Anything About IT

Learning, Building, Sharing

Exploring IdentityAccountInfo - Building a KQL Query to Assess Identity Password Security Posture

Use IdentityAccountInfo and IdentityInfo in Defender XDR to assess password hygiene, account sensitivity, and risky password policy settings.

Modern Security for Legacy Systems

How to deploy and manage Microsoft Defender for Endpoint on Windows 7 and Server 2008 R2, including prerequisites, onboarding, and policy management.

Defender for Identity - Automatic Windows Event Auditing Configuration

How to enable and validate Microsoft Defender for Identity Automatic Windows Event Auditing Configuration and troubleshoot common conflicts.

Collect Microsoft Entra Connect Sync Audit Events

How to forward Microsoft Entra Connect Sync admin audit events to Microsoft Sentinel using AMA and Windows Security Events via AMA.

Shedding Light on Dormant Sensitive Accounts

Use Microsoft Defender XDR and KQL to enrich dormant sensitive account findings and add missing account context for remediation.

Microsoft Defender for Endpoint - Security Settings Management Internals 0x1

A technical walkthrough of how Defender for Endpoint Security Settings Management works internally on Windows Server, including Entra device objects and dynamic group targeting.