#cswrld โ Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cswrld, aggregated by home.social.
-
๐๐จ๐ฐ ๐ญ๐จ ๐๐ซ๐๐๐ญ๐ ๐ ๐๐๐3 ๐๐ข-๐ ๐ข ๐ฉ๐ซ๐จ๐๐ข๐ฅ๐ ๐๐จ๐ซ ๐๐ข๐ง๐๐จ๐ฐ๐ฌ ๐ข๐ง ๐๐ข๐๐ซ๐จ๐ฌ๐จ๐๐ญ ๐๐ง๐ญ๐ฎ๐ง๐
Microsoft Intune still cannot natively create a Wi-Fi profile with WPA3-Personal security at this time. Within the configuration templates, there is only Wi-Fi with WPA/WPA2 security, but WPA3 is missing.
If you have a Wi-Fi where WPA3 is enforced without hybrid mode with WPA2, then if you create a profile as WPA2, the device will not connect to it. So, if you have WPA3 enforced, you need to configure Wi-Fi using a custom profile and OMA-URI.
https://www.cswrld.com/2026/03/how-to-create-a-wpa3-wi-fi-profile-for-windows-in-microsoft-intune/
-
๐๐จ๐ฐ ๐ญ๐จ ๐๐ซ๐๐๐ญ๐ ๐ ๐๐๐3 ๐๐ข-๐ ๐ข ๐ฉ๐ซ๐จ๐๐ข๐ฅ๐ ๐๐จ๐ซ ๐๐ข๐ง๐๐จ๐ฐ๐ฌ ๐ข๐ง ๐๐ข๐๐ซ๐จ๐ฌ๐จ๐๐ญ ๐๐ง๐ญ๐ฎ๐ง๐
Microsoft Intune still cannot natively create a Wi-Fi profile with WPA3-Personal security at this time. Within the configuration templates, there is only Wi-Fi with WPA/WPA2 security, but WPA3 is missing.
If you have a Wi-Fi where WPA3 is enforced without hybrid mode with WPA2, then if you create a profile as WPA2, the device will not connect to it. So, if you have WPA3 enforced, you need to configure Wi-Fi using a custom profile and OMA-URI.
https://www.cswrld.com/2026/03/how-to-create-a-wpa3-wi-fi-profile-for-windows-in-microsoft-intune/
-
๐๐จ๐ฐ ๐ญ๐จ ๐๐ซ๐๐๐ญ๐ ๐ ๐๐๐3 ๐๐ข-๐ ๐ข ๐ฉ๐ซ๐จ๐๐ข๐ฅ๐ ๐๐จ๐ซ ๐๐ข๐ง๐๐จ๐ฐ๐ฌ ๐ข๐ง ๐๐ข๐๐ซ๐จ๐ฌ๐จ๐๐ญ ๐๐ง๐ญ๐ฎ๐ง๐
Microsoft Intune still cannot natively create a Wi-Fi profile with WPA3-Personal security at this time. Within the configuration templates, there is only Wi-Fi with WPA/WPA2 security, but WPA3 is missing.
If you have a Wi-Fi where WPA3 is enforced without hybrid mode with WPA2, then if you create a profile as WPA2, the device will not connect to it. So, if you have WPA3 enforced, you need to configure Wi-Fi using a custom profile and OMA-URI.
https://www.cswrld.com/2026/03/how-to-create-a-wpa3-wi-fi-profile-for-windows-in-microsoft-intune/
-
๐๐จ๐ฐ ๐ญ๐จ ๐๐ซ๐๐๐ญ๐ ๐ ๐๐๐3 ๐๐ข-๐ ๐ข ๐ฉ๐ซ๐จ๐๐ข๐ฅ๐ ๐๐จ๐ซ ๐๐ข๐ง๐๐จ๐ฐ๐ฌ ๐ข๐ง ๐๐ข๐๐ซ๐จ๐ฌ๐จ๐๐ญ ๐๐ง๐ญ๐ฎ๐ง๐
Microsoft Intune still cannot natively create a Wi-Fi profile with WPA3-Personal security at this time. Within the configuration templates, there is only Wi-Fi with WPA/WPA2 security, but WPA3 is missing.
If you have a Wi-Fi where WPA3 is enforced without hybrid mode with WPA2, then if you create a profile as WPA2, the device will not connect to it. So, if you have WPA3 enforced, you need to configure Wi-Fi using a custom profile and OMA-URI.
https://www.cswrld.com/2026/03/how-to-create-a-wpa3-wi-fi-profile-for-windows-in-microsoft-intune/
-
๐๐จ๐ฐ ๐ญ๐จ ๐๐ซ๐๐๐ญ๐ ๐ ๐๐๐3 ๐๐ข-๐ ๐ข ๐ฉ๐ซ๐จ๐๐ข๐ฅ๐ ๐๐จ๐ซ ๐๐ข๐ง๐๐จ๐ฐ๐ฌ ๐ข๐ง ๐๐ข๐๐ซ๐จ๐ฌ๐จ๐๐ญ ๐๐ง๐ญ๐ฎ๐ง๐
Microsoft Intune still cannot natively create a Wi-Fi profile with WPA3-Personal security at this time. Within the configuration templates, there is only Wi-Fi with WPA/WPA2 security, but WPA3 is missing.
If you have a Wi-Fi where WPA3 is enforced without hybrid mode with WPA2, then if you create a profile as WPA2, the device will not connect to it. So, if you have WPA3 enforced, you need to configure Wi-Fi using a custom profile and OMA-URI.
https://www.cswrld.com/2026/03/how-to-create-a-wpa3-wi-fi-profile-for-windows-in-microsoft-intune/
-
๐๐จ๐ฐ ๐๐จ๐ง๐๐ข๐ญ๐ข๐จ๐ง๐๐ฅ ๐๐๐๐๐ฌ๐ฌ ๐๐จ๐ฅ๐ข๐๐ข๐๐ฌ ๐๐ซ๐ ๐๐ฏ๐๐ฅ๐ฎ๐๐ญ๐๐ ๐ข๐ง ๐๐ข๐๐ซ๐จ๐ฌ๐จ๐๐ญ ๐๐ง๐ญ๐ซ๐ ๐๐
Understanding how Conditional Access policies are evaluated in Microsoft Entra ID is absolutely essential if you are involved in their creation or management.
I often encounter fundamental misunderstandings regarding how the evaluation of Conditional Access policies takes place. Many administrators are accustomed to systems like firewalls, where there is an order or priority for evaluating created rules. However, it does not work this way with Conditional Access policies in Microsoft Entra ID. Applying the same principle to Conditional Access policies will very likely lead to significant security risks.
