Anything About IT

Learning, Building, Sharing

Collecting AzureAD User Authentication Method Information

Collect Azure AD user authentication methods using Microsoft Graph PowerShell for MFA and passwordless analysis.

Generating Advanced hunting queries with PowerShell

Writing advanced hunting queries for Microsoft Defender ATP to search for execution of specific PowerShell commands.

User Spam & Phish Submissions configuration in Office 365 – Part 1

A new feature being rolled out in Office 365 to configure user submissions.

PowerShell 7 – Group Policy Settings and Eventlogs

On December 16th Joey announced the PowerShell 7.0 release candidate. PowerShell 7 comes with Group Policy Settings and Eventlogs.

How to identify orphan Group Policy content within the Sysvol folder

Today I was working on a Microsoft Security Configuration baseline implementation and browsing through the Sysvol folder for orphan GPO content.

Microsoft Defender ATP Advanced Hunting – Who's logging on with local admin rights?

Use KQL Advanced Hunting in Microsoft Defender ATP to find out who is logging on with local administrator rights.