Auditing Microsoft Defender and Intune Configuration Changes
Microsoft is clearly moving toward a more unified security operations experience within the Defender portal. Over the last few years, we have seen Microsoft bring more security capabilities together under the Defender platform. Instead of working with completely separate portals...
Microsoft Defender Threat Intelligence: Native Defender Integration and API Access
Previously, Microsoft Defender Threat Intelligence (MDTI) was offered as a separate product and portal experience. Organizations that wanted access to the full Defender TI capabilities required an additional premium license, which could cost tens of thousands of dollars per year...
How to collect Microsoft Defender Client Analyzer Files via MDE Live Response
When troubleshooting Microsoft Defender for Endpoint (MDE) issues, Microsoft Support or internal IT teams often request Defender Client Analyzer logs. Traditionally, collecting these logs requires local access to the endpoint. Using Live Response, you can remotely execute the Microsoft Defender...
Configure AI agent runtime protection (preview) with Microsoft Defender for Endpoint
Artificial Intelligence (AI) agents are becoming part of more and more workflows. From coding assistants and CLI-based agents to autonomous desktop applications, these tools can read files, execute commands, interact with APIs, and perform tasks on behalf of users. This...
Simplified onboarding of Microsoft Defender for Endpoint using the Defender deployment tool
Rolling out endpoint protection across an organization can sometimes feel more complex than it should be. Microsoft has simplified the onboarding process for Microsoft Defender for Endpoint (MDE) in the past months with deployment packages that make onboarding devices straightforward,...
Automatic migration from Defender for Identity Sensor v2 to v3.x and gMSA changes
Microsoft has enhanced Defender for Identity with the introduction of the new v3.x sensor, designed to simplify onboarding and streamline configuration. This update makes deployment faster and more efficient. Previously, migrating from v2.x to v3.x was a complex process that...
Automatic Windows event auditing configuration for Defender for Identity V3.x sensor
Defender for Identity is crucial for capturing events, alerting on MDI threats, and collecting information from on-premises systems through the installed sensor. For environments still running on-premises, ensuring Defender for Identity is running optimally is key for effective attack disruption...
How to natively archive Defender XDR logs for up to 12 years
For years, customers have asked for ways to extend data retention in Microsoft Defender XDR beyond the default limits to support advanced hunting and long-term archiving needs. By default, Defender XDR retains incidents, alerts, and related data for up to...
Microsoft Sentinel Cost Management: How to get insights in data lake usage
Microsoft announced the public preview of Microsoft Sentinel Cost Management at Microsoft Ignite 2025. The new feature brings more in-depth cost visibility into the usage of Sentinel and Sentinel Data Lake. With the release of Microsoft Sentinel data lake, it...
2025 Microsoft Defender Optimization & Configuration Cheat Sheet
With just 2 remaining months in 2025, it is a good idea to check the Microsoft Defender environment and check of new features are correctly configured. In recent months, Microsoft has released numerous new features and security solutions to protect...