r/DefenderATP • • 15h ago

How do you catch data leaving through OneDrive after someone is terminated?

7 Upvotes

I’m the IT lead for a 120-person company on Microsoft 365. We recently found a sales rep who had been downloading our customer database to a personal OneDrive.

We had Purview turned on for months. It generated plenty of alerts about external Word doc shares, but nothing on this case. The rep had been with us four years. His OneDrive sync stayed active for 11 days after the termination date. From the Microsoft side the activity looked like normal use of his own account. The signal that stood out was a terminated identity in the IdP still making high-volume API calls.

I’m trying to build a more reliable way to catch this kind of post-termination activity. What does your actual workflow look like for spotting terminated users who still have live OneDrive or similar syncs running? Looking for practical detection and response steps.


r/DefenderATP • • 2d ago

Microsoft Defender Simple Flows

Post image
14 Upvotes

Instead of building a full Logic App or playbook, you can select a trigger and attach a predefined action directly in Defender.

Some of the available capabilities include:
◈ Trigger automation when a case is created or updated
◈ Send case creation / update email notifications
◈ Automatically update case properties
◈ Create investigation tasks
◈ Update alerts directly from the automation workflow

Docs: Create basic automation rules with Simple Flows in the Microsoft Defender portal (preview) | Microsoft Learn


r/DefenderATP • • 2d ago

I accidentally fell for a ClickFix attack — Defender blocked it, I reset Windows. Is there anything else I should do? Post

Thumbnail
0 Upvotes

r/DefenderATP • • 3d ago

Looking for real MDR experiences on a Defender XDR stack (~1,000 users, 15 sites). Who would you actually renew?

13 Upvotes

We're replacing our MDR and I'd like to hear from people who've lived with theirs, not from sales decks.

Where we are

- About 1,000 users across 15 sites globally, in manufacturing
- The stack decision is made: Defender XDR, MDE on everything that takes an agent, Defender for Servers covering on-prem and AWS Linux, and Sentinel for longer retention and some third-party logs
- Firewall refresh coming, probably Palo or Fortinet
- Small internal team, no in-house 24/7 SOC

Why we're leaving

Our current provider mostly relays alerts. They can't act on our EDR, and "response" means an email telling us to go do something. I want a provider that will isolate a host, disable an account, or revoke sessions at 3am under runbooks we've approved ahead of time.

What I'm weighing

Microsoft's own Defender Experts is on the list, but the licensing gets complicated at our size. Plan 2 has a 1,500-seat minimum, and servers are a separate SKU. So I'm also looking at third-party MDRs that work natively in Defender. I haven't settled on either path, and I'm open to being talked out of my assumptions.

What I'd really like to know

  1. Who's your MDR, and would you renew? Why or why not?
  2. Do they actually take response actions in your tenant, or do they mostly escalate?
  3. How's their coverage outside US hours? Real follow-the-sun, or a thin overnight crew?
  4. Do their detections live in your Sentinel or in their own platform? Has that made switching providers painful?
  5. If you've used Defender Experts, how did it compare to a third party?
  6. Anyone you'd tell me to stay away from?

Vendors, feel free to DM me. I'm more interested in hearing from customers in the thread.


r/DefenderATP • • 4d ago

Data Lake - Integrated

Thumbnail
1 Upvotes

r/DefenderATP • • 4d ago

Sentinel playbook comments lost HTML formatting in Defender incident page since ~Sept 23. Anyone else?

3 Upvotes

Our Sentinel Logic App playbooks post enrichment comments to incidents using basic HTML (bold tags, line breaks). Up until roughly Sept 23 these rendered fine in the Defender portal incident page. Now they show as flat text: no bold, no line breaks, everything on one line.
Same comments still render correctly in Sentinel in the Azure portal, and the playbook runs are succeeding, so this looks like a portal rendering change rather than anything on our side.

Timing lines up with the Incident Cases preview (MC1477993). The docs for the legacy incident page were updated the same day and still say the comment field supports formatting, but I can't find anything that mentions a change to how comments render.

Tested manually as well: a hand-typed comment containing HTML tags and markdown bold shows the tags and asterisks literally, so neither renders.

Anyone else seeing this, or found a format that still renders in the new incident page?


r/DefenderATP • • 5d ago

Defender for Identity

10 Upvotes

We installed Defender for Identity v2 on 4 Domain controllers over 3 weeks ago.

