Microsoft Defender Weekly Wrap – Issue #54

========================= [Want to discuss this further? Hit me up on Twitter or LinkedIn] [Subscribe to the RSS feed for this blog] [Subscribe to the Weekly Microsoft Sentinel Newsletter] [Subscribe to the Weekly Microsoft Defender Newsletter] [Learn KQL with the Must Learn KQL series and book]

Field Notes: Service running with gMSA account not starting

I recently deployed a new Active Directory Forest in my lab on Windows Server 2022. I wanted to configure the Microsoft On Demand Assessments for Active Directory and also needed to deploy Microsoft Defender for Identity (MDI). I wanted to use a Group Managed Service account to run these instead of a normal service account. … Continue reading Field Notes: Service running with gMSA account not starting

Building Your Own Potential Malicious Events Heatmap for Microsoft Sentinel

With the new entry point actively rolling out to Microsoft Sentinel environments (see: There‚Äôs a New Microsoft Sentinel Entry Page in Town), some organizations are wishing they could at least retain the heatmap from the original console layout. According to most, the rest of the new UI is valuable and likeable, but the heatmap is … Continue reading Building Your Own Potential Malicious Events Heatmap for Microsoft Sentinel

Permanently delete objects from the Active Directory Recycle Bin

With the Active Directory Recycle Bin enabled, deleted Active Directory objects can be easily recovered. The deleted items can be recovered for as long as the Active Directory tombstone lifetime. Based on default configuration this should be 180 days. I recently received a request from a customer to know how they can permanently delete user … Continue reading Permanently delete objects from the Active Directory Recycle Bin

Building Microsoft Sentinel Incident Tasks Recipes

Today, we announced a new feature in public preview called Incident Tasks. Incident Tasks allow organizations to develop a recorded encyclopedia of methods they commonly use to approach specific events in their environment. This enables the security teams to work better and more efficiently and allows all levels of security expertise on the team to … Continue reading Building Microsoft Sentinel Incident Tasks Recipes

Save Azure costs using Spot Instances

In this article I want to talk about how Azure Spot Instances can save you money on your Virtual Machines. These virtual machines are categorized as Infrastructure as a Service (IaaS). I recently received a new subscription and had to rebuild my infrastructure from scratch. At the moment I have four Active Directory Domain Controllers, … Continue reading Save Azure costs using Spot Instances

There’s a New Microsoft Sentinel Entry Page in Town

A new entry page for Microsoft Sentinel is rolling out after a successful stint in the Private Preview program. The rollout is slow but is creeping its way into every Microsoft Sentinel instance as you read this. You can see the differences between the two overviews in the image below and the changes are significant. … Continue reading There’s a New Microsoft Sentinel Entry Page in Town