Read my blog post bellow ๐ ๐
https://www.cswrld.com/2026/02/how-conditional-access-policies-are-evaluated-in-microsoft-entra-id/ -
๐๐จ๐ฐ ๐๐จ๐ง๐๐ข๐ญ๐ข๐จ๐ง๐๐ฅ ๐๐๐๐๐ฌ๐ฌ ๐๐จ๐ฅ๐ข๐๐ข๐๐ฌ ๐๐ซ๐ ๐๐ฏ๐๐ฅ๐ฎ๐๐ญ๐๐ ๐ข๐ง ๐๐ข๐๐ซ๐จ๐ฌ๐จ๐๐ญ ๐๐ง๐ญ๐ซ๐ ๐๐
Understanding how Conditional Access policies are evaluated in Microsoft Entra ID is absolutely essential if you are involved in their creation or management.
I often encounter fundamental misunderstandings regarding how the evaluation of Conditional Access policies takes place. Many administrators are accustomed to systems like firewalls, where there is an order or priority for evaluating created rules. However, it does not work this way with Conditional Access policies in Microsoft Entra ID. Applying the same principle to Conditional Access policies will very likely lead to significant security risks.
Read my blog post bellow ๐ ๐
https://www.cswrld.com/2026/02/how-conditional-access-policies-are-evaluated-in-microsoft-entra-id/ -
๐๐จ๐ฐ ๐๐จ๐ง๐๐ข๐ญ๐ข๐จ๐ง๐๐ฅ ๐๐๐๐๐ฌ๐ฌ ๐๐จ๐ฅ๐ข๐๐ข๐๐ฌ ๐๐ซ๐ ๐๐ฏ๐๐ฅ๐ฎ๐๐ญ๐๐ ๐ข๐ง ๐๐ข๐๐ซ๐จ๐ฌ๐จ๐๐ญ ๐๐ง๐ญ๐ซ๐ ๐๐
Understanding how Conditional Access policies are evaluated in Microsoft Entra ID is absolutely essential if you are involved in their creation or management.
I often encounter fundamental misunderstandings regarding how the evaluation of Conditional Access policies takes place. Many administrators are accustomed to systems like firewalls, where there is an order or priority for evaluating created rules. However, it does not work this way with Conditional Access policies in Microsoft Entra ID. Applying the same principle to Conditional Access policies will very likely lead to significant security risks.
Read my blog post bellow ๐ ๐
https://www.cswrld.com/2026/02/how-conditional-access-policies-are-evaluated-in-microsoft-entra-id/ -
๐๐จ๐ฐ ๐๐จ๐ง๐๐ข๐ญ๐ข๐จ๐ง๐๐ฅ ๐๐๐๐๐ฌ๐ฌ ๐๐จ๐ฅ๐ข๐๐ข๐๐ฌ ๐๐ซ๐ ๐๐ฏ๐๐ฅ๐ฎ๐๐ญ๐๐ ๐ข๐ง ๐๐ข๐๐ซ๐จ๐ฌ๐จ๐๐ญ ๐๐ง๐ญ๐ซ๐ ๐๐
Understanding how Conditional Access policies are evaluated in Microsoft Entra ID is absolutely essential if you are involved in their creation or management.
I often encounter fundamental misunderstandings regarding how the evaluation of Conditional Access policies takes place. Many administrators are accustomed to systems like firewalls, where there is an order or priority for evaluating created rules. However, it does not work this way with Conditional Access policies in Microsoft Entra ID. Applying the same principle to Conditional Access policies will very likely lead to significant security risks.
Read my blog post bellow ๐ ๐
https://www.cswrld.com/2026/02/how-conditional-access-policies-are-evaluated-in-microsoft-entra-id/ -
๐๐จ๐ฐ ๐ญ๐จ ๐ฎ๐ฌ๐ ๐๐๐๐๐ฌ๐ฌ ๐ฉ๐๐๐ค๐๐ ๐๐ฌ ๐ญ๐จ ๐ฆ๐๐ง๐๐ ๐ ๐ ๐ซ๐จ๐ฎ๐ฉ ๐ฆ๐๐ฆ๐๐๐ซ๐ฌ๐ก๐ข๐ฉ๐ฌ
Access packages allow you to dynamically manage group, Teams, application, and SharePoint site membership based on user requests.
It works by creating an access package and then publishing it to users โ either all users or a select group of users. Users can then activate the package from the My Access portal after meeting defined conditions.
https://www.cswrld.com/2026/02/how-to-use-access-packages-to-manage-group-memberships/
#cswrld #entraid #entitlementmanagement #identitygovernance #accesspackage
-
๐๐จ๐ฐ ๐ญ๐จ ๐ฎ๐ฌ๐ ๐๐๐๐๐ฌ๐ฌ ๐ฉ๐๐๐ค๐๐ ๐๐ฌ ๐ญ๐จ ๐ฆ๐๐ง๐๐ ๐ ๐ ๐ซ๐จ๐ฎ๐ฉ ๐ฆ๐๐ฆ๐๐๐ซ๐ฌ๐ก๐ข๐ฉ๐ฌ
Access packages allow you to dynamically manage group, Teams, application, and SharePoint site membership based on user requests.
It works by creating an access package and then publishing it to users โ either all users or a select group of users. Users can then activate the package from the My Access portal after meeting defined conditions.
https://www.cswrld.com/2026/02/how-to-use-access-packages-to-manage-group-memberships/
#cswrld #entraid #entitlementmanagement #identitygovernance #accesspackage
-
๐๐จ๐ฐ ๐ญ๐จ ๐ฎ๐ฌ๐ ๐๐๐๐๐ฌ๐ฌ ๐ฉ๐๐๐ค๐๐ ๐๐ฌ ๐ญ๐จ ๐ฆ๐๐ง๐๐ ๐ ๐ ๐ซ๐จ๐ฎ๐ฉ ๐ฆ๐๐ฆ๐๐๐ซ๐ฌ๐ก๐ข๐ฉ๐ฌ
Access packages allow you to dynamically manage group, Teams, application, and SharePoint site membership based on user requests.
It works by creating an access package and then publishing it to users โ either all users or a select group of users. Users can then activate the package from the My Access portal after meeting defined conditions.
https://www.cswrld.com/2026/02/how-to-use-access-packages-to-manage-group-memberships/
#cswrld #entraid #entitlementmanagement #identitygovernance #accesspackage
-
๐๐จ๐ฐ ๐ญ๐จ ๐ฎ๐ฌ๐ ๐๐๐๐๐ฌ๐ฌ ๐ฉ๐๐๐ค๐๐ ๐๐ฌ ๐ญ๐จ ๐ฆ๐๐ง๐๐ ๐ ๐ ๐ซ๐จ๐ฎ๐ฉ ๐ฆ๐๐ฆ๐๐๐ซ๐ฌ๐ก๐ข๐ฉ๐ฌ
Access packages allow you to dynamically manage group, Teams, application, and SharePoint site membership based on user requests.