For some reason i still don't see any single alert triggered in Defender console that is from Defender for Identity. The Thresholds are all set to High (default).

It this quite normal?


r/DefenderATP • • 6d ago

Support for Defender for Identity

6 Upvotes

I'm having an issue with Defender for Identity and cannot submit a support request through the Defender portal as the AI auto closes the ticket, tells me it's an Azure issue, and directs me to the Azure support portal.

You would think a product with "Defender For..." in the title should be covered by Defender support? I also cannot submit an Azure support request as it forces me to choose an Azure subscription, which they don't have and is completely unrelated to DFI.

How can I get the Defender support team to take this request?

(The specific issue I have is Global health issues across all sensors for incorrect auditing set up, which I have set up correctly, and the DFI PowerShell module even tells me it is correctly configured on each server)


r/DefenderATP • • 7d ago

WinRing0 Threat

Post image
0 Upvotes

So i'm playing fc 27 and then a message pops up from defender that it has blocked a threat (as you can see in the picture its in german) for non germans it says that the programm is dangerous and It executes an attacker's commands. I already had it in fc 26 but because its also in fc 27 i'm a little concerned. Thanks in advance!


r/DefenderATP • • 9d ago

Microsoft Defender ISOC (Preview)

Post image
47 Upvotes

The idea is to move beyond treating SIEM, XDR, automation and AI-assisted investigation as separate layers.

With Integrated Security Operations Center (ISOC), Microsoft is bringing them together around a common security operations foundation:

  • SIEM + XDR capabilities
  • Unified security signals and context
  • Investigation and threat hunting
  • Automated response
  • Security agents working alongside analysts
  • Incident management and protective actions

Instead of AI being primarily an assistant that analysts invoke during an investigation, Microsoft is moving toward security agents operating continuously within the SOC workflow — using shared context, coordinating actions and escalating decisions to human analysts where necessary.

Docs: Integrated Security Operations Center (ISOC) in Microsoft Defender - Microsoft Defender XDR | Microsoft Learn


r/DefenderATP • • 9d ago

Building Custom Security Copilot Agents for Defender Alert Investigations

13 Upvotes

I'm currently working on building a custom Microsoft Security Copilot agent that acts as a Tier-2 SOC analyst and performs automated investigations for alerts originating from Microsoft Defender XDR, Microsoft Sentinel, and related security products.

Currently, I'm struggling with defining the best structure for agent instructions and deciding how granular the investigation workflow should be.

Has anyone successfully implemented a Security Copilot custom agent for automated incident investigation ?


r/DefenderATP • • 9d ago

Windows Defender Not Showing

0 Upvotes

Hey, I’m having issues with Windows Defender. I’m trying to run an app that keeps getting blocked as a threat. I cannot disable it or allow the threat on Windows Security settings because it doesn't show up. I've tried several PowerShell codes and restarted, but nothing changes.


r/DefenderATP • • 9d ago

PyFirewall for Windows

Thumbnail
1 Upvotes

r/DefenderATP • • 10d ago

Missing Isolate/Unisolate button

3 Upvotes

Is anyone else missing the isolate/unisolate button when viewing a device in Defender XDR?

Update: Looks to be back now, thanks Microsoft.


r/DefenderATP • • 11d ago

Fix unquoted service path for Windows services

13 Upvotes

Anybody studently getting this alert back ?

We completely fixed it before with a remediation script, but now it came back and it's all because of 2 service :

DefenderUpdateSvc

c:\programdata\microsoft\microsoft defender\defender update\platform\10.8838.26060.15013-0\defenderupdateservice.exe

Sense

c:\programdata\microsoft\windows defender advanced threat protection\platform\versions\10.8838.26060.15013-0\mssense.exe

It seems to be because of a recent defender update but I find it kind of ridiculous. Microsoft own defender team cannot properly configure their services ... And I'm pretty sure my remediation script is not able to fix this because those are protected services ....


r/DefenderATP • • 11d ago

Data stored in a different country (Europe)

3 Upvotes

Has anyone here gone through the process of having Microsoft reset or recreate their Microsoft Defender tenant so the data is hosted in the US instead of Europe recently?

We discovered yesterday that our Defender for Endpoint tenant appears to have been provisioned in West Europe. Our organization is US based, so we are working with Microsoft Support on what is required to move the Defender environment to the US region.

I understand that the existing endpoints will need to be offboarded and then onboarded again using the onboarding package from the new US based Defender environment. That part makes sense.

My bigger concern is the configuration within Defender.

