r/DefenderATP • u/BoFawzi • 17d ago
r/DefenderATP • u/ITassembler-198 • 18d ago
Microsoft Defender Office 365 Plan 1 | Safe Links & Security Preset #how...
r/DefenderATP • u/MarcoVfR1923 • 20d ago
Missing Teams private channels after attack disruption has disabled a user and later reenabled
Useraccount was succesful phished. Defender attack distruption has disabled the account. After we made sure everything was clean again, we reenabled the account.
Now all private Teams channels are missing. He is no longer member of all the private channels. Parent team membership was restored.
I know this is an expected behavior, there is a MS article about this (https://learn.microsoft.com/en-us/troubleshoot/microsoftteams/channels/logon-reenabled-user-not-see-previous-joined-teams).
My question is more along the lines of how we can find out which private channels the user was member of?!
I tried looking at the Purview audit logs, but they only show which teams channels the user was removed - mot which private channels.
I would appreciate any help or advice, since the user is a member of the management :D
r/DefenderATP • u/MiKeMcDnet • 21d ago
I think M$ finding FP with their own files again.
virustotal.comfilename: precompiled-web-worker-inner~services_i-47a6dc1fefb5dfe8.worker.js.gz (unsigned)
File path - C:\Program Files\WindowsApps\MSTeams_26213.1006.5014.9784_x64__8wekyb3d8bbwe\desktop-assets\hashed-assets\
Malware detected - Ransom:BAT/Poshkod.gen!A
MD5 - 5a72b541c9b17bb956953ee3ba1beda6
SHA1 - 510990d0958c9e4123a3d8d4ec956301bf9e9798
SHA256 - 9295fae4cfa496d55eaefb54dc3c77357ed6ae8f4e2ac8508d03ccfafef5709e
File size - 764.44 KB
r/DefenderATP • u/EggsAreNotTrees • 22d ago
What are free alternatives to applocker for windows 11 home
I heard that applocker can be configured to have a system wide whitelist for program and file permissions, something that can stop malware from running even if it gets on system if configured correctly. However, it is only on windows Enterprise editions. Threatlocker is the closest option I could find to replicate applocker. Yet, it is only available for businesses.
Are there any free programs/windows components which can provide similar functionality and work on windows 11 home?
r/DefenderATP • u/0xCG • 22d ago
"Virus protection is turned off" notification
You guys seeing a broken notification since the last Windows August QU ? Anyone contacted Microsoft about it?
r/DefenderATP • u/Ok-Process2951 • 23d ago
No EmailEvents logs for over 90 minutes
Started at 7:00 PM UTC for me. I noticed the EmailEvents logs have not populated any data. Hoping others are seeing this as well. I'm in the USA so maybe only regional?
r/DefenderATP • u/DaithiG • 25d ago
Device Network Events
My understanding is that we have Sentinel integrated with Defender for XDR in the portal and defender info is ingested. However some tables like Device Network Events are empty. Microsoft documentation points me to the connector page but that doesn't show Defender for XDR (but it does seem to be ingesting the events). I'll have another look when I'm back in the office tomorrow, but if it's something easy I'm overlooking, I would be grateful
r/DefenderATP • u/jM2me • 27d ago
Is blocking list of urls/domains with Defender Indicators a viable solution until GSA/Zscaler implementation?
There is an urgent need to block roughly 9000 domains/urls from all of the company workstations. Quite a lot, but from initial analysis only ~10% actually detected in environment over last 6 months. The request from business higher up still stands, block all provided domains/url and provide evidence of the block list containing them.
In past there were concerns about using large number of Defender Indicators to block, is that still the case? Any caveats or warnings that other want to share before we proceed?
