Microsoft Defender Threat Intelligence: Native Defender Integration and API Access
Previously, Microsoft Defender Threat Intelligence (MDTI) was offered as a separate product and portal experience. Organizations that wanted access to the full Defender TI capabilities required an additional premium license, which could cost tens of thousands of dollars per year...
How to collect Microsoft Defender Client Analyzer Files via MDE Live Response
When troubleshooting Microsoft Defender for Endpoint (MDE) issues, Microsoft Support or internal IT teams often request Defender Client Analyzer logs. Traditionally, collecting these logs requires local access to the endpoint. Using Live Response, you can remotely execute the Microsoft Defender...
Defender for Endpoint performance troubleshooting on Linux
Microsoft Defender for Endpoint (MDE) provides advanced endpoint protection, detection, and response capabilities for Linux systems. While the solution is designed to operate efficiently, administrators may occasionally experience performance issues such as high CPU utilization, excessive memory consumption, increased disk...
Configure AI agent runtime protection (preview) with Microsoft Defender for Endpoint
Artificial Intelligence (AI) agents are becoming part of more and more workflows. From coding assistants and CLI-based agents to autonomous desktop applications, these tools can read files, execute commands, interact with APIs, and perform tasks on behalf of users. This...
Closing the Azure AD Graph Visibility Gap: Why AADGraphActivityLogs is important for Defenders
For years, defenders relied on MicrosoftGraphActivityLogs to monitor Graph API activity in Microsoft Entra ID. However, this visibility was incomplete because the table only captures requests to Microsoft Graph (graph.microsoft.com) and does not include activity against the legacy Azure AD...
Disable alert generation for Unsanctioned Apps in Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps (MDCA) can integrate with Defender for Endpoint (MDE). With the integration, it is possible to get an out-of-the-box cloud app discovery view of the used apps and Shadow IT. When blocking apps via Defender for...
Simplified onboarding of Microsoft Defender for Endpoint using the Defender deployment tool
Rolling out endpoint protection across an organization can sometimes feel more complex than it should be. Microsoft has simplified the onboarding process for Microsoft Defender for Endpoint (MDE) in the past months with deployment packages that make onboarding devices straightforward,...
Automatic migration from Defender for Identity Sensor v2 to v3.x and gMSA changes
Microsoft has enhanced Defender for Identity with the introduction of the new v3.x sensor, designed to simplify onboarding and streamline configuration. This update makes deployment faster and more efficient. Previously, migrating from v2.x to v3.x was a complex process that...
Defending with Microsoft: A Deep Dive into the Microsoft Defender Suite – Blog series intro
it is time for a new blog series. After wrapping up my deep dive into Microsoft Defender for Endpoint, the next logical step was clear; expand the scope and cover the full Microsoft Defender suite. Each product deserves its own...
How to Secure Microsoft Copilot Studio Agents with Real-Time Protection in Defender
AI agents have become powerful tools for organizations to create custom solutions. The risk associated with these agents lies in their integration with internal data and systems. From a security perspective, this represents a shift in the threat landscape and...