229 questions with Microsoft Defender for Identity-related tags

Sort by: Updated
0 answers

AxiosError: Request failed with status code 400

Hi, When we are trying to raise our secure score we encountered this problem: Something went wrong We have encountered an error loading this page, please try again later: AxiosError: Request failed with status code 400 Can someone explain why its having…

Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,874 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,449 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
229 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
158 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
17 questions
asked 2024-12-16T22:13:47.3766667+00:00
Lyle 70 Reputation points
commented 2024-12-27T21:03:49.2966667+00:00
Matt 0 Reputation points
3 answers

Defender for Identity Radius Aad Syncer Disabling User Accounts - Not Sure Why?

We have users randomly getting disabled and the audit logs are showing that Radius Aad Syncer is the culprit. The logs don't offer much more information so I'm not sure how to approach troubleshooting this, but a growing number of users are affected.

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
229 questions
asked 2024-12-17T17:23:47.1333333+00:00
K12SysAdmin 11 Reputation points
answered 2024-12-23T18:55:03.8833333+00:00
K12SysAdmin 11 Reputation points
0 answers

Microsoft Defender Email Collaboration

I want to customize quaratine notification. When user recieve malicous mail ( for example it will be phishing link , malicous attachment, spam mail and etc) , it will go quarantine due policies. Quarantine also sends notification to user, as quarantine…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,449 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
229 questions
asked 2024-12-20T10:46:32.79+00:00
Kanan Ganiyev 0 Reputation points
commented 2024-12-23T06:19:35.6166667+00:00
Kanan Ganiyev 0 Reputation points
3 answers

Package fails to install for Windows 2016 endpoints in Microsoft Defender for Identity

Problem with enroling Windows 2016 devices in Microsoft Defender for Identity As part of moving from a third party AV to defender (2019 and 2022 work fine). PowerShell Running the installation package fails on 2016 for multiple servers All available…

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
229 questions
asked 2024-01-11T17:29:36.0466667+00:00
Arran 0 Reputation points
commented 2024-12-19T06:04:36.7866667+00:00
SpikeNZ 0 Reputation points
0 answers

Can't access Microsoft Secure Score

I get this error when I try to access the Secure score to make improvements I have tried different browsers, credentials are correct, org customization is enabled

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
229 questions
asked 2024-12-17T14:57:49.7+00:00
JKL 0 Reputation points
edited a comment 2024-12-19T01:18:55.8866667+00:00
Alex Zhang-MSFT 3,155 Reputation points Microsoft Vendor
1 answer One of the answers was accepted by the question author.

Vulnerability Alert - Virtual Machine contains an Entra browser cookie of the user account

Hi Team, We received a Defender alert recently telling us that there is a Virtual Machine that contains an Entra browser cookie of a user account, providing lateral movement to a Key Vault. This happened after one of our Admin users logged in to Azure…

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
5,375 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
229 questions
asked 2024-11-26T02:08:44.8433333+00:00
Carl Hansen 40 Reputation points
accepted 2024-12-19T00:24:14.6833333+00:00
Carl Hansen 40 Reputation points
0 answers

how to export scan data and xml report of an asset that has been detected for being vulnerable by MS Defender xdr

Hello ☺️ I am trying to figure out how to generate scan data and XML report of an asset that has been detected for vulnerability for a specific CVE on defender XDR. I am trying to provide this information to the Rapid7 team as the vulnerability report…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,449 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
229 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
158 questions
asked 2024-12-12T12:45:53.3766667+00:00
Saborni Barua 0 Reputation points
edited the question 2024-12-18T06:31:47.4266667+00:00
RNareddy 1,430 Reputation points Microsoft Vendor
1 answer

Role & Permissions

What are the correct roles or permissions to let a user read and edit the email threat policies in Microsoft defender portal? From what I can find it would be Security Administrator. Is there a way to lower this role so it is not as privileged, if no…

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
229 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,665 questions
asked 2024-10-08T20:50:58.76+00:00
Son man 20 Reputation points
edited the question 2024-12-18T06:00:20.3066667+00:00
Rakesh Gurram 10,635 Reputation points Microsoft Vendor
0 answers

how to export scan data and xml report of an asset that has been detected for being vulnerable by MS Defender

Hello I am trying to figure out how to generate scan data and XML report of an asset that has been detected for vulnerability for a specific CVE on defender XDR. I am trying to provide this information to the Rapid7 team as the vulnerability report they…

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
229 questions
asked 2024-12-12T12:51:28.27+00:00
Saborni Barua 0 Reputation points
1 answer

Duplicate SecurityEvent logging after migrating from MMA to AMA

Greetings, I added a few extra tags to this as we are not quite sure of why we cannot Disconnect or Delete the Security Events Via the Legacy Agent Connector from our Sentinel environment. All Azure VMs have been migrated from the MMA (Legacy) agent to…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,449 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,194 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
229 questions
asked 2024-12-06T20:24:41.8566667+00:00
mpls 80 Reputation points
commented 2024-12-11T14:29:11.2466667+00:00
mpls 80 Reputation points
0 answers

