@KronheimK Profile picture

Philip K

@KronheimK

IT Specialist #Windows10 #ConfigMgr #Intune #EMS #SCCM

Joined December 2015
Similar User
MikeT photo

@Deploy_Boy

Karsten Löhring photo

@klowpv

René photo

@SirConfigmgr

Philipp Wree photo

@PROVPWR

Könich von Südschweden photo

@Sweden_King

Rick Becerra photo

@RJBMSNYC

Brent Hendrix photo

@benerbas

Philip K Reposted

In the last months, I have collected some awesome new #KQL sources, and this 🧵lists them. Are you using Defender For Endpoint, Sentinel, Intune or do you want to learn KQL then have a look! #MDE #Sentinel #Intune #Detection #ThreatHunting


Philip K Reposted

This @Microsoft #EntraID tweet blew up, so here is some #KQL to go along with it... I removed Per-user MFA from all but one user (you got to have a control!); checking the impact of that change: Colours are hard to make out, but only one user impacted post-change! #Result

Tweet Image 1

Quick @Microsoft #EntraID tip: Getting excessive MFA prompts? Use the "Authentication Prompts Analysis" workbook under Entra ID > Identity > Monitoring & Health > Workbooks and look for "Authentication prompts by policy"

Tweet Image 1


Philip K Reposted

Just released my latest analysis of Defender for Endpoint features by OS. Targeted at folks deploying MDE to understand what can be used and where; what capabilities you might have missed; or potential customers evaluating options. Blog + download: campbell.scot/mde-comparison…

Tweet Image 1

Philip K Reposted

1/ Defender prevented the execution of the malware 'Casdet' on an endpoint. Especially with AV alerts, besides the detection, I am always interested in the birth time of the detected file. Was the file detected when it was written to the disk, or since when is it present? 🧵

Tweet Image 1

Philip K Reposted

I've always thought that in order for Defenders to be truly effective, it is vital they know where the telemetry they are leveraging is coming from. Today I am releasing a project called TelemetrySource that is meant to support that cause. Blog: posts.specterops.io/uncovering-win…


Philip K Reposted

This short and sweet video explains the Microsoft Defender for Endpoint architecture. Thanks @HeikeRitter youtube.com/watch?v=C0ato8…

Tweet Image 1

Philip K Reposted

Wait...whaaa....!?

Did you know you can populate Administrative Units in Azure AD based on a user's on-premises OU? You can now key off of the onPremisesDistinguisedName property of a user to add them to an AU:

Tweet Image 1


Philip K Reposted

Security Settings Management in Microsoft Defender for Endpoint is now generally available: Security Settings Management in Microsoft Defender for Endpoint is now generally available (3 min.) Preventing data breaches and… bit.ly/3FFJUVV #MDATP #Security #MEM

Tweet Image 1

Philip K Reposted

📢 All sessions from the Modern Endpoint Management Summit 2022 are now available on YouTube #MSIntune #Intune #MEMPowered youtu.be/Xuh4ZPUUulY


Philip K Reposted

Progress in Windows 11 22610:

Tweet Image 1

Announcing Windows 11 Insider Preview Build 22610 blogs.windows.com/windows-inside…



Philip K Reposted

Thread of some Defender for Endpoint/Defender Antivirus config + deployment tips that are often overlooked. 1. Modern AVs like to update frequently and intelligence updates are done with deltas. Unless you have exceptionally poor internet, set updates to hourly and before scans.

Tweet Image 1

Philip K Reposted

#AzureAD #ConditionalAccess needs to be carefully monitored and you need to act on any insecure configuration changes. I decided to create a Conditional Access analytic rules pack for #MicrosoftSentinel, and here it is!! danielchronlund.com/2022/04/13/mon…

Tweet Image 1

Philip K Reposted

➡️Intune Audit Logs Track Who Created Updated Device Compliance Policy – anoopcnair.com/intune-audit-l…

Tweet Image 1

Philip K Reposted

Just updated my BSOD remediation script to: - Automatically detect devices with new BSOD - Automatically send logs on SharePoint - Automatically create a new notif on Teams #MEMPowered #MSIntune #Intune #SharePoint

Tweet Image 1

Philip K Reposted

Working on a new Proactive Remediation to inform user their Azure AD password will soon expire #MEMPowered #MSIntune #Intune

Tweet Image 1

Philip K Reposted

#ProTip If you check the following paths on the device & don't see the #WindowsUpdate policy you've "set"- you haven't set it. GP: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate CSP: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\current\device\Update

Tweet Image 1

Philip K Reposted

A quick Proactive Remediation script for low disk space to: - Display a toast notif warning - Display an HTML report of larger content on disk (larger folders in C:\Users and C:\, larger files in C:\, folder redirection status...) systanddeploy.com/2022/01/proact… #MEMPowered #MSIntune

Tweet Image 1
Tweet Image 2

Philip K Reposted

Evolving Autopilot Manager ...learn about the latest enhancements and how you might benefit from it. #MSIntune #WindowsAutopilot #Autopilot #Microsoft #MEM #AutopilotManager #Windows oliverkieselbach.com/2021/12/21/evo…


United States Trends
Loading...

Something went wrong.


Something went wrong.