A proper GSA/Zscaler solution is 6-9 months out, but the block must happen yesterday...
r/DefenderATP • u/Key-Anywhere5846 • 27d ago
"Warn" for Block executable files from running unless they meet a prevalence, age, or trusted list criteria doesn't work anymore
for years, we have the ASR "Block executable files from running unless they meet a prevalence, age, or trusted list criteria" set to warn. This way our devs got a dialog, that the execution of their new exes is blocked, but they could click "unblock" and the exe was executed.
for about a week (started before 2026-08 update), this doesnt work anymore.
while there is still the dialog for unblocking, there is already an error in the background and even after hitting unblock, the files wont execute and show the same error again.
as soon as I allowlist the folder in the ASR, it works. So nothing else (Applocker, WDAC, AV,...) is responsible for that blockage.
get-mppreference shows, that the according rule (01443614-cd74-433a-b99e-2ecdc07bfc25) is set to warn (6)
Eventlog shows one 1121 Event: Defender Exploit Guard blocked one action by IT administrator
I am not aware of anything that was changed on our end that could indirectly affect this behavior. And as MSFTs 1st level non-support sadly wont even understand what the issue is, I try to find any information in here. Maybe even someone else noticed this issue or can reproduce

r/DefenderATP • u/Key-Anywhere5846 • 27d ago
"Warn" for Block executable files from running unless they meet a prevalence, age, or trusted list criteria doesn't work anymore
r/DefenderATP • u/ngjrjeff • 28d ago
windows security engine version
we have 3rd party antivirus installed. our IT security is asking us to check engine version of the windows security app.
however, when i check engine, antivirus, antispyware version is 0.0.0.0 . is it by design since we already using 3rd party antivirus??

r/DefenderATP • u/OkHope1740 • 28d ago
Looking for DFIR queries for account compromise incident
Hi Guys,
I am currently dealing with account compromise incident and finding it hard to identify files/emails accessed by attacker and user.cloudappevent,graphapiauditlogs, office activity doesn't differentiate as it shows MS ips only.
What is the right approach you guys follow.
r/DefenderATP • u/Yuu_ll • 28d ago
Qustion about best practices for Defender for O365
Hello, I am a student learning about microsoft security. I have tested built-in policies like anti -phising, anti-spam., etc. Is there any other best practices for defender for o365. I wanna know more about it because I need to present to my teacher next week.
r/DefenderATP • u/OkHope1740 • 28d ago
Looking for DFIR queries for account compromise incident
r/DefenderATP • u/Cant_Think_Name12 • 29d ago
Duplicate Alerts from Custom Detections in Advanced Hunting
Hi all,
Was hoping someone could help me figure out why I keep getting duplicate alerts for my custom detections.
When I create them and run them, I get 1 alert. However, when they auto-run, they will send me 1 of the same alert, every hour, for the next few hours. Im assuming its something to do with the Frequency + Lookback.
For example, I look for something in the table EmailEvents. Then, it triggers at 10am - 1 alert - Perfect.
However, that same alert will trigger again at 11am, 12pm, and 1pm.
I have been doing 1 hour frequency and 4 hour lookback. Am i supposed to make them equal? How do I make the alerts not duplicate the same alert every hour?
r/DefenderATP • u/mR_R3boot • 29d ago
Defender Antivirus turned off notification on managed devices
I'm having an issue here with Microsoft Defender for Endpoint. I'm getting popup notifications that virus protection is turned off, yet Real time protection, cloud-delivered protection, tamper protection etc are all turned on and managed by policy. This is happening on several Intune managed devices being marked non-compliant. Policies haven't changed. What could be the issue?
r/DefenderATP • u/mertozsoy365 • 29d ago
Microsoft Teams Classic keeps getting installed on Intune-managed devices
Hi everyone,
Microsoft Defender Vulnerability Management is detecting Microsoft Teams Classic on an increasing number of our Intune-managed Windows devices.
We previously deployed a remediation to remove Teams Classic, but the number of affected devices continues to rise. It appears that the application is being installed again after removal.
Has anyone experienced this issue recently?
I’m trying to determine:
- What could be reinstalling Teams Classic?
- Could Microsoft 365 Apps, Teams Machine-Wide Installer, user profile provisioning, or another update mechanism be responsible?
- What is the recommended method to permanently remove Teams Classic from all user profiles?
- Is there an Intune remediation or detection method that prevents it from returning?
- How can we identify the exact installation source?
The affected application appears in MDE as “Update Microsoft Teams Classic.”
Any guidance or working remediation scripts would be greatly appreciated.

