Housekeeping with Defender for Identity – finding unassinged AD subnets using the IdentityLogonEvents table
Find clients authenticating from unassigned AD subnets – using Defeder for Identity
https://f12.hu/2024/10/25/find-clients-authenticating-from-unassigned-ad-subnets-using-defeder-for-identity/
Hunting for report-only (Microsoft-managed) Conditional Access impacts
Evaluating report-only Conditional Access impact is very straightforward when Entra ID logs are streamed to Log Analytics. Those who can’t have this feature enabled can still use the AADSignInEvents beta table in Defender to find some extra insights.
https://f12.hu/2024/01/17/hunting-for-report-only-microsoft-managed-conditional-access-impacts/
Conditional Access Gap Analyzer – without Log Analytics Integration
Recently, John Savill* uploaded a video on this very cool feature and I thought to give it a try when I realized I have no Log Analytics integration enabled, so no Workbooks for me 🙁[*big fan of John’s videos, pure gold] This is not fair to those who only use Microsoft 365 products or who […]
https://f12.hu/2023/09/03/conditional-access-gap-analyzer-without-log-analytics-integration/