Anything About IT

Learning, Building, Sharing

Testing Windows Defender MAPS Connectivity with PowerShell

Whenever I work with customers on Windows Defender, one of the first things I review is the MAPS (Microsoft Active Protection Service) connectivity.

The case of Running the Device and Credential Guard Hardware Readiness Tool and unknown architecture

My findings about running the Windows Device and Credential Guard Hardware Readiness Tool and the unknown architecture error.

Managing Role Based Access (RBAC) for Microsoft Defender Advanced Threat Protection

How to manage Role Based Access Control (RBAC) for Microsoft Defender Advanced Threat Protection.

Exploring Microsoft Cloud App Security with PowerShell – Part1

Last Friday I presented at the Configuration Manager Community Event in Bern. Here is how to explore Microsoft Cloud App Security with PowerShell.

Retrieving Windows Defender Exploit Guard Windows Event logs with PowerShell

Most Windows Defender Exploit Guard features can be enabled in audit or block mode. The impact can be analyzed by looking at Windows Event logs.

How to Configure Splunk to pull Windows Defender ATP alerts

Windows Defender ATP provides SIEM integration, allowing you to pull alerts from Windows Defender ATP Security Center into Splunk.