Microsoft Defender for Identity Inc FULL DEMO

Поділитися
Вставка
  • Опубліковано 10 гру 2023
  • In this episode I take a deep dive into Microsoft Defender for Identity. Including a full demo on how to set it up and configure it. I’ll also show a demo of an Advisory In the Middle Attack AiTM and demonstrate how Microsoft’s XDR platform can not only detect these attacks but how AI & machine learning can help thwart such attacks by undertaking a constant behavioural analysis of every user and their login attempts. This is a session packed with demos, so if you’re preparing for certification or simply looking to learn. Then this will be an invaluable session for you.
    For more details on me visit Andymalone.org
    If you want access to exclusive content and more why not consider supporting me and join me on Patreon. / andymalonemvp

КОМЕНТАРІ • 43

  • @luizhenriquecenturiao9794
    @luizhenriquecenturiao9794 7 місяців тому

    Really exciting to be part of the 100k milestone!! Much more coming, you deserve it!

  • @ChristopherNealBUSHIDO49ERS
    @ChristopherNealBUSHIDO49ERS 7 місяців тому +1

    As always thank you so much, Andy. Cheers!

    • @AndyMaloneMVP
      @AndyMaloneMVP  7 місяців тому

      You’re very welcome, and thank you 👍

  • @robbybatong8050
    @robbybatong8050 7 місяців тому

    Just Subscribed :) Merry Christmas Andy

    • @AndyMaloneMVP
      @AndyMaloneMVP  7 місяців тому

      Likewise and thanks so much👍😊🎄🎄🎄

  • @GoreGamer
    @GoreGamer 7 місяців тому

    I just wanted to extend a heartfelt thank you for your series of videos. Back in 2016, when I was working as an admin, Microsoft's constant rebranding and renaming made it quite a labyrinth to navigate through. Your videos, with their clear and concise approach, have been a beacon of clarity for me. The bite-sized format is perfect for understanding complex topics without feeling overwhelmed.
    Now, as I've transitioned to working for a non-profit, and we're in the midst of shifting over to MS365, your videos have become an invaluable resource. They've greatly simplified the migration and rollout process, making what could have been a daunting task much more manageable. Your insights and straightforward explanations have not only helped me but also my entire team in adapting to the new system.
    I cannot emphasize enough the significant influence your work has had on our organization. Your commitment to demystifying the administration of MS365 and making it approachable for everyone is truly praiseworthy. Thank you once more for your priceless advice and steadfast support throughout this journey! TPR Thanks you!

    • @AndyMaloneMVP
      @AndyMaloneMVP  7 місяців тому +1

      Thanks so very much for your kind comments they’re very much appreciated and I’m delighted to have you on board 👍 😊

  • @ryngrd1
    @ryngrd1 7 місяців тому +1

    Subscribed 👍let's get it!

  • @user-jp1gp2qv8b
    @user-jp1gp2qv8b Місяць тому

    Big like and a comment, that is a great video. thanks

  • @ioannisskouras5283
    @ioannisskouras5283 7 місяців тому

    Andy that was really great, clear instructions which helps you to understand the deployment. What it would be great (if this possible) is to create a video where you will translate the security features of M365 what business needs fulfill, like talking to c-levels-decision owners. What conditional access, intune, defender,etc mean for their business describe some benefits with real time examples . I hope my comment was clear. Thanks again for the great work.

  • @patrick__007
    @patrick__007 7 місяців тому +1

    Thanks again Andy! 100K subscribers come on!!

  • @ACrispiels
    @ACrispiels 7 місяців тому +1

    Thank you Andy for this new short demo but one more time the license requirements do not meet small companies, too bad...

  • @pramodkrishna5364
    @pramodkrishna5364 5 місяців тому

    Thanks for the wonderful explanation Andy. Just wanted to check with you.. do we need to enable Sentinel Logging or Does it automatically log the incidents post configuring the Defender for Identities? Because i saw something like we need to enable syslog which instead integrates with Sentinel. Please explain..

    • @AndyMaloneMVP
      @AndyMaloneMVP  5 місяців тому

      You will need to enable Azure log analytics. Gather data you will then connect to your various data sources using the connectors at the bottom left-hand corner. Be careful though over monitoring can be a pricey affair 😊

  • @KayKas007
    @KayKas007 4 місяці тому

    Hi Andy, two questions - 1. when this is deployed, will there be downtime? If yes, roughly how long? 2. Are there any visible changes from the users point of view? Thank you

    • @AndyMaloneMVP
      @AndyMaloneMVP  4 місяці тому

      You can install it on multiple domain controllers, thus reducing the possibility of downtime.

  • @fbifido2
    @fbifido2 7 місяців тому

    @4:42- if you have more than one server, will you use the same key?

  • @KayKas007
    @KayKas007 5 місяців тому

    Hi Andy, apart from the documentation on MS Learning, do you have any for this? I need advice on how to implement this. Thank you.

    • @AndyMaloneMVP
      @AndyMaloneMVP  5 місяців тому +1

      Peter Rising wrote a great book on Defender for Endpoint :-)

    • @KayKas007
      @KayKas007 5 місяців тому +1

      @@AndyMaloneMVP thank you. I got one on Amazon and it arrived today. Exciting times.

