
Can Chromebooks be managed with MEM?
Chromebooks have been hugely popular within the education space these last few years. They are positioned as affordable tablet computers running on Google’s ChromeOS. ChromeOS has a Play Store of it’s own where Android apps can be installed, but also some ChromeOS specific apps. As these tablets have been imbedded within the educational space for … Continue Reading Can Chromebooks be managed with MEM?

Why you should be using Azure Sentinel as an MSSP
If you have been following me on Twitter or my blog, it’s no secret that I absolutely love Azure Sentinel. It’s on the fastest moving product within the Microsoft Security stack and provides some awesome capabilities. But unfortunately, a lot of people seem to be afraid of it. When you start talking about a ‘SIEM’ … Continue Reading Why you should be using Azure Sentinel as an MSSP

Road to passwordless: 1 year in
Passwordless was one of the big buzzwords in 2020 when you think about Identity & Access. The goal of it is pretty simple: remove all passwords in the day-to-day life of your end-users and remove them in your directory. I have blogged about it in 2019 and explained that the road to passwordless isn’t as … Continue Reading Road to passwordless: 1 year in

The issue of Log Analytics column names and spaces
Today it’s time for a rather short blog post on an issue I ran into for which I couldn’t find anything online. The issue I have been working with the Sