How to Be Notified by Email When a New Zero Day is Reported

Customers of Microsoft Defender for Endpoint have a wealth of knowledge available at their fingertips, enabling the most comprehensive view of the security of the estate. This wealth of knowledge is crucial, but it may not be always feasible - and definitely not always necessary - to hover in front of the Microsoft 365 Defender … Continue reading How to Be Notified by Email When a New Zero Day is Reported

Estimating the Size of the M365 Advanced Tables for Microsoft Sentinel Enablement

The Microsoft 365 Defender Connector in Microsoft Sentinel is coming along nicely with all the table sources now available to select. The Connector is still in public preview, but the progress is a very welcome sight. All the logs Even though ingesting the M365 Advanced logs is considered necessary, enabling them will cost something. There … Continue reading Estimating the Size of the M365 Advanced Tables for Microsoft Sentinel Enablement

Replay Available: Cicadas and Microsoft Defender for Identity on the Microsoft Security Insights Podcast

Edward was out again this week so I filled in, helping as a guest-host once again. The discussion was wonderful and I learned a heap about Microsoft Defender for Identity, including some things I've been asked about by customers recently. Now, I can go back to those customers and sound really cool and intelligent. I … Continue reading Replay Available: Cicadas and Microsoft Defender for Identity on the Microsoft Security Insights Podcast

Connect Incidents & Alerts for Microsoft 365 Defender Now in Public Preview

Many of you have been waiting for Microsoft to take the wraps off the ability to connect Microsoft 365 Defender​ to Azure Sentinel so that the Microsoft 365 Defender Incidents will appear in the incidents queue. This is also the capability that allows bi-directional synching between both products, i.e., close an incident in one, the … Continue reading Connect Incidents & Alerts for Microsoft 365 Defender Now in Public Preview