Training Assignments not showing

I created an attack simulation training and assigned it to my non-admin user account to test the format and functionality. After receiving the email and clicking the link, it redirected me to the training assignments page. However, no assignments were…

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
229 questions
asked 2024-12-04T10:34:12.05+00:00
Nick Anderson 0 Reputation points
edited the question 2024-12-11T11:43:36.94+00:00
simo-k 1,360 Reputation points
0 answers

Privacy protection VPN option is not visible on my Microsoft defender

Privacy protection VPN option is not visible on my Microsoft defender. Earlier I was used now it's not visible, I have 365 personal plan

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
229 questions
asked 2024-12-10T00:50:54.28+00:00
Thirumal Vellingiri 0 Reputation points
2 answers One of the answers was accepted by the question author.

How to resolve about Sentinel and XDR not connecting properly.

We are currently doing integration testing between Sentinel and XDR. After onboarding and offboarding the workspace from XDR side several times ,following the steps provided in Microsoft's official documentation, encountered the following…

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
5,375 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,194 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
229 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,665 questions
asked 2024-11-23T16:11:42.9666667+00:00
Ryo Suzuki 25 Reputation points
commented 2024-12-09T11:27:50.67+00:00
Ryo Suzuki 25 Reputation points
0 answers

Alerting when break-glass domain admin account has been used by someone

Hi, I have a break-glass domain admin account in several forests whose DCs have MDI sensors installed. Is it possible to get alert/mail notification when that account has been used by someone leveraging MDI events/logs?

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
229 questions
asked 2024-12-08T20:28:49.3066667+00:00
Bojan Zivkovic 486 Reputation points
edited the question 2024-12-08T20:29:19.35+00:00
Bojan Zivkovic 486 Reputation points
0 answers

Troubles Enrolling Server through Microsoft Defender

Hi, I’m working on configuring Hybrid Azure AD Join for our domain-joined devices, and I've already set up Active Directory and Hybrid Azure AD. The next step I’m trying to take is enrolling devices through Microsoft Defender Settings > Endpoints >…

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
229 questions
asked 2024-12-05T17:12:17.0133333+00:00
Kaleb Francoeur 0 Reputation points
1 answer

How to export piechart from MS Defender XDR Advanced Hunting?

Hello everyone, I am trying to export query result as a piechart, but there is no such an option. Do I miss something or is impossible? Thanks! Aleksandar

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
5,375 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,194 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
229 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
158 questions
asked 2024-11-12T09:51:02.8+00:00
Aleksandar Tomov 30 Reputation points
edited the question 2024-12-05T06:07:01.6233333+00:00
Rakesh Gurram 10,635 Reputation points Microsoft Vendor
1 answer One of the answers was accepted by the question author.

The Address you provided is invalid, please provide a valid address and try again!!!

Hi, While I was trying to schedule the SC-200 Exam, I got the error message that the billing address isn't valid. How can I fix this issue. Thanks! Best Regards, Jasmina Jakob

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,449 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,194 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
229 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
158 questions
asked 2024-04-12T19:23:56.8333333+00:00
Anonymous
edited the question 2024-12-04T13:55:23.0733333+00:00
Rakesh Gurram 10,635 Reputation points Microsoft Vendor
0 answers

Hunting: why some quiries is not working like user name, InitiatingProcessCommandLine , user Id and a lot of them thee is redline under it while it is correctly connected with intune and avaliable

example and most of my quries is like this

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,449 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,365 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
229 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
158 questions
asked 2024-06-25T23:26:27.2666667+00:00
Abdelgalil, Mohamed 0 Reputation points
edited the question 2024-12-04T13:49:27.89+00:00
Rakesh Gurram 10,635 Reputation points Microsoft Vendor
1 answer

How to secure my network from getting exploit

@Crystal-MSFT I have purchased Defender for Endpoint P2 license i want to block hackers to exploit in my network as i dont have firewall installed in my network. Is there any feature in plan 1 or plan 2 which helps in blocking and provide network…

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
229 questions
asked 2024-05-06T12:42:01.6933333+00:00
Ravi Kumar Sharma 20 Reputation points
edited the question 2024-12-04T13:44:43.8933333+00:00
Rakesh Gurram 10,635 Reputation points Microsoft Vendor
1 answer

unable to run the Phishing simulation from inside Defender

I am unable to run the Phishing simulation from inside Defender I get the following error: Diagnostic…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,449 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
229 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
158 questions
asked 2024-08-26T14:07:57.98+00:00
Daniel Araneda 0 Reputation points
edited the question 2024-12-04T11:12:32.0433333+00:00
Rakesh Gurram 10,635 Reputation points Microsoft Vendor