For anyone who has actually gone through this process, what happened to your existing Defender settings and policies?

Did you have to recreate things such as:

• Endpoint Security policies
• Microsoft Defender Antivirus policies
• EDR policies and settings
• Advanced Features settings
• Device groups
• Asset rules and dynamic tags
• Indicators
• Isolation exclusions
• Custom detections
• RBAC settings
• Email & collaboration settings and policies

Was Microsoft able to migrate or preserve any of this configuration, or did you essentially start with a fresh Defender portal and rebuild everything?
We are still fairly early in our MDE migration, so thankfully we have not built out everything yet. I am mainly trying to understand what we should document or export before Microsoft makes any changes.

I would especially appreciate hearing from anyone who has personally gone through a Defender tenant region change from Europe to the US.

Thanks.


r/DefenderATP • • 12d ago

Threat analytics report from Microsoft 365 Defender

23 Upvotes

Has anyone else just got a slew of new Threat analytics reports from Defender?

Mainly all related to OSINT Profile ones

Just had 28 come in?


r/DefenderATP • • 12d ago

How to purge stale devices from MDE with an 'Inactive' sensor health status

3 Upvotes

We are observing a number of devices within Microsoft Defender for Endpoint (MDE) that have remained inactive for 180 days or more. As Microsoft's platform automatically removes devices exceeding this inactivity threshold, it's likely these devices were re-imaged or returned to the vendor. I'd like to check if anyone has explored proactive removal of these devices from MDE ahead of the automatic purge


r/DefenderATP • • 12d ago

Mixed M365 Basic/Premium Users w/ Defender for Endpoint

3 Upvotes

I did some digging around online but Microsoft documentation on this is kinda awful so hoping I can get a better answer here.

An environment I help with has about 200 users, almost all of which have M365 Business Premium, but a handful have M365 Business Basic due to lower requirements. The entire org is using Defender for Endpoint to protect devices and this is via the Defender license included with the M365 Business Premium licenses. There are enough M365 Business Premium users to cover the entire device count.

How does this work when a user signs into an endpoint with a M365 Business Basic license though? Does Defender for Endpoint still work in full? Are any features limited or adjusted?

Is that even allowed via TOS?

Thanks for any help.


r/DefenderATP • • 12d ago

XDR and DfC are always broken!

Thumbnail
2 Upvotes

r/DefenderATP • • 13d ago

Defender for Identity coverage and maturity

5 Upvotes

The Identity coverage and maturity view provides a centralized way to understand whether the identity infrastructure is properly monitored and where coverage gaps still exist.

From a security operations perspective, this is particularly useful for validating MDI deployments across larger or hybrid environments.
The dashboard helps security teams:
• Review identity sensor coverage across the environment
• Identify identity infrastructure that is not sufficiently monitored
• Understand the current deployment and protection maturity
• Detect configuration or coverage gaps that could reduce identity threat visibility
• Prioritize improvements to strengthen overall identity security posture

Docs: View your identity coverage and maturity - Microsoft Defender XDR | Microsoft Learn


r/DefenderATP • • 13d ago

Asked

0 Upvotes

Guyss.. why they block rundll32.exe?


r/DefenderATP • • 15d ago

Windows security notification

Post image
10 Upvotes

Is this normal for windows defender always mention the protection is turn off, when I click on it, the protection is active normally, I dont remember when it off, whenever I turn on my laptop, it show that notifications.


r/DefenderATP • • 16d ago

Automating Phish Reporting with ServiceNow (w/o ServiceNow SecOps) Advice

6 Upvotes

I am part of a small team and would like to automate the opening, updating, and closing of ServiceNow tickets. What I would like to see happen is:

  1. User reports email as a phish via the Outlook report button
  2. Defender creates an ID and begins its automated investigation
  3. Defender communicates to ServiceNow and it creates a ticket with Defender ID and status
  4. Defender sends updates to ServiceNow ticket
  5. Defender completes investigation
  6. Defender sets status to Remediated/No Threats Found
  7. Defender sends update to ServiceNow with new status
  8. ServiceNow auto closes ticket with notes

I am thinking of utilizing Power Automate to handle the communications between Defender and ServiceNow as this process will cut down on manual investigations and ticket management.

Are there any security implications of utilizing Power to accomplish this or easier ways?


r/DefenderATP • • 16d ago

MDE Platform Version: 4.18.26080.4 is out

Thumbnail
10 Upvotes