Anything About IT

Learning, Building, Sharing

Collect Microsoft Entra Connect Sync Audit Events

How to forward Microsoft Entra Connect Sync admin audit events to Microsoft Sentinel using AMA and Windows Security Events via AMA.

Monitoring Windows built-in local security Groups with Microsoft Defender XDR or Sentinel

Detect and monitor local security group changes using Microsoft Defender XDR and Microsoft Sentinel.

How to analyze Microsoft Sentinel Daily Cap Alerts - AADNonInteractiveUserSignInLogs

How to investigate Microsoft Sentinel daily cap alerts and identify high-volume AADNonInteractiveUserSignInLogs contributors.