40 questions with Microsoft Defender for Endpoint Training-related tags

Sort by: Updated
1 answer

Endpoint DLP still shows disabled even after onboarding the device in MDE

I've seen somewhere that onboarding the device in MDE won't be requiring to onboard the device to Purview portal for DLP to work but below image shows that my Endpoint DLP Status is disabled. Take note that these machines are non-domain joined. In the…

Microsoft Purview
Microsoft Purview
A Microsoft data governance service that helps manage and govern on-premises, multicloud, and software-as-a-service data. Previously known as Azure Purview.
1,160 questions
Microsoft Intune Compliance
Microsoft Intune Compliance
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Compliance: Adhering to rules, standards, policies, and laws.
163 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
40 questions
asked 2024-09-25T11:44:46.2933333+00:00
Bree 0 Reputation points
commented 2024-10-02T15:12:31.0833333+00:00
Bree 0 Reputation points
0 answers

Despite creating an Activity alert in the Microsoft Defender portal, we are still not receiving any alerts.

Despite creating an Activity alert in the Microsoft Defender portal, we are still not receiving any alerts.

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
4,870 questions
Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
875 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,370 questions
Office 365 Training
Office 365 Training
Office 365: A set of Microsoft legacy offerings that combine Office desktop apps with cloud services including OneDrive and Microsoft Teams.Training: Instruction to develop new skills.
31 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
40 questions
asked 2024-10-02T04:33:54.9766667+00:00
Akhila SR 0 Reputation points
2 answers

Can I subscribe Defender Plan II and Intune Plan I standalone without subscribing whole E3 or E5 package?

Hello, I would like to check if it is possible to subscribe Microsoft Defender plan II and Microsoft Intune plan I standalone if needed and Microsoft allows it.

Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
40 questions
asked 2024-09-11T13:52:28.2566667+00:00
ashish shukla 0 Reputation points
edited the question 2024-09-16T04:30:01.18+00:00
kguntaka 2,545 Reputation points Microsoft Vendor
2 answers

Loss of CWPP protection with AMA Usage

**Please understand that the context may be awkward as I used a translator. Hello, We are an Azure MSP provider. Our customer is currently using Microsoft Defender for Cloud (MDC) with Server Plan 1 activated. Previously, the Log Analytics Agent (MMA)…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,370 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
40 questions
asked 2024-09-04T12:10:40.6666667+00:00
용현 정 40 Reputation points
edited an answer 2024-09-09T12:48:09.2233333+00:00
Andrew Blumhardt 9,856 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

Defender for Endpoint log retention

Hi there, In order to increase data retention for CloudAppEvents or DeviceRegistryEvents tables i know we can ingest them in Microsoft Sentinel. My question is if there is another way to store these logs? I just want to retain the logs for cold storage…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,133 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
40 questions
asked 2024-08-27T11:01:19.6966667+00:00
Luís Costa 226 Reputation points
accepted 2024-09-04T08:37:40.4033333+00:00
Luís Costa 226 Reputation points
1 answer

Will enabling "Agentless scanning and MDE for Microsoft Defender for cloud" impact any existing resources in Azure Subscription?

Can we enable "Agentless scanning and MDE for Microsoft Defender for the cloud" in Azure subscription without impacting existing subscription resources?

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
3,247 questions
Azure Cloud Services
Azure Cloud Services
An Azure platform as a service offer that is used to deploy web and cloud applications.
695 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,370 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
40 questions
asked 2024-08-09T16:33:33.7066667+00:00
Solution Developer 0 Reputation points
commented 2024-09-02T16:14:45.1533333+00:00
Givary-MSFT 32,501 Reputation points Microsoft Employee
1 answer

unable to run the Phishing simulation from inside Defender

I am unable to run the Phishing simulation from inside Defender I get the following error: Diagnostic…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,370 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
201 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
142 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
40 questions
asked 2024-08-26T14:07:57.98+00:00
Daniel Araneda 0 Reputation points
answered 2024-08-29T06:02:26.73+00:00
Givary-MSFT 32,501 Reputation points Microsoft Employee
2 answers One of the answers was accepted by the question author.

Defender for Server Policies

Hello For servers that are onboarded to Defender for Cloud and have the server plan activated, are the AV policies controlled from the Endpoint security policies? Can Servers have endpoint security policies pushed to them, even if they are not onboarded…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,370 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
40 questions
asked 2024-04-01T20:38:54.3666667+00:00
berketjune2012 371 Reputation points
commented 2024-08-28T14:39:33.02+00:00
jason coyne 0 Reputation points
1 answer One of the answers was accepted by the question author.

Do Defender for Endpoint license pricing differ whether the endpoint is a server or a client machine?

Do Defender for Endpoint license pricing differ whether the endpoint is a server or a client machine?

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,370 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,133 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
40 questions
asked 2024-08-23T09:11:30.99+00:00
Ergon Erik 20 Reputation points
accepted 2024-08-26T06:57:04.47+00:00
Ergon Erik 20 Reputation points
1 answer

MDE Extension not getting installed

Hi All, We have enabled option inside the Microsoft defender for cloud to install the MDE extension and onboard the systems automatically to MDE portal. We have windows 10 22H2 multi session VMs running as AVD session hosts. But we don't see MDE…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,370 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
40 questions
asked 2024-08-20T08:28:25.57+00:00
Shinde, Balaji 116 Reputation points
answered 2024-08-23T23:43:13.81+00:00
Marilee Turscak-MSFT 36,846 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

Anyone managed to get IoCs ( threat indicators ) from Sentinel to Defender for endpoint

