers

files are not scanned that uploaded on teams connected site

files are not scanned that uploaded on teams connected site

Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2024-02-26T14:53:07.0033333+00:00
O365 Buddy 71 Reputation points
0 answers

API Advanced Hunting IdentityLogonEvents error

Hi everyone, I'm trying to get the Identitylogonevents result from the API, and I get a forbidden error message, I gave all rights, read all Microsoft documentation and article I found nothing. i have test all this API : #$url =…

Microsoft Identity Manager
Microsoft Identity Manager
A family of Microsoft products that manage a user's digital identity using identity synchronization, certificate management, and user provisioning.
625 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-05-02T13:29:07.31+00:00
mehdi dakhama 336 Reputation points MVP
commented 2024-02-22T09:27:19.62+00:00
Fiona Matu 86 Reputation points Microsoft Employee
0 answers

Windows Defender MpCmdRun.exe Custom Scan Automation Job Failing intermittently in Production Environment using TeamCity Tool

Hello Microsoft Community, We are currently facing an issue with our TeamCity build automation, specifically related to the custom virus scan using the MpCmdRun.exe command-line utility. Our setup involves executing the command: MpCmdRun.exe -Scan…

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,501 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,263 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,212 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2024-02-05T02:04:28.9966667+00:00
Vamshi Krishna 0 Reputation points
commented 2024-02-21T11:51:39.01+00:00
Givary-MSFT 28,571 Reputation points Microsoft Employee
1 answer

office 365 identity - diff user and workstation AD

Dear All, We have customer would has below requirement, 1- user would be synced from Forest A to O365 2- Forest B would contain the same user A and workstation would be joined to Forest B 3- Identity in Forest A and Forest B would be synced for password…

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
3,938 questions
Microsoft Identity Manager
Microsoft Identity Manager
A family of Microsoft products that manage a user's digital identity using identity synchronization, certificate management, and user provisioning.
625 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2024-01-31T22:30:50.2766667+00:00
Hasan Reza 161 Reputation points
answered 2024-02-20T11:23:17.43+00:00
Catherine Kyalo 650 Reputation points Microsoft Employee
0 answers

Unable to receive incidents with status `redirected` using Outh2.0

I am using [https://graph.microsoft.com/v1.0/security/incidents](https://graph.microsoft.com/v1.0/security/incidents%60) API to fetch all the incidents. To access this API, I am using two types of tokens. Basic Auth: By providing client_id and…

Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2024-02-14T12:02:57.8566667+00:00
Herman Edwards 6 Reputation points
edited the question 2024-02-15T05:42:40.03+00:00
Herman Edwards 6 Reputation points
0 answers

Avoid upload/download big file in Dropbox (PC)?

Hi, I would like to know if using Defender for Cloud Apps (MCAS) it is possible to avoid uploading or downloading a 10 Gb file to Dropbox Enterprise. Dropbox desktop app or web app are possible. I checked during a lot of time in the web (including…

Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-03-10T16:58:03.0333333+00:00
Rodriguez, Antonio 25 Reputation points
commented 2024-02-14T13:50:41.07+00:00
Catherine Kyalo 650 Reputation points Microsoft Employee
1 answer

Compliance configuration for Teams on mobile

Hello all Wanted to double check something : I am about to edit a handful of setting in Microsoft defender , all related to link and attachment sharing This wave of updates are focusing on the enforcement of new rules for security and compliance on…

Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-06-12T19:58:57.27+00:00
Juan Manuel de oliveira Bestagno 0 Reputation points
answered 2024-02-14T10:15:48.6466667+00:00
Fiona Matu 86 Reputation points Microsoft Employee
1 answer

How do i allow my organisation access to the Microsoft store?

I'm trying to access add-ins within Powerpoint App but keep getting an error that my organisation hasnt allowed access. I am the administrator of the account, we have a non-profit account (work or school). Any advice on how to allow to the store for…

Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-03-06T15:44:41.04+00:00
Luke Capon 0 Reputation points
answered 2024-02-13T08:46:38.5233333+00:00
Fiona Matu 86 Reputation points Microsoft Employee
1 answer

Reviewing the Quarantine for a Mail-Enabled Public Folder

Our organization used mostly Public Folders rather than Shared Mailboxes. A number of these Public Folders are mail-enabled and have an email address assigned to them. We also use Microsoft Defender (security.microsoft.com/quarantine) for our email…

Microsoft Exchange Online
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-03-29T18:27:11.6333333+00:00
Adam 5 Reputation points
answered 2024-02-13T08:06:46.9566667+00:00
Catherine Kyalo 650 Reputation points Microsoft Employee
1 answer

Removed the unwanted app but still showing in MDE portal

Hi Community, Hope all are doing well!! am facing an issue, i saw WhatsApp application in MDE software inventory which was installed in one PC and later we uninstalled it from the PC but it is still showing in inventory under MDE portal don't know…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,212 questions
Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
349 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2024-02-08T07:02:19.6033333+00:00
Prince Chauhan 0 Reputation points
edited an answer 2024-02-09T01:18:10.7966667+00:00
Crystal-MSFT 44,321 Reputation points Microsoft Vendor
1 answer

Is there a way to configure Microsoft Defender to send an alert whenever its settings are altered?

Is there a way to configure Microsoft Defender to send an alert whenever its settings are altered?

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,212 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2024-02-05T18:51:30.3966667+00:00
Rosedose 0 Reputation points
commented 2024-02-08T23:29:23.56+00:00
JamesTran-MSFT 36,476 Reputation points Microsoft Employee
1 answer

E3 vs E5 from a security perspective: Unified XDR/SIEM

Hi, A customer with E5 wants to downgrade to E3. Currently, he has XDR services (All Defenders) and Sentinel. Will he lose any services during the downgrade process?

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,212 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,000 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
159 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2024-01-30T19:46:09.0366667+00:00
Riadh Zehani 125 Reputation points
commented 2024-02-01T06:54:24.3433333+00:00
Akshay-MSFT 16,436 Reputation points Microsoft Employee
1 answer

What is the difference between Microsoft Defender for Cloud difference Microsoft Defender for Cloud Apps?

What is the difference between Microsoft Defender for Cloud difference Microsoft Defender for Cloud Apps?

Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-05-22T07:44:28.3733333+00:00
Robert Maraan 0 Reputation points
answered 2024-01-30T08:15:37.41+00:00
Catherine Kyalo 650 Reputation points Microsoft Employee
1 answer

Microsoft Defender for Endpoint

Hi team , I am trying to roll out a feature just for a certain group of devices but when i tried to create a Device Groups i went to settings > Endpoints > Permissions > Device Groups i can 't see permission option when in endpoint. I am…

Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
107 questions
asked 2023-09-29T22:42:09.47+00:00
J-3804 1,516 Reputation points
edited an answer 2024-01-30T08:02:21.88+00:00
Catherine Kyalo 650 Reputation points Microsoft Employee