  • @fbifido2
    @fbifido2 7 місяців тому

    @1:28 - what if you don't have on-prem AD?

    • @AndyMaloneMVP
      @AndyMaloneMVP  7 місяців тому +1

      Then you don’t need defender for identity

  • @user-me7gm7fh2u
    @user-me7gm7fh2u 4 місяці тому

    We appreciate your videos on YT. I just had a look on your pateron page and found some nice courses. I hope you reconsider the prices especailly for those countries in Middle East and Asia. I believe more subscribour will join you patreon Silver & Gold. Training is a crucial for jounior and most of the comanies try to force the junior to pay from their own pocket which is not fair at all.

    • @AndyMaloneMVP
      @AndyMaloneMVP  4 місяці тому +1

      Thanks for your nice comment. Regarding the Patreon prices I think they’re very good value considering the list price of actually attending these courses is tenfold the price that I’m charging in addition remember you also get the monthly zoom call and can ask questions at any point.

  • @jimmyroels7604
    @jimmyroels7604 7 місяців тому

    Hello Andy, what happend with the computer screen recording? It's to blurry to watch, I'm sorry.

    • @AndyMaloneMVP
      @AndyMaloneMVP  7 місяців тому

      Blurry? Hmm not sure perhaps UA-cam rendering is a bit slow

  • @johnmeyers4378
    @johnmeyers4378 6 місяців тому

    I handle alerts and incidents from MDI in the Security portal on a regular basis. Although this protection is a must, I find the details provided in the alerts to be lacking in a practical sense. That is to say, I see alerts for say a suspicious login event/attempt, but nothing in the alert details or timeline explains exactly how the event was suspicious - nothing specific is highlighted in the event details. This is true for all other types of MDI alerts as well. And we are mostly just left reviewing AzureAD sign-in logs and asking other IT Admins about possible scheduled network maintenance, to inevitably just guessing if the event is something to worry about or not. There really is very little usable details in the MDI alerts.

    • @AndyMaloneMVP
      @AndyMaloneMVP  6 місяців тому

      I agree with you concerning the base alerts. However, you can create your own alerts and your own rules. Have you explored this? For more information check out learn.microsoft.com as this contains all the learning and documentation materials for this.

  • @Nimitz_oceo
    @Nimitz_oceo 7 місяців тому

    Hold on… did you says full courses for patreon members?

    • @AndyMaloneMVP
      @AndyMaloneMVP  7 місяців тому

      Yes, I record a module of full training and add it to my Patreon site every week courses up at the moment. Include SC 900 a security and compliance master class and SC 300.

  • @lassmirandadennsiewillja3943
    @lassmirandadennsiewillja3943 7 місяців тому

    i would love to see a Video of how to get Fslogics & office products to work while you roam through more than one Server. the tokens are always messed up at some point and you have to deal wit AADBroker Plugin and stuff. You even get a 1001 Error in Outlook and MS has no answer and says to use the owa as a Workaround. Well...No

    • @AndyMaloneMVP
      @AndyMaloneMVP  7 місяців тому

      Honestly, this is not one of my topics. Have you checked out John Savile’s channel as he specialises in Microsoft, Azure Operations. Whereas I tend to focus more on Microsoft 365. That said I will add it to my list and take a look. Thanks again.

    • @lassmirandadennsiewillja3943
      @lassmirandadennsiewillja3943 6 місяців тому

      @@AndyMaloneMVPthank you for your answer. It is really one of the main problems we have with ms. Since fslogix is also a microsoft product i do not understand that no one has the answer. Changing/add regkeys is no answer really. If you know someone who knows someone i would be very thankful.

  • @johnjoy322
    @johnjoy322 7 місяців тому

    great video man!!!!!! do like mickey mouse club

  • @user-sy6dh3ni4z
    @user-sy6dh3ni4z 6 місяців тому

    Hi everyone. I am looking for solution to restrict teams calls to C level executives from regular users. I have a E5 license attached to all C level and regular users also. Thank you for feedback 😊

    • @AndyMaloneMVP
      @AndyMaloneMVP  6 місяців тому

      Try posting this question on the Microsoft tech Community.

  • @mikegrady6089
    @mikegrady6089 6 місяців тому

    Andy one of things that are missing in most videos regarding Microsoft products are lacking in one key areas, licensing dependencies. Is Microsoft Defender for Identity included in any other licenses? Are parts of it included in other products, if so which ones? This is probably a simple question, but this holds true on most of the products that are show in UA-cam videos. Not picking on you.

    • @AndyMaloneMVP
      @AndyMaloneMVP  6 місяців тому

      I totally agree of course, most of the features I’m demonstrating are in A5 but are also often available in other skews. A great website for you to check out is M365maps.com. You can compare the different features and different plans. It’s an awesome site.

  • @laykside
    @laykside 19 днів тому

    Do I need to set the Windows service to log on as a service or a local account under services.msc?

    • @AndyMaloneMVP
      @AndyMaloneMVP  17 днів тому

      Using the service account, it’s always a good idea and of course it’s more secure