Anything About IT

Learning, Building, Sharing

Exploring IdentityAccountInfo - Building a KQL Query to Assess Identity Password Security Posture

Use IdentityAccountInfo and IdentityInfo in Defender XDR to assess password hygiene, account sensitivity, and risky password policy settings.

Defender for Identity - Automatic Windows Event Auditing Configuration

How to enable and validate Microsoft Defender for Identity Automatic Windows Event Auditing Configuration and troubleshoot common conflicts.

Collect Microsoft Entra Connect Sync Audit Events

How to forward Microsoft Entra Connect Sync admin audit events to Microsoft Sentinel using AMA and Windows Security Events via AMA.

Shedding Light on Dormant Sensitive Accounts

Use Microsoft Defender XDR and KQL to enrich dormant sensitive account findings and add missing account context for remediation.

Microsoft Defender for Endpoint - Security Settings Management Internals 0x1

A technical walkthrough of how Defender for Endpoint Security Settings Management works internally on Windows Server, including Entra device objects and dynamic group targeting.

Assessment and Control of Browser Extensions

How to assess, hunt, and control browser extensions with Microsoft Defender for Endpoint and policy controls.