How to collect Microsoft Defender Client Analyzer Files via MDE Live Response
When troubleshooting Microsoft Defender for Endpoint (MDE) issues, Microsoft Support or internal IT teams often request Defender Client Analyzer logs. Traditionally, collecting these logs requires local access to the endpoint. Using Live Response, you can remotely execute the Microsoft Defender...
Defender for Endpoint performance troubleshooting on Linux
Microsoft Defender for Endpoint (MDE) provides advanced endpoint protection, detection, and response capabilities for Linux systems. While the solution is designed to operate efficiently, administrators may occasionally experience performance issues such as high CPU utilization, excessive memory consumption, increased disk...
Configure AI agent runtime protection (preview) with Microsoft Defender for Endpoint
Artificial Intelligence (AI) agents are becoming part of more and more workflows. From coding assistants and CLI-based agents to autonomous desktop applications, these tools can read files, execute commands, interact with APIs, and perform tasks on behalf of users. This...
Disable alert generation for Unsanctioned Apps in Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps (MDCA) can integrate with Defender for Endpoint (MDE). With the integration, it is possible to get an out-of-the-box cloud app discovery view of the used apps and Shadow IT. When blocking apps via Defender for...
Simplified onboarding of Microsoft Defender for Endpoint using the Defender deployment tool
Rolling out endpoint protection across an organization can sometimes feel more complex than it should be. Microsoft has simplified the onboarding process for Microsoft Defender for Endpoint (MDE) in the past months with deployment packages that make onboarding devices straightforward,...
Troubleshoot configured Defender AV settings with effective settings in Defender
To ensure Microsoft Defender Antivirus (Defender AV) provides full protection and leverages all its capabilities, it must be configured with the correct antivirus settings. Since Defender AV can be managed through multiple methods, it’s essential to monitor and identify potential...
AiTM/ MFA phishing attacks in combination with “new” Microsoft protections (2026 edition)
Adversary-in-the-middle phishing attacks are still more common in use. In the last year and the start of 2026, there is still a more visible increase in AiTM/ MFA phishing. Since the removal of basic authentication from Exchange Online, more and...
How to store Defender XDR data for years in Sentinel data lake without expensive ingestion cost
In recent years, an increasing number of customers have requested options to extend retention in Microsoft Defender XDR beyond the default 30 days at a low cost, all with the requirement of having the KQL experience available. Blog information: Feature is...
Configure automatic Attack Disruption in Microsoft Defender XDR
Microsoft Defender XDR includes a powerful response capability with the name Attack Disruption. As part of the Defender XDR solution attack disruption capabilities can protect the environment against sophisticated, high-impact attacks. Attack Disruption works automatically; however, it still needs manual...
Common mistakes during Microsoft Defender for Endpoint deployments
Microsoft Defender for Endpoint (MDE) is part of Microsoft Defender XDR and can be deployed via multiple configurations. During my experience with the product, I deployed/ reviewed and evaluated many Defender for Endpoint instances and configured new instances for many...