Posts

Showing posts with the label MDE

Microsoft Defender Live Response - The last line of defence!

Image
Ever been in a situation when the state of the device is so bad, so unusable that it feels like you have exhausted all options and there is no hope? I think it is safe to say that most of us in the world of endpoint management, would have such days at some point in our lives. I recently delt with a device that was in a deadlock state. To give some more context, here is a snapshot of what I was dealing with - 1. The device reset had failed from Microsoft Intune and as part of the process was also deleted from the admin portal. 2. To make matters worse, the device object was deleted from Entra ID as well. (Don't ask why, it's just the way it is.:-) ). 3. The enrolled user had standard permissions and in order to elevate the permissions, one would need either a GA role or LAPS. While LAPS was configured, due to step 2, there was no way to retrieve the password, even through Graph. 4. GA wouldn't work as well as the device had lost trust with Entra ID. 5. Even if you rebooted i...

Microsoft Purview DLP Domain Restrictions for macOS

Image
While scoping for a project for a customer involving the features of Microsoft Purview for Windows devices, it got me thinking about other OS platforms like macOS and what all Purview had to offer. As it turns out, there is a lot. From real-time file inspection across different file types & classification to robust policy protection controls, Microsoft Purview DLP offers a rich set of capabilities.  As of writing this blog, here is a complete list of features supported on macOS. Source: Microsoft Once devices are onboarded into the Microsoft Purview solutions, the information about what users are doing with sensitive items is made visible in the Purview portal. There is a bit involved in getting the macOS devices onboarded and creating policies in Purview, so let's get started. What are the pre-requisites? 1. If you are using Intune, then make sure the device is enrolled in Intune. 2. Device is onboarded to Microsoft Defender for Endpoint with a minimum version of 101.95.07.x 3...

Behavior Monitoring in Defender for Endpoint for macOS - Let's see what's it all about..

Image
Microsoft recently released a capability within Microsoft Defender for Endpoint which improves the early detection and prevention of suspicious and malicious activities targeting  macOS users. I participated in early private previews and I was really impressed by its level of real-time monitoring and detection capabilities. According to Microsoft -  "Behavior monitoring observes how software behaves in real-time to detect and analyze potential threats based on the behavior of the applications, daemons, and files within your system. Behavior monitoring is a cornerstone of Microsoft Defender’s cloud-based protection strategy." BM is being gradually rolled out, but once fully deployed, customers will benefit from this cloud-based protection within Microsoft Defender for Endpoint.  As of writing this blog, there are of course some prerequisites that organizations will need to consider - 1. The device must be onboarded to Microsoft Defender for Endpoint. 2. Preview features mu...