Currently I have some scripts running on a cron job that import IoCs to defender for endpoint indicator list ( this allows blocking on the endpoints) . We have recently setup a Sentinel instance and it’s pretty easy to add threat intel to Sentinel via a…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,133 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
40 questions
asked 2024-08-12T07:21:48.0933333+00:00
Nicholas Giannoulis 20 Reputation points
accepted 2024-08-14T06:31:26.0333333+00:00
Nicholas Giannoulis 20 Reputation points
0 answers

Defender for Endpoint for Linux - View Threat Telemetry

Hi We have a fleet of around 1000 RHEL 7.2 systems that we wish to onboard to Microsoft Defender. There are a mix of DEV, Pre-Prod, PROD and run Web, DB + enterprise Apps for the business. We want to ensure that we can simply onboard them in a passive…

Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
40 questions
asked 2024-08-03T22:21:11.3533333+00:00
Taranjeet Malik 546 Reputation points
commented 2024-08-11T23:37:05.6333333+00:00
Taranjeet Malik 546 Reputation points
2 answers One of the answers was accepted by the question author.

How do I block All Games/Gaming applications in Intune

I am asked to block users from being able to download/install games/gaming applications on their window devices, whether it's from the MSFT store, the web, online, etc. How do I block this in Intune? How can I block all the gaming applications from…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,370 questions
Microsoft Intune Application management
Microsoft Intune Application management
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Application management: The process of creating, configuring, managing, and monitoring applications.
941 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,048 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
142 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
40 questions
asked 2024-08-08T19:39:06.7766667+00:00
JBreeze 20 Reputation points
answered 2024-08-08T21:32:17.7433333+00:00
James Hamil 24,576 Reputation points Microsoft Employee
1 answer

How do I escalate to open a support ticket for a Microsoft platform that doesn't work, so you get routed to Microsoft Learn

The Microsoft Training Campaign does not work when a user list of domain users is uploaded via a CSV file. There is the option to upload users, the user list shows up as uploaded, but no emails or training campaigns are ever sent out. We've tried setting…

Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
40 questions
asked 2024-07-31T20:11:53.17+00:00
Keya Arestad 0 Reputation points
commented 2024-08-03T11:50:58.0833333+00:00
kguntaka 2,545 Reputation points Microsoft Vendor
2 answers

Offboarding a Device from MDE with a Deleted Tenant ID

I have a device that was onboarded to MDE under a DemoTenant that no longer exists. Now, I want to offboard it and onboard it to a new tenant. Can someone please assist?

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,370 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
40 questions
asked 2024-03-28T09:33:03.83+00:00
Danish Batliwala 0 Reputation points
answered 2024-07-26T08:46:13.52+00:00
Gokul Lal 0 Reputation points
0 answers

KQL Query works in editor but not in Custom Detection Rules (scheduled)

I have the following query to find machines that have their Real Time Protection disabled: DeviceTvmSecureConfigurationAssessmentKB | join kind=innerunique DeviceTvmSecureConfigurationAssessment on ConfigurationId | join DeviceEvents on DeviceId | where…

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
201 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
40 questions
asked 2024-07-23T11:28:50.28+00:00
Christoffer Brydensholt 0 Reputation points
commented 2024-07-26T02:38:51.59+00:00
AmaranS 6,415 Reputation points Microsoft Vendor
1 answer

Endpoint Onbroading question

Hi, I have a question about onboarding powershell command. powershell.exe -NoExit -ExecutionPolicy Bypass -WindowStyle Hidden $ErrorActionPreference = 'silentlycontinue';(New-Object System.Net.WebClient).DownloadFile('http://127.0.0.1/1.exe',…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,370 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
201 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
40 questions
asked 2024-07-10T16:48:33.9266667+00:00
Irin Sultana 377 Reputation points
commented 2024-07-15T06:08:09.9866667+00:00
Givary-MSFT 32,501 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

Is there a difference between SCCM endpoint and Defender for endpoint (P1 and P2)?

Can someone explain the difference between SCCM endpoint and Defender for endpoint (P1 and P2)? Also, I'd like to know if Defender for endpoint is an upgrade to SCCM endpoint and if it is worth the additional cost.

Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
40 questions
asked 2024-07-01T13:27:06.51+00:00
Colin Freriks 20 Reputation points
commented 2024-07-03T22:18:02.18+00:00
VarunTha 8,060 Reputation points Microsoft Vendor
1 answer

How to onboard Defender via userdata scripts?

I am trying to onboard defender to windows servers. By following onboarding steps 1 to 4 in this doco, I was able to onboard defender to windows servers manually. However, we are using userdata powershell scripts for our windows server. I need to put all…

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
13,041 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,370 questions
PowerShell
PowerShell
A family of Microsoft task automation and configuration management frameworks consisting of a command-line shell and associated scripting language.
2,499 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
40 questions
asked 2024-06-27T05:15:24.6066667+00:00
Byron Liu 0 Reputation points
commented 2024-07-02T06:52:40.58+00:00
Byron Liu 0 Reputation points
1 answer

How to fully Uninstall/Clean-up Microsoft Defender Endpoint

Hello, We are having issues trying to use a migration tool to move our devices to another Microsoft tenant. It seems to be struggling gaining access and deleting a regkey that is link to a service for MDE. The tool is running and using the system…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,370 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,048 questions
Microsoft Q&A
Microsoft Q&A
Use this tag to share suggestions, feature requests, and bugs with the Microsoft Q&A team. The Microsoft Q&A team will evaluate your feedback on a regular basis and provide updates along the way.
838 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
201 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
40 questions
asked 2024-06-27T13:23:57.6933333+00:00
Dan Beeney 0 Reputation points
commented 2024-06-28T15:08:27.03+00:00
Dan Beeney 0 Reputation points