It works by creating an access package and then publishing it to users โ either all users or a select group of users. Users can then activate the package from the My Access portal after meeting defined conditions.
https://www.cswrld.com/2026/02/how-to-use-access-packages-to-manage-group-memberships/
#cswrld #entraid #entitlementmanagement #identitygovernance #accesspackage
-
๐๐จ๐ฐ ๐ญ๐จ ๐ฎ๐ฌ๐ ๐๐๐๐๐ฌ๐ฌ ๐ฉ๐๐๐ค๐๐ ๐๐ฌ ๐ญ๐จ ๐ฆ๐๐ง๐๐ ๐ ๐ ๐ซ๐จ๐ฎ๐ฉ ๐ฆ๐๐ฆ๐๐๐ซ๐ฌ๐ก๐ข๐ฉ๐ฌ
Access packages allow you to dynamically manage group, Teams, application, and SharePoint site membership based on user requests.
It works by creating an access package and then publishing it to users โ either all users or a select group of users. Users can then activate the package from the My Access portal after meeting defined conditions.
https://www.cswrld.com/2026/02/how-to-use-access-packages-to-manage-group-memberships/
#cswrld #entraid #entitlementmanagement #identitygovernance #accesspackage
-
๐๐จ๐ฐ ๐ญ๐จ ๐ ๐๐ญ ๐ฎ๐ง๐ฅ๐ข๐ฆ๐ข๐ญ๐๐ ๐ฆ๐๐ข๐ฅ๐๐จ๐ฑ ๐ฌ๐ข๐ณ๐ ๐ข๐ง ๐๐ฑ๐๐ก๐๐ง๐ ๐ ๐๐ง๐ฅ๐ข๐ง๐
Exchange Online Plan 1 licenses generally have a primary mailbox capacity of 50 GB. Exchange Online Plan 2 licenses have a capacity of 100 GB. However, this capacity can be extended by using Online Archive. With Exchange Online Plan 2, this capacity is unlimited. Technically speaking, the capacity is limited to 1.5 TB.
An interesting fact is that Microsoft 365 Business Premium licenses, which by default include Exchange Online Plan 1, are also entitled to this feature.
-
๐๐จ๐ฐ ๐ญ๐จ ๐ ๐๐ญ ๐ฎ๐ง๐ฅ๐ข๐ฆ๐ข๐ญ๐๐ ๐ฆ๐๐ข๐ฅ๐๐จ๐ฑ ๐ฌ๐ข๐ณ๐ ๐ข๐ง ๐๐ฑ๐๐ก๐๐ง๐ ๐ ๐๐ง๐ฅ๐ข๐ง๐
Exchange Online Plan 1 licenses generally have a primary mailbox capacity of 50 GB. Exchange Online Plan 2 licenses have a capacity of 100 GB. However, this capacity can be extended by using Online Archive. With Exchange Online Plan 2, this capacity is unlimited. Technically speaking, the capacity is limited to 1.5 TB.
An interesting fact is that Microsoft 365 Business Premium licenses, which by default include Exchange Online Plan 1, are also entitled to this feature.
-
๐๐จ๐ฐ ๐ญ๐จ ๐ ๐๐ญ ๐ฎ๐ง๐ฅ๐ข๐ฆ๐ข๐ญ๐๐ ๐ฆ๐๐ข๐ฅ๐๐จ๐ฑ ๐ฌ๐ข๐ณ๐ ๐ข๐ง ๐๐ฑ๐๐ก๐๐ง๐ ๐ ๐๐ง๐ฅ๐ข๐ง๐
Exchange Online Plan 1 licenses generally have a primary mailbox capacity of 50 GB. Exchange Online Plan 2 licenses have a capacity of 100 GB. However, this capacity can be extended by using Online Archive. With Exchange Online Plan 2, this capacity is unlimited. Technically speaking, the capacity is limited to 1.5 TB.
An interesting fact is that Microsoft 365 Business Premium licenses, which by default include Exchange Online Plan 1, are also entitled to this feature.
-
๐๐จ๐ฐ ๐ญ๐จ ๐ ๐๐ญ ๐ฎ๐ง๐ฅ๐ข๐ฆ๐ข๐ญ๐๐ ๐ฆ๐๐ข๐ฅ๐๐จ๐ฑ ๐ฌ๐ข๐ณ๐ ๐ข๐ง ๐๐ฑ๐๐ก๐๐ง๐ ๐ ๐๐ง๐ฅ๐ข๐ง๐
Exchange Online Plan 1 licenses generally have a primary mailbox capacity of 50 GB. Exchange Online Plan 2 licenses have a capacity of 100 GB. However, this capacity can be extended by using Online Archive. With Exchange Online Plan 2, this capacity is unlimited. Technically speaking, the capacity is limited to 1.5 TB.
An interesting fact is that Microsoft 365 Business Premium licenses, which by default include Exchange Online Plan 1, are also entitled to this feature.
-
๐๐ผ๐ ๐๐ผ ๐ฎ๐๐๐ผ๐บ๐ฎ๐๐ถ๐ฐ๐ฎ๐น๐น๐ ๐๐ฝ๐ฑ๐ฎ๐๐ฒ ๐ฎ๐ฝ๐ฝ๐น๐ถ๐ฐ๐ฎ๐๐ถ๐ผ๐ป๐ ๐ผ๐ป ๐ฐ๐ผ๐บ๐ฝ๐๐๐ฒ๐ฟ๐ ๐ถ๐ป ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐๐ป๐๐๐ป๐ฒ
Microsoft Intune does not have any built-in options for updating installed applications on Windows computers.
If you want to update applications on managed computers, you must manually create a new version of the given application and deploy it to all computers. However, this is quite a lot of manual work, and you also have to monitor the availability of new versions of installed applications, which is another lot of manual work.
Read more in the article on my blog ๐ ๐
https://www.cswrld.com/2025/08/how-to-update-applications-using-patch-my-pc/#cswrld #cybersecurityworld #blog #intune #applicationmanagement #appupdates #patchmypc
-
๐๐ผ๐ ๐๐ผ ๐ฎ๐๐๐ผ๐บ๐ฎ๐๐ถ๐ฐ๐ฎ๐น๐น๐ ๐๐ฝ๐ฑ๐ฎ๐๐ฒ ๐ฎ๐ฝ๐ฝ๐น๐ถ๐ฐ๐ฎ๐๐ถ๐ผ๐ป๐ ๐ผ๐ป ๐ฐ๐ผ๐บ๐ฝ๐๐๐ฒ๐ฟ๐ ๐ถ๐ป ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐๐ป๐๐๐ป๐ฒ
Microsoft Intune does not have any built-in options for updating installed applications on Windows computers.
If you want to update applications on managed computers, you must manually create a new version of the given application and deploy it to all computers. However, this is quite a lot of manual work, and you also have to monitor the availability of new versions of installed applications, which is another lot of manual work.
