Skip to content

Vertho | Verheyden Thomas

Blogging about (Microsoft) Security and more

  • Events
  • List of Blogs
  • URBAC Mapper
  • About
  • Contact
Vertho | Verheyden Thomas
Blogging about (Microsoft) Security and more
  • 4 August 2023

    Microsoft Defender for Endpoint security management (MDE Attach v2) on Linux : A deep dive

    Intro This blog post is inspired by Rudy Ooms, who wrote a excellent write up about the behind the scenes of the MDE attach v2 process and security configuration on Windows endpoints. Which can be found here. A must read if you want a better understanding how MDE attach v2 is working… I was getting…

    Read more

  • 20 July 2023

    Unleash the power of defender plan 2: Just-in-time VM access – part 4

    Intro Malicious actors actively search for machines with open management ports, such as RDP or SSH, to exploit. All of your virtual machines are potential targets for these attacks if you have those ports open. Once a VM is compromised, it serves as a entry point for the attackers to target other resources within your…

    Read more

  • 30 June 2023

    Tool: MDE-Troubleshooter is born !

    Background story During my consultancy work, I have received feedback from numerous clients indicating that they consistently encountered difficulties when attempting to troubleshoot issues with Defender for Endpoint on their local endpoints. They often found it a struggle to navigate through various locations, such as PowerShell for security configuration, the event viewer for log files,…

    Read more

  • 23 June 2023

    Your isolated device stuck in Defender for Endpoint Isolation mode , not anymore !

    Intro When you want to investigate a endpoint that has indication of being comprised you might want to put the endpoint in Defender for Endpoint isolation mode. Isolation will disconnected the potential comprised endpoint from the network and will only allow connection to Defender for Endpoint Service. Depending on your OS level you can also…

    Read more

  • 15 June 2023

    Microsoft Defender for Endpoint settings management: Enhancements

    *UPDATE 17/07/2023* Added extra information about system labels Intro Microsoft is doing a very good job at listening to their customers, partners and MVP’s lately. One of the highly requested feature was to simplify the requirements for their MDE settings management (AKA ‘MDE Attach’) . But that’s not all, more exciting news will be announced…

    Read more

  • 14 June 2023

    Unleash the power of Defender for Servers Plan 2: Agentless scanning – part 3

    Intro Welcome to part three of the blog series on Unleach the power of Defender for Servers Plan 2! In our previous blog, we explored how to start implementing Adaptive Application control.  In part 3, we’ll dive into the concept of agentless scanning, which is included in Defender for Cloud Plan 2. We’ll explore what…

    Read more

  • 5 June 2023

    Direct on board your non-Azure servers to defender for cloud WITHOUT Azure Arc

    Intro Up until now, onboarding non-Azure servers to Defender for Servers required Azure Arc as a mandatory pre-requisite. With this new release, Microsoft is introducing an additional direct onboarding path for non-Azure servers that does not require Azure Arc (making it optional rather than mandatory).

    Read more

  • 17 May 2023

    Unleash the power of Defender for Servers Plan 2: Adaptive Application Controls – Part 2

    Welcome, this is the second part of the Defender for server P2 advanced protection series I will blog about.  If you want to read the other parts they can be found here: The topic of this blog will be about how to start with adaptive application controls (ACC). Let’s begin with explaining high level what…

    Read more

  • 4 May 2023

    How to work around the Azure Security Agent extension not deploying by default on the latest VM windows images, a currently know limitation…

    Intro This blog will be about an issue I bumped into when deploying one of the enhanced protection features in defender for cloud. The enhanced feature, adaptive application control, requires the deployment of the Azure Monitor Agent. The Azure Monitoring Agent also installs additional extensions. One of those additional extensions is the Azure Security Agent…

    Read more

  • 19 April 2023

    Unleash the power of Defender for Servers Plan 2: File integrity monitoring – Part 1

    Intro Welcome to part 1 of the blog series about enhanced protection features available in Defender for Servers Plan 2. Part 1 will be about  the protection feature called File Integrity Monitoring (FIM) in Defender for cloud.

    Read more

«Previous Page
1 2 3 4
Next Page»

Delen:

  • Share on X (Opens in new window) X
  • Share on LinkedIn (Opens in new window) LinkedIn

Like this:

Like Loading…
Tweets by ThomasVrhydn
Facebook X Instagram

© 2026 Vertho | Verheyden Thomas

Scroll to top
  • Events
  • List of Blogs
  • URBAC Mapper
  • About
  • Contact
Search
%d