Windows Hello for Business Cloud Kerberos Trust | Part 1

The blog post discusses the deployment of Windows Hello for Business via the Cloud Kerberos Trust deployment model. Windows Hello for Business uses methods like cloud Kerberos trust for user authentication. Advantages include simplified deployment, reduced infrastructure, enhanced security, and seamless user experience. It involves setting up a Kerberos server object for cloud Kerberos trust, installing the Azure AD Hybrid Authentication Management module, and creating the Kerberos server object using Windows PowerShell.

Intune: Grouping based on Hardware Inventory data

It's been couple of years since I blogged a post. In the meantime, I moved to Intune Product Group as a Product Manager and now I'm a member of Grouping and Targeting team. One of the top blocker in grouping and targeting space is the lack of ability to group the managed devices based on … Continue reading Intune: Grouping based on Hardware Inventory data

Introducing Local Administrator Password Solution (LAPS) via Microsoft Entra ID and Intune

Introduction In today's digital age, securing sensitive information and managing access to critical systems is paramount. One aspect of this security is the management of local administrator passwords on Windows devices. Microsoft recognized the need for a secure solution to manage local administrator passwords and introduced the Local Administrator Password Solution (LAPS) a few years … Continue reading Introducing Local Administrator Password Solution (LAPS) via Microsoft Entra ID and Intune

The crazy IMPACT of the Data Lake

When we began building the security data lake solution, we had no idea that this solution would evolve and meet so many important needs for the enterprise. Most importantly, we found the solution is changing the way we approach security engineering. We didn't anticipate that we would be able to bring together multiple IT silos … Continue reading The crazy IMPACT of the Data Lake

The crazy IMPACT of the Data Lake

When we began building the security data lake solution, we had no idea that this solution would evolve and meet so many important needs for the enterprise. Most importantly, we found the solution is changing the way we approach security engineering. We didn't anticipate that we would be able to bring together multiple IT silos … Continue reading The crazy IMPACT of the Data Lake

Download the Microsoft Defender for Identity sensor

The Microsoft Defender for Identity (MDI) sensor can be downloaded from the Microsoft 365 Defender portal. The MDI sensor installation package is the same for Domain Controllers, ADFS and ADCS. If you have previously downloaded the package, you can use this for the installation, although I would recommend downloading the latest version for any new deployments.

Big Lake = Big Value

“Getting value out of your data lake” For the first time in the security industry, we are seeing security operations teams and data analytics teams working together. This positive development illustrates that security data has value to everyone and can be shared throughout a company. It is important to take control of your data destiny, … Continue reading Big Lake = Big Value