Defender XDR
3 articles tagged Defender XDR.
Compromised Microsoft 365 account runbook: contain, investigate, recover
A step-by-step runbook for a confirmed Microsoft 365 account takeover: disable and revoke, remove attacker persistence, scope the breach with audit logs and restore the user safely.
Deploy Defender for Identity sensors on domain controllers and AD CS
Choose between sensor v3.x and v2.x, activate or install Microsoft Defender for Identity on domain controllers and AD CS servers, configure the auditing it needs, and confirm the data arrives.
Onboard Windows devices to Defender for Endpoint with Intune step by step
Connect Microsoft Intune to Defender for Endpoint, deploy an EDR onboarding policy to Windows devices, and verify sensor health on the device, in the Defender portal and with advanced hunting.