Read more in the article on my blog ๐ ๐
https://www.cswrld.com/2025/08/how-to-update-applications-using-patch-my-pc/#cswrld #cybersecurityworld #blog #intune #applicationmanagement #appupdates #patchmypc
-
๐๐ผ๐ ๐๐ผ ๐ฎ๐๐๐ผ๐บ๐ฎ๐๐ถ๐ฐ๐ฎ๐น๐น๐ ๐๐ฝ๐ฑ๐ฎ๐๐ฒ ๐ฎ๐ฝ๐ฝ๐น๐ถ๐ฐ๐ฎ๐๐ถ๐ผ๐ป๐ ๐ผ๐ป ๐ฐ๐ผ๐บ๐ฝ๐๐๐ฒ๐ฟ๐ ๐ถ๐ป ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐๐ป๐๐๐ป๐ฒ
Microsoft Intune does not have any built-in options for updating installed applications on Windows computers.
If you want to update applications on managed computers, you must manually create a new version of the given application and deploy it to all computers. However, this is quite a lot of manual work, and you also have to monitor the availability of new versions of installed applications, which is another lot of manual work.
Read more in the article on my blog ๐ ๐
https://www.cswrld.com/2025/08/how-to-update-applications-using-patch-my-pc/#cswrld #cybersecurityworld #blog #intune #applicationmanagement #appupdates #patchmypc
-
๐๐ผ๐ ๐๐ผ ๐ฎ๐๐๐ผ๐บ๐ฎ๐๐ถ๐ฐ๐ฎ๐น๐น๐ ๐๐ฝ๐ฑ๐ฎ๐๐ฒ ๐ฎ๐ฝ๐ฝ๐น๐ถ๐ฐ๐ฎ๐๐ถ๐ผ๐ป๐ ๐ผ๐ป ๐ฐ๐ผ๐บ๐ฝ๐๐๐ฒ๐ฟ๐ ๐ถ๐ป ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐๐ป๐๐๐ป๐ฒ
Microsoft Intune does not have any built-in options for updating installed applications on Windows computers.
If you want to update applications on managed computers, you must manually create a new version of the given application and deploy it to all computers. However, this is quite a lot of manual work, and you also have to monitor the availability of new versions of installed applications, which is another lot of manual work.
Read more in the article on my blog ๐ ๐
https://www.cswrld.com/2025/08/how-to-update-applications-using-patch-my-pc/#cswrld #cybersecurityworld #blog #intune #applicationmanagement #appupdates #patchmypc
-
๐๐ผ๐ ๐๐ผ ๐ฎ๐๐๐ผ๐บ๐ฎ๐๐ถ๐ฐ๐ฎ๐น๐น๐ ๐๐ฝ๐ฑ๐ฎ๐๐ฒ ๐ฎ๐ฝ๐ฝ๐น๐ถ๐ฐ๐ฎ๐๐ถ๐ผ๐ป๐ ๐ผ๐ป ๐ฐ๐ผ๐บ๐ฝ๐๐๐ฒ๐ฟ๐ ๐ถ๐ป ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐๐ป๐๐๐ป๐ฒ
Microsoft Intune does not have any built-in options for updating installed applications on Windows computers.
If you want to update applications on managed computers, you must manually create a new version of the given application and deploy it to all computers. However, this is quite a lot of manual work, and you also have to monitor the availability of new versions of installed applications, which is another lot of manual work.
Read more in the article on my blog ๐ ๐
https://www.cswrld.com/2025/08/how-to-update-applications-using-patch-my-pc/#cswrld #cybersecurityworld #blog #intune #applicationmanagement #appupdates #patchmypc
-
๐๐ผ๐ ๐๐ผ ๐ฐ๐ผ๐น๐น๐ฒ๐ฐ๐ ๐ฐ๐๐๐๐ผ๐บ ๐ฒ๐๐ฒ๐ป๐ ๐๐๐ ๐๐ผ ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐ฆ๐ฒ๐ป๐๐ถ๐ป๐ฒ๐น
Microsoft Sentinel is Microsoft's SIEM/SOAR. It is used to collect and evaluate logs.
If you choose to collect security logs from Windows Server, Microsoft Sentinel can collect predefined log sets using the built-in settings. By default, you have the option to select from the predefined sets All Security Events, Common, or Minimal.
However, if you need to collect some custom Event IDs that do not belong to the above built-in categories, or simply want your own set of Event IDs to collect, you can define your own Event IDs using XPath queries.
XPath (XML Path Language) is a query language used for selecting nodes from an XML document. It allows you to navigate through elements and attributes in XML documents, making it a powerful tool for extracting specific pieces of information. XPath is commonly used in combination with XML parsers to filter and locate data based on complex conditions.
Read my blog post bellow ๐ ๐
https://www.cswrld.com/2025/06/how-to-collect-custom-event-ids-to-microsoft-sentinel/ -
๐๐ผ๐ ๐๐ผ ๐ฐ๐ผ๐น๐น๐ฒ๐ฐ๐ ๐ฐ๐๐๐๐ผ๐บ ๐ฒ๐๐ฒ๐ป๐ ๐๐๐ ๐๐ผ ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐ฆ๐ฒ๐ป๐๐ถ๐ป๐ฒ๐น
Microsoft Sentinel is Microsoft's SIEM/SOAR. It is used to collect and evaluate logs.
If you choose to collect security logs from Windows Server, Microsoft Sentinel can collect predefined log sets using the built-in settings. By default, you have the option to select from the predefined sets All Security Events, Common, or Minimal.
However, if you need to collect some custom Event IDs that do not belong to the above built-in categories, or simply want your own set of Event IDs to collect, you can define your own Event IDs using XPath queries.
XPath (XML Path Language) is a query language used for selecting nodes from an XML document. It allows you to navigate through elements and attributes in XML documents, making it a powerful tool for extracting specific pieces of information. XPath is commonly used in combination with XML parsers to filter and locate data based on complex conditions.
Read my blog post bellow ๐ ๐
https://www.cswrld.com/2025/06/how-to-collect-custom-event-ids-to-microsoft-sentinel/ -
๐๐ผ๐ ๐๐ผ ๐ฐ๐ผ๐น๐น๐ฒ๐ฐ๐ ๐ฐ๐๐๐๐ผ๐บ ๐ฒ๐๐ฒ๐ป๐ ๐๐๐ ๐๐ผ ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐ฆ๐ฒ๐ป๐๐ถ๐ป๐ฒ๐น
Microsoft Sentinel is Microsoft's SIEM/SOAR. It is used to collect and evaluate logs.
If you choose to collect security logs from Windows Server, Microsoft Sentinel can collect predefined log sets using the built-in settings. By default, you have the option to select from the predefined sets All Security Events, Common, or Minimal.
