Tracking Defender Antivirus Scans with Log Analytics Insights & Actionable Steps

March 20th, 2025 → 6:25 am @ // No Comments

Microsoft Defender for Endpoint provides powerful antivirus scanning capabilities, but how do you ensure that full scans are occurring regularly across all devices? With Log Analytics, you can track antivirus scans, analyze trends, and take action if full scans are not happening often enough. In this post, we’ll walk through how to use Kusto Query Language (KQL) to pull Defender Antivirus scan reports, interpret the data, and adjust configurations to ensure optimal security coverage. Enable Data Collection from Defender for Endpoint To start logging Defender scan events, you need to configure Microsoft Defender for Endpoint to send data to Log Analytics. Step 1: Configure Defender Data Streaming Go to Microsoft Defender Portal Open Microsoft Defender Security Center. Navigate to Settings > Endpoints > Advanced features. Enable Microsoft Defender for Endpoint Raw Data Streaming. Enable Defender for Endpoint Data Connector in Sentinel If you’re using Microsoft Sentinel, you can enable the […]

Cybersecurity

SMS Or an Authenticator App – Which One Is More Secure?

January 9th, 2025 → 1:17 am @ // No Comments

In the world that we live in today, simply using a password is not enough.  Although it has been the most widely used mechanism for authentication, it suffers from many flaws that the Cyberattacker can take advantage of quite easily.  Thus, many businesses today are now requiring their employees and contractors to submit through a procedure called Two Factor Authentication, also known as 2FA. This is where you confirm identity through at least two means, such as a password, and something that is stronger, such as Smart Card, an RSA Token, or even a One Time Password (OTP). With the latter, this is often sent via a text message (also known as SMS) or authenticator app on your smartphone. So now the question becomes, which is method is the more robust to use?  We will further explore this. The SMS This is an acronym that stands for “Short Message Service”.  […]

Cybersecurity

Understanding Azure Recovery Service Vaults (RSVs) : Ensuring Secure and Reliable Backup Solutions By Tulasi Nakka

December 11th, 2024 → 8:05 am @ // No Comments

In today’s digital landscape, safeguarding data is paramount. Azure Recovery Services Vaults (RSVs) play a crucial role in protecting sensitive information and ensuring business continuity. This blog will explore what Recovery Services Vaults are, the different types available, essential settings to configure, and key results to monitor for optimal backup management. What Are Recovery Service Vaults (RSVs)? Recovery Services Vaults are Azure-based storage entities designed to manage and store backups and site recovery data. They provide a unified experience for configuring backup policies and recovery points, making it easy to protect data for Azure Virtual Machines (VMs), SQL databases, on-premises servers, and more. RSVs are essential for ensuring data recovery in case of accidental deletion, corruption, or other data loss events. Understanding the Components of RSVs To better understand how RSVs function, it’s essential to look at the key components and their roles, along with how they relate to backup […]

Cybersecurity

A Review of The Public Key Infrastructure

December 10th, 2024 → 7:10 pm @ // No Comments

As digital assets become even more interconnected with each other, the need to make sure that any information and data that is transmitted to and through them are difficult to intercept by the Cyberattacker. One area that is being used quite heavily in this regard is known as Encryption and is a branch of Cryptography.  This is where that information and data is scrambled into a meaningless state, so that if it were to be heisted, there is nothing that can be done with it.  The only way that it can be rendered back into a meaningful state so that it can be decipherable is using the Private Key.  PKI is becoming a more important security configuration now that Microsoft has added PKI license options for organizations that use Microsoft Intune. What Is The Public Key Infrastructure (PKI)? PKI can be technically defined as follows: “Public key infrastructure (PKI) is […]

Cybersecurity

Enhancing Device Security with Guard+: A Comprehensive Overview of Policy Configurations

November 5th, 2024 → 11:29 pm @ // No Comments

By Tulasi Nakka Introduction In today’s increasingly complex digital landscape, organizations must adopt security measures to safeguard their systems and data. Device configuration policies play a pivotal role in maintaining secure and compliant environments, particularly by setting baseline configurations for endpoints such as Windows and iOS devices. These policies ensure that security configurations, such as antivirus scanning, attack surface reduction (ASR) rules, and system update controls, are consistently applied across all organizational devices. What Are Device Configurations and Why Are They Important? Device configurations are predefined policies and settings applied to devices to ensure they adhere to security and compliance standards set by the organization. These settings manage critical security features like firewalls, encryption, antivirus, and more, establishing a uniform security posture across all devices within a network. Device configuration policies help organizations safeguard against vulnerabilities by ensuring every device meets baseline security requirements, no matter where or how it’s […]