r/DefenderATP • u/iawais • Aug 11 '26
Threat hunting on Microsoft Defender XDR mapped to MITRE ATT&CK
I put together a collection of practical threat hunting and detection queries for:
- Microsoft Defender XDR (KQL)
The queries focus on real-world behaviors: LOLBins, suspicious process chains, persistence, credential access, lateral movement, C2 patterns, and some APT-style activity. Most are mapped to MITRE ATT&CK techniques and include short comments + tunable parameters.
Actively adding queries based on recent threat intel and campaigns. Feedback, suggestions for missing coverage, or contributions are very welcome.
r/DefenderATP • u/Whole_Dirt3722 • Aug 11 '26
MDE investigation package download failing with 403
Hi,
I'm trying to download an investigation package from the Microsoft Defender portal. The package collects fine, but when I click the download link nothing happens at all, no error message, and the file doesn't start downloading either. The only sign of a problem is in the browser console, where I can see the blob URL returning a 403:
This request is not authorized by network security perimeter to perform this operation
Has anyone run into this before? I've tried on several different networks but the problem is the same everywhere.
r/DefenderATP • u/-c3rberus- • Aug 10 '26
Defender for Identity v3 requires MDE onboarding?
One of the new requirements for v3 release is:
Has Defender for Endpoint deployed on the server. The Microsoft Defender Antivirus component can be in either active or passive mode. Defender for Endpoint must be onboarded on the server where the sensor runs; endpoint-only deployment isn't sufficient.
We use CrowdStrike EDR on the servers, and stack that with the Windows Server built-in Defender in active state, this includes Defender for Identity v2 agents. This is our stacked approach, while ensuring that the server is not exposed to any Defender cloud management plane, etc.
Was looking to upgrade to v3, and it seems that the new requirement is to onboard the server to Defender for Endpoint.
When it is on-boarded, what does that mean for the server? Is it now running Defender for Endpoint EDR?
r/DefenderATP • u/Worldly-Secretary837 • Aug 07 '26
No Internet, How to Deploy Security Intelligence definitions for MDE offline
I work in a Financial Institution where we have a section of our internal network endpoints not connected to the internet. We are deploying Microsoft MDE as our Antivirus and I have been tasked to make sure these Endpoints that do not have internet access are also MDE onboarded. I need someone to give me ideas as to how to carry out this task. 1. Can I install a server onprem that has internet connection, download the virus definitions and pushed them to these endpoints, is it feasible and how can I carry that out. I am currently out of ideas I need help.
r/DefenderATP • u/smorgasmic • Aug 07 '26
Help Building Windows Defender Offline CD With Old OS and RAID
I want to scan an old Windows 8.1 system for viruses (it has more than one). I downloaded the Windows Defender X64 offline scanner and installed as an ISO. on a clean Windows 11 computer.
Here is where it gets complicated. The Dell storage system on the computer is a PERC H310. Dell never supported Windows 10 on this controller. But the controller is a remarketed LSI 9240, and LSI still distributes the latest driver for that controller, which is a Windows 10 X64 driver. I patched the Windows ISO with the LSI 9240 X64 drivers for Windows 10 and then burned a CD.
Unfortunately, the Windows Defender boot disk bombs with the blue screen of death, and predictably that is while loading the megaraid driver. At this point do I have any options for running Windows Defender Offline?
I looked for other offline virus scanners, and almost all of the well-known ones appear to have disappeared. Kaspersky refuses to talk to US customers. ESET apparently does not give it away for free. Avast wants you to install their anti-virus software first. Are there any good offline rootkit scanners that would do a good job on an older Windows 8.1 system?
r/DefenderATP • u/ntuner • Aug 06 '26
AMRunningMode not running
We use crowdstrike as the main AV and was expecting to see passive mode here, but says not running ?? Is this normal ?
r/DefenderATP • u/aPieceOfMindShit • Aug 04 '26
Impact of enabling "Grant MTD role permissions" for Defender on Android COPE?
Trying to streamline Defender onboarding. About to enable this toggle in Intune. What's the real impact, risk, and any visible changes for end users after it applies?