However, if you need to collect some custom Event IDs that do not belong to the above built-in categories, or simply want your own set of Event IDs to collect, you can define your own Event IDs using XPath queries.
XPath (XML Path Language) is a query language used for selecting nodes from an XML document. It allows you to navigate through elements and attributes in XML documents, making it a powerful tool for extracting specific pieces of information. XPath is commonly used in combination with XML parsers to filter and locate data based on complex conditions.
Read my blog post bellow ๐ ๐
https://www.cswrld.com/2025/06/how-to-collect-custom-event-ids-to-microsoft-sentinel/ -
๐๐ผ๐ ๐๐ผ ๐ฐ๐ผ๐น๐น๐ฒ๐ฐ๐ ๐ฐ๐๐๐๐ผ๐บ ๐ฒ๐๐ฒ๐ป๐ ๐๐๐ ๐๐ผ ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐ฆ๐ฒ๐ป๐๐ถ๐ป๐ฒ๐น
Microsoft Sentinel is Microsoft's SIEM/SOAR. It is used to collect and evaluate logs.
If you choose to collect security logs from Windows Server, Microsoft Sentinel can collect predefined log sets using the built-in settings. By default, you have the option to select from the predefined sets All Security Events, Common, or Minimal.
However, if you need to collect some custom Event IDs that do not belong to the above built-in categories, or simply want your own set of Event IDs to collect, you can define your own Event IDs using XPath queries.
XPath (XML Path Language) is a query language used for selecting nodes from an XML document. It allows you to navigate through elements and attributes in XML documents, making it a powerful tool for extracting specific pieces of information. XPath is commonly used in combination with XML parsers to filter and locate data based on complex conditions.
Read my blog post bellow ๐ ๐
https://www.cswrld.com/2025/06/how-to-collect-custom-event-ids-to-microsoft-sentinel/ -
๐๐ผ๐ ๐๐ผ ๐ฑ๐ถ๐๐ฎ๐ฏ๐น๐ฒ ๐ฆ๐ฒ๐น๐ณ-๐ฆ๐ฒ๐ฟ๐๐ถ๐ฐ๐ฒ ๐ฃ๐ฎ๐๐๐๐ผ๐ฟ๐ฑ ๐ฅ๐ฒ๐๐ฒ๐ ๐ณ๐ผ๐ฟ ๐ฎ๐ฑ๐บ๐ถ๐ป๐ถ๐๐๐ฟ๐ฎ๐๐ผ๐ฟ๐ ๐ถ๐ป ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐๐ป๐๐ฟ๐ฎ ๐๐
Self-service password reset can be a useful feature that allows users to access their account in case they forget their password.
On the other hand, it is potentially risky, as a potential attacker may target the self-service password reset feature to gain access to the account. Especially for privileged accounts, this is very risky and therefore I would generally recommend disabling self-service password resets for privileged accounts.
๐บ Watch my YouTube video bellow ๐ ๐
https://youtu.be/KIlRPx_9XRA#cswrld #videotutorial #sspr #passwordreset #entraid #administrators
-
๐๐ผ๐ ๐๐ผ ๐ฑ๐ถ๐๐ฎ๐ฏ๐น๐ฒ ๐ฆ๐ฒ๐น๐ณ-๐ฆ๐ฒ๐ฟ๐๐ถ๐ฐ๐ฒ ๐ฃ๐ฎ๐๐๐๐ผ๐ฟ๐ฑ ๐ฅ๐ฒ๐๐ฒ๐ ๐ณ๐ผ๐ฟ ๐ฎ๐ฑ๐บ๐ถ๐ป๐ถ๐๐๐ฟ๐ฎ๐๐ผ๐ฟ๐ ๐ถ๐ป ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐๐ป๐๐ฟ๐ฎ ๐๐
Self-service password reset can be a useful feature that allows users to access their account in case they forget their password.
On the other hand, it is potentially risky, as a potential attacker may target the self-service password reset feature to gain access to the account. Especially for privileged accounts, this is very risky and therefore I would generally recommend disabling self-service password resets for privileged accounts.
๐บ Watch my YouTube video bellow ๐ ๐
https://youtu.be/KIlRPx_9XRA#cswrld #videotutorial #sspr #passwordreset #entraid #administrators
-
๐๐ผ๐ ๐๐ผ ๐ฑ๐ถ๐๐ฎ๐ฏ๐น๐ฒ ๐ฆ๐ฒ๐น๐ณ-๐ฆ๐ฒ๐ฟ๐๐ถ๐ฐ๐ฒ ๐ฃ๐ฎ๐๐๐๐ผ๐ฟ๐ฑ ๐ฅ๐ฒ๐๐ฒ๐ ๐ณ๐ผ๐ฟ ๐ฎ๐ฑ๐บ๐ถ๐ป๐ถ๐๐๐ฟ๐ฎ๐๐ผ๐ฟ๐ ๐ถ๐ป ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐๐ป๐๐ฟ๐ฎ ๐๐
Self-service password reset can be a useful feature that allows users to access their account in case they forget their password.
On the other hand, it is potentially risky, as a potential attacker may target the self-service password reset feature to gain access to the account. Especially for privileged accounts, this is very risky and therefore I would generally recommend disabling self-service password resets for privileged accounts.
๐บ Watch my YouTube video bellow ๐ ๐
https://youtu.be/KIlRPx_9XRA#cswrld #videotutorial #sspr #passwordreset #entraid #administrators
-
๐๐ผ๐ ๐๐ผ ๐ฑ๐ถ๐๐ฎ๐ฏ๐น๐ฒ ๐ฆ๐ฒ๐น๐ณ-๐ฆ๐ฒ๐ฟ๐๐ถ๐ฐ๐ฒ ๐ฃ๐ฎ๐๐๐๐ผ๐ฟ๐ฑ ๐ฅ๐ฒ๐๐ฒ๐ ๐ณ๐ผ๐ฟ ๐ฎ๐ฑ๐บ๐ถ๐ป๐ถ๐๐๐ฟ๐ฎ๐๐ผ๐ฟ๐ ๐ถ๐ป ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐๐ป๐๐ฟ๐ฎ ๐๐
Self-service password reset can be a useful feature that allows users to access their account in case they forget their password.
On the other hand, it is potentially risky, as a potential attacker may target the self-service password reset feature to gain access to the account. Especially for privileged accounts, this is very risky and therefore I would generally recommend disabling self-service password resets for privileged accounts.
๐บ Watch my YouTube video bellow ๐ ๐
https://youtu.be/KIlRPx_9XRA#cswrld #videotutorial #sspr #passwordreset #entraid #administrators
-
๐๐ผ๐ ๐๐ผ ๐ฏ๐น๐ผ๐ฐ๐ธ ๐ฎ๐๐๐ผ๐บ๐ฎ๐๐ถ๐ฐ ๐ฒ๐บ๐ฎ๐ถ๐น ๐ณ๐ผ๐ฟ๐๐ฎ๐ฟ๐ฑ๐ถ๐ป๐ด ๐ถ๐ป ๐ข๐ณ๐ณ๐ถ๐ฐ๐ฒ ๐ฏ๐ฒ๐ฑ
Automatic email forwarding is very risky. First, it can lead to exfiltration of sensitive internal information outside the corporate environment. But it can also cause account compromise, for example through password reset whose code arrives at some external address that may be under the control of an attacker.
๐บ Watch my YouTube video bellow ๐ ๐
https://youtu.be/sdjG-gl6Xxs#cswrld #videotutorial #email #forwarding #office365 #exchangeonline
-
๐๐ผ๐ ๐๐ผ ๐ฏ๐น๐ผ๐ฐ๐ธ ๐ฎ๐๐๐ผ๐บ๐ฎ๐๐ถ๐ฐ ๐ฒ๐บ๐ฎ๐ถ๐น ๐ณ๐ผ๐ฟ๐๐ฎ๐ฟ๐ฑ๐ถ๐ป๐ด ๐ถ๐ป ๐ข๐ณ๐ณ๐ถ๐ฐ๐ฒ ๐ฏ๐ฒ๐ฑ
Automatic email forwarding is very risky. First, it can lead to exfiltration of sensitive internal information outside the corporate environment. But it can also cause account compromise, for example through password reset whose code arrives at some external address that may be under the control of an attacker.
๐บ Watch my YouTube video bellow ๐ ๐
https://youtu.be/sdjG-gl6Xxs#cswrld #videotutorial #email #forwarding #office365 #exchangeonline
-
๐๐ผ๐ ๐๐ผ ๐ฏ๐น๐ผ๐ฐ๐ธ ๐ฎ๐๐๐ผ๐บ๐ฎ๐๐ถ๐ฐ ๐ฒ๐บ๐ฎ๐ถ๐น ๐ณ๐ผ๐ฟ๐๐ฎ๐ฟ๐ฑ๐ถ๐ป๐ด ๐ถ๐ป ๐ข๐ณ๐ณ๐ถ๐ฐ๐ฒ ๐ฏ๐ฒ๐ฑ
Automatic email forwarding is very risky. First, it can lead to exfiltration of sensitive internal information outside the corporate environment. But it can also cause account compromise, for example through password reset whose code arrives at some external address that may be under the control of an attacker.
๐บ Watch my YouTube video bellow ๐ ๐
https://youtu.be/sdjG-gl6Xxs#cswrld #videotutorial #email #forwarding #office365 #exchangeonline
-
๐๐ผ๐ ๐๐ผ ๐ฏ๐น๐ผ๐ฐ๐ธ ๐ฎ๐๐๐ผ๐บ๐ฎ๐๐ถ๐ฐ ๐ฒ๐บ๐ฎ๐ถ๐น ๐ณ๐ผ๐ฟ๐๐ฎ๐ฟ๐ฑ๐ถ๐ป๐ด ๐ถ๐ป ๐ข๐ณ๐ณ๐ถ๐ฐ๐ฒ ๐ฏ๐ฒ๐ฑ
Automatic email forwarding is very risky. First, it can lead to exfiltration of sensitive internal information outside the corporate environment. But it can also cause account compromise, for example through password reset whose code arrives at some external address that may be under the control of an attacker.
๐บ Watch my YouTube video bellow ๐ ๐
https://youtu.be/sdjG-gl6Xxs#cswrld #videotutorial #email #forwarding #office365 #exchangeonline
-
๐๐ผ๐ ๐๐ผ ๐ฏ๐ฎ๐ฐ๐ธ๐๐ฝ ๐ข๐ณ๐ณ๐ถ๐ฐ๐ฒ ๐ฏ๐ฒ๐ฑ ๐ฑ๐ฎ๐๐ฎ
Right off the bat, you might be wondering why I should back up data from Office 365 when it's a cloud service. Microsoft assures you of high data availability, but the service itself has no built-in backup mechanisms. And that's something to keep in mind.
Office 365 has two levels of recycle bins in it. The first level is user level, and data from this recycle bin can be restored directly by the user. The second level is admin and only an administrator can restore data from this level. You can have litigation hold and in-place hold set up, but that is not available in all plans, and you probably won't activate it on all mailboxes, SharePoint sites and teams in Teams.
๐บ Learn more how to backup Office 365 data in my today's video ๐ ๐
https://youtu.be/BBEjAKeaRCQ -
๐๐ผ๐ ๐๐ผ ๐ฏ๐ฎ๐ฐ๐ธ๐๐ฝ ๐ข๐ณ๐ณ๐ถ๐ฐ๐ฒ ๐ฏ๐ฒ๐ฑ ๐ฑ๐ฎ๐๐ฎ
Right off the bat, you might be wondering why I should back up data from Office 365 when it's a cloud service. Microsoft assures you of high data availability, but the service itself has no built-in backup mechanisms. And that's something to keep in mind.
Office 365 has two levels of recycle bins in it. The first level is user level, and data from this recycle bin can be restored directly by the user. The second level is admin and only an administrator can restore data from this level. You can have litigation hold and in-place hold set up, but that is not available in all plans, and you probably won't activate it on all mailboxes, SharePoint sites and teams in Teams.
๐บ Learn more how to backup Office 365 data in my today's video ๐ ๐
https://youtu.be/BBEjAKeaRCQ -
๐๐ผ๐ ๐๐ผ ๐ฏ๐ฎ๐ฐ๐ธ๐๐ฝ ๐ข๐ณ๐ณ๐ถ๐ฐ๐ฒ ๐ฏ๐ฒ๐ฑ ๐ฑ๐ฎ๐๐ฎ
Right off the bat, you might be wondering why I should back up data from Office 365 when it's a cloud service. Microsoft assures you of high data availability, but the service itself has no built-in backup mechanisms. And that's something to keep in mind.
Office 365 has two levels of recycle bins in it. The first level is user level, and data from this recycle bin can be restored directly by the user. The second level is admin and only an administrator can restore data from this level. You can have litigation hold and in-place hold set up, but that is not available in all plans, and you probably won't activate it on all mailboxes, SharePoint sites and teams in Teams.
๐บ Learn more how to backup Office 365 data in my today's video ๐ ๐
https://youtu.be/BBEjAKeaRCQ -
๐๐ผ๐ ๐๐ผ ๐ฏ๐ฎ๐ฐ๐ธ๐๐ฝ ๐ข๐ณ๐ณ๐ถ๐ฐ๐ฒ ๐ฏ๐ฒ๐ฑ ๐ฑ๐ฎ๐๐ฎ
Right off the bat, you might be wondering why I should back up data from Office 365 when it's a cloud service. Microsoft assures you of high data availability, but the service itself has no built-in backup mechanisms. And that's something to keep in mind.
Office 365 has two levels of recycle bins in it. The first level is user level, and data from this recycle bin can be restored directly by the user. The second level is admin and only an administrator can restore data from this level. You can have litigation hold and in-place hold set up, but that is not available in all plans, and you probably won't activate it on all mailboxes, SharePoint sites and teams in Teams.
๐บ Learn more how to backup Office 365 data in my today's video ๐ ๐
https://youtu.be/BBEjAKeaRCQ -
๐๐ผ๐ ๐๐ผ ๐ฏ๐น๐ผ๐ฐ๐ธ ๐๐ฝ๐ฒ๐ฐ๐ถ๐ณ๐ถ๐ฐ ๐ณ๐ถ๐น๐ฒ ๐๐๐ฝ๐ฒ๐ ๐ถ๐ป ๐ฒ๐บ๐ฎ๐ถ๐น ๐ฎ๐๐๐ฎ๐ฐ๐ต๐บ๐ฒ๐ป๐๐
A very common source of infection is email. Everyone uses email and threat actors take advantage of it. Either in the form of phishing or in the form of malicious attachments.
There are very advanced protection options within Office 365. Whether it be within Exchange Online Protection, which is included in all Office 365 / Exchange Online plans, or within Safe Attachments, which is an extension within Microsoft Defender for Office 365.
But a very effective protection is the very simple blocking of unwanted file types within email attachments. You simply block what is unwanted, making it very easy and effective to block many potentially malicious files.
๐บ Watch my YouTube video bellow ๐ ๐
https://youtu.be/dFlD_CH5Kp8#cswrld #videotutorial #email #attachments #filter #office365 #exchangeonline
-
๐๐ผ๐ ๐๐ผ ๐ฏ๐น๐ผ๐ฐ๐ธ ๐๐ฝ๐ฒ๐ฐ๐ถ๐ณ๐ถ๐ฐ ๐ณ๐ถ๐น๐ฒ ๐๐๐ฝ๐ฒ๐ ๐ถ๐ป ๐ฒ๐บ๐ฎ๐ถ๐น ๐ฎ๐๐๐ฎ๐ฐ๐ต๐บ๐ฒ๐ป๐๐
A very common source of infection is email. Everyone uses email and threat actors take advantage of it. Either in the form of phishing or in the form of malicious attachments.
There are very advanced protection options within Office 365. Whether it be within Exchange Online Protection, which is included in all Office 365 / Exchange Online plans, or within Safe Attachments, which is an extension within Microsoft Defender for Office 365.
But a very effective protection is the very simple blocking of unwanted file types within email attachments. You simply block what is unwanted, making it very easy and effective to block many potentially malicious files.
๐บ Watch my YouTube video bellow ๐ ๐
https://youtu.be/dFlD_CH5Kp8#cswrld #videotutorial #email #attachments #filter #office365 #exchangeonline
-
๐๐ผ๐ ๐๐ผ ๐ฏ๐น๐ผ๐ฐ๐ธ ๐๐ฝ๐ฒ๐ฐ๐ถ๐ณ๐ถ๐ฐ ๐ณ๐ถ๐น๐ฒ ๐๐๐ฝ๐ฒ๐ ๐ถ๐ป ๐ฒ๐บ๐ฎ๐ถ๐น ๐ฎ๐๐๐ฎ๐ฐ๐ต๐บ๐ฒ๐ป๐๐
A very common source of infection is email. Everyone uses email and threat actors take advantage of it. Either in the form of phishing or in the form of malicious attachments.
There are very advanced protection options within Office 365. Whether it be within Exchange Online Protection, which is included in all Office 365 / Exchange Online plans, or within Safe Attachments, which is an extension within Microsoft Defender for Office 365.
But a very effective protection is the very simple blocking of unwanted file types within email attachments. You simply block what is unwanted, making it very easy and effective to block many potentially malicious files.
๐บ Watch my YouTube video bellow ๐ ๐
https://youtu.be/dFlD_CH5Kp8#cswrld #videotutorial #email #attachments #filter #office365 #exchangeonline
-
๐๐ผ๐ ๐๐ผ ๐ฏ๐น๐ผ๐ฐ๐ธ ๐๐ฝ๐ฒ๐ฐ๐ถ๐ณ๐ถ๐ฐ ๐ณ๐ถ๐น๐ฒ ๐๐๐ฝ๐ฒ๐ ๐ถ๐ป ๐ฒ๐บ๐ฎ๐ถ๐น ๐ฎ๐๐๐ฎ๐ฐ๐ต๐บ๐ฒ๐ป๐๐
A very common source of infection is email. Everyone uses email and threat actors take advantage of it. Either in the form of phishing or in the form of malicious attachments.
There are very advanced protection options within Office 365. Whether it be within Exchange Online Protection, which is included in all Office 365 / Exchange Online plans, or within Safe Attachments, which is an extension within Microsoft Defender for Office 365.
But a very effective protection is the very simple blocking of unwanted file types within email attachments. You simply block what is unwanted, making it very easy and effective to block many potentially malicious files.
๐บ Watch my YouTube video bellow ๐ ๐
https://youtu.be/dFlD_CH5Kp8#cswrld #videotutorial #email #attachments #filter #office365 #exchangeonline
-
๐๐ผ๐ ๐๐ผ ๐ฏ๐น๐ผ๐ฐ๐ธ ๐๐ป๐ธ๐ป๐ผ๐๐ป ๐ฝ๐น๐ฎ๐๐ณ๐ผ๐ฟ๐บ๐ ๐ถ๐ป ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐๐ป๐๐ฟ๐ฎ ๐๐
Under conditional access policies, it is possible to block individual device platforms. In general, it is a good idea to eliminate all ways that a potential threat actor could use to compromise the environment. In other words, block everything that is not needed.
This also applies to device platforms within Microsoft Entra ID. For example, if your organization only uses Windows, iOS, and Android, it's a good idea to disable all other platforms. If you also use macOS, you need to add macOS as well, of course.
What I would definitely recommend blocking is Windows Phone and other unknown platforms. Unrecognized / unknown platforms are usually spoofed User Agents, which is mainly used by threat actors.
๐บ Watch my YouTube video bellow ๐ ๐
https://youtu.be/vFhQgwXmqTo#cswrld #videotutorial #entraid #conditionalaccess #platforms #blocking
-
๐๐ผ๐ ๐๐ผ ๐ฏ๐น๐ผ๐ฐ๐ธ ๐๐ป๐ธ๐ป๐ผ๐๐ป ๐ฝ๐น๐ฎ๐๐ณ๐ผ๐ฟ๐บ๐ ๐ถ๐ป ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐๐ป๐๐ฟ๐ฎ ๐๐
Under conditional access policies, it is possible to block individual device platforms. In general, it is a good idea to eliminate all ways that a potential threat actor could use to compromise the environment. In other words, block everything that is not needed.
This also applies to device platforms within Microsoft Entra ID. For example, if your organization only uses Windows, iOS, and Android, it's a good idea to disable all other platforms. If you also use macOS, you need to add macOS as well, of course.
What I would definitely recommend blocking is Windows Phone and other unknown platforms. Unrecognized / unknown platforms are usually spoofed User Agents, which is mainly used by threat actors.
๐บ Watch my YouTube video bellow ๐ ๐
https://youtu.be/vFhQgwXmqTo#cswrld #videotutorial #entraid #conditionalaccess #platforms #blocking
-
๐๐ผ๐ ๐๐ผ ๐ฏ๐น๐ผ๐ฐ๐ธ ๐๐ป๐ธ๐ป๐ผ๐๐ป ๐ฝ๐น๐ฎ๐๐ณ๐ผ๐ฟ๐บ๐ ๐ถ๐ป ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐๐ป๐๐ฟ๐ฎ ๐๐
Under conditional access policies, it is possible to block individual device platforms. In general, it is a good idea to eliminate all ways that a potential threat actor could use to compromise the environment. In other words, block everything that is not needed.
This also applies to device platforms within Microsoft Entra ID. For example, if your organization only uses Windows, iOS, and Android, it's a good idea to disable all other platforms. If you also use macOS, you need to add macOS as well, of course.
What I would definitely recommend blocking is Windows Phone and other unknown platforms. Unrecognized / unknown platforms are usually spoofed User Agents, which is mainly used by threat actors.
๐บ Watch my YouTube video bellow ๐ ๐
https://youtu.be/vFhQgwXmqTo#cswrld #videotutorial #entraid #conditionalaccess #platforms #blocking
-
๐๐ผ๐ ๐๐ผ ๐ฏ๐น๐ผ๐ฐ๐ธ ๐๐ป๐ธ๐ป๐ผ๐๐ป ๐ฝ๐น๐ฎ๐๐ณ๐ผ๐ฟ๐บ๐ ๐ถ๐ป ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐๐ป๐๐ฟ๐ฎ ๐๐
Under conditional access policies, it is possible to block individual device platforms. In general, it is a good idea to eliminate all ways that a potential threat actor could use to compromise the environment. In other words, block everything that is not needed.
This also applies to device platforms within Microsoft Entra ID. For example, if your organization only uses Windows, iOS, and Android, it's a good idea to disable all other platforms. If you also use macOS, you need to add macOS as well, of course.
What I would definitely recommend blocking is Windows Phone and other unknown platforms. Unrecognized / unknown platforms are usually spoofed User Agents, which is mainly used by threat actors.
๐บ Watch my YouTube video bellow ๐ ๐
https://youtu.be/vFhQgwXmqTo#cswrld #videotutorial #entraid #conditionalaccess #platforms #blocking
-
๐๐ผ๐ ๐๐ผ ๐ฏ๐น๐ผ๐ฐ๐ธ ๐ป๐ฒ๐๐น๐ ๐ฟ๐ฒ๐ด๐ถ๐๐๐ฒ๐ฟ๐ฒ๐ฑ ๐ฑ๐ผ๐บ๐ฎ๐ถ๐ป๐ ๐ถ๐ป ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐๐ฒ๐ณ๐ฒ๐ป๐ฑ๐ฒ๐ฟ ๐ณ๐ผ๐ฟ ๐๐ป๐ฑ๐ฝ๐ผ๐ถ๐ป๐
Newly registered domains can of course be legitimate. Every domain is new at some point. But usually there isnโt any content on new domains right away โ the content is still being developed, and the launch of the site wonโt happen for some time.
But newly registered domains are often a tool for phishing attacks. Such domains are usually used in phishing attacks immediately after registration and usually disappear again after a short time, for example because they are cancelled or blocked by the registrar.
Blocking access to newly registered domains is a relatively popular and effective way of eliminating phishing.
It is possible to block newly registered and parked domains within Microsoft Defender for Endpoint. Domains within the first 30 days of registration are considered newly registered.
๐บ Watch my YouTube video bellow ๐ ๐
https://youtu.be/oYtDHK90P1M -
๐๐ผ๐ ๐๐ผ ๐ฏ๐น๐ผ๐ฐ๐ธ ๐ป๐ฒ๐๐น๐ ๐ฟ๐ฒ๐ด๐ถ๐๐๐ฒ๐ฟ๐ฒ๐ฑ ๐ฑ๐ผ๐บ๐ฎ๐ถ๐ป๐ ๐ถ๐ป ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐๐ฒ๐ณ๐ฒ๐ป๐ฑ๐ฒ๐ฟ ๐ณ๐ผ๐ฟ ๐๐ป๐ฑ๐ฝ๐ผ๐ถ๐ป๐
Newly registered domains can of course be legitimate. Every domain is new at some point. But usually there isnโt any content on new domains right away โ the content is still being developed, and the launch of the site wonโt happen for some time.
But newly registered domains are often a tool for phishing attacks. Such domains are usually used in phishing attacks immediately after registration and usually disappear again after a short time, for example because they are cancelled or blocked by the registrar.
Blocking access to newly registered domains is a relatively popular and effective way of eliminating phishing.
It is possible to block newly registered and parked domains within Microsoft Defender for Endpoint. Domains within the first 30 days of registration are considered newly registered.
๐บ Watch my YouTube video bellow ๐ ๐
https://youtu.be/oYtDHK90P1M -
๐๐ผ๐ ๐๐ผ ๐ฏ๐น๐ผ๐ฐ๐ธ ๐ป๐ฒ๐๐น๐ ๐ฟ๐ฒ๐ด๐ถ๐๐๐ฒ๐ฟ๐ฒ๐ฑ ๐ฑ๐ผ๐บ๐ฎ๐ถ๐ป๐ ๐ถ๐ป ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐๐ฒ๐ณ๐ฒ๐ป๐ฑ๐ฒ๐ฟ ๐ณ๐ผ๐ฟ ๐๐ป๐ฑ๐ฝ๐ผ๐ถ๐ป๐
Newly registered domains can of course be legitimate. Every domain is new at some point. But usually there isnโt any content on new domains right away โ the content is still being developed, and the launch of the site wonโt happen for some time.
But newly registered domains are often a tool for phishing attacks. Such domains are usually used in phishing attacks immediately after registration and usually disappear again after a short time, for example because they are cancelled or blocked by the registrar.
Blocking access to newly registered domains is a relatively popular and effective way of eliminating phishing.
It is possible to block newly registered and parked domains within Microsoft Defender for Endpoint. Domains within the first 30 days of registration are considered newly registered.
๐บ Watch my YouTube video bellow ๐ ๐
https://youtu.be/oYtDHK90P1M