Cybersecurity

An Introduction To The DMARC

September 27th, 2024 → 9:46 pm @ // No Comments

Email Security Protocol When compared to the late 90’s when the first major Phishing attack occurred on AOL, there are many tools and mechanisms that are now available at your disposal to keep suspicious email from reaching into your inbox.  Although M365 and Microsoft Azure offer a plethora of offerings, there is yet another one which should not be ignored:  DMARC. What Is DMARC? It is an acronym that stands for “Domain-based Message Authentication, Reporting and Conformance”.  Simply put, it is like any other email protocol that you may have encountered before, but it is unique in the sense that it does a highly effective job in blocking suspicious email from entering your email system.  It is powerful enough that even traditional Spam based filters will reject any acceptance of it, and just ignore it. But a huge benefit of it is that DMARC can be installed and custom configured […]

Cybersecurity

Ensuring Email Deliverability

September 8th, 2024 → 11:01 am @ // No Comments

In a recent article, we examined some of the key issues that are involved with sending bulk emails to your prospects and customers.  Probably one of the worst consequences you can face is that of being completely blacklisted, where your domain is no longer accessible to the outside world. In this article, we look at some other ways to make sure your emails get through. What Are The Other Methods? Some of the newer methods that you have to use now, especially if you make use of your personal email accounts to send bulk emails, most notably from Yahoo and Google (Gmail), are as follows: Keeping a threshold: Most Internet Service Providers (ISP’s) also usually provide email services along with your web hosting account.  They too are leery of having their account holders sending out too many emails which get marked as “Spam”.  As a result, they have established thresholds […]

Cybersecurity

Streamlining Endpoint Security: Mastering Software Inventory on Your Devices

September 6th, 2024 → 10:08 pm @ // No Comments

by Tulasi Nakka In today’s digital landscape, it’s crucial to maintain visibility over the software installed across an organization’s devices to ensure security and compliance. The challenge lies in the vast amount of data and the limited tools available for analysis. Guard+ was developed as a tool for Managers and senior security analysts to provide a fresh perspective on an organization’s security. By effectively tracking critical details such as software names, versions, vendors, and associated devices, IT administrators can preempt potential vulnerabilities and ensure compliance with regulatory requirements. This level of monitoring enables organizations to mitigate risk, enforce security policies, and maintain an up-to-date inventory of all software deployed across their infrastructure. Guard+ already enables visibility into device compliance. It allows you to identify software that requires upgrades, patches, or, in some cases, removal. This new feature in Guard+ enhances the capabilities of Managers and security analysts by providing a […]

Cybersecurity

Are Business Premium Licenses Adequate for Security?

August 17th, 2024 → 7:43 am @ // No Comments

When it comes to selecting the right Microsoft 365 license for your business, understanding the security features and limitations of each option is crucial. Microsoft 365 Business Premium is designed for small to medium-sized businesses, while the Enterprise E3 and E5 licenses cater to larger organizations with more complex needs. Let’s break down the key differences to help you make an informed decision. Microsoft 365 Business Premium Designed For: Smaller businesses on a budget. Features: Office apps (Word, Excel, PowerPoint) Email and calendaring Microsoft Teams OneDrive SharePoint Basic security features like Microsoft Defender for Office 365 Limitations: Limited to 300 users Lacks advanced security, compliance, and analytics features found in the Enterprise plans Microsoft 365 Business Premium provides essential tools and basic security for smaller businesses. However, its limitations in advanced security and compliance make it less suitable for organizations with more stringent security requirements. Microsoft 365 Enterprise E3 Designed […]

Cybersecurity

Maximizing Security with MFA: What Your Sign In Reports Reveal

August 14th, 2024 → 8:00 pm @ // No Comments

By: Tulasi Nakka Introduction In today’s digital age, robust security is more crucial than ever, with cyber threats growing increasingly sophisticated. One of the most effective ways to protect sensitive data is through Multi-Factor Authentication (MFA), which adds an extra layer of security by requiring multiple forms of verification. This article explores the importance of MFA in modern cybersecurity. By analyzing key metrics from our User Sign In Reports, we gain insights into MFA’s effectiveness, identify potential vulnerabilities, and make informed decisions to enhance our defenses. Whether you’re an IT professional or simply interested in digital security, this article provides essential insights into the role of MFA in safeguarding your digital assets. What is MFA and Why is it Important? Multi-Factor Authentication (MFA) is a security measure that requires users to provide two or more verification factors to gain access to a resource such as an application or an online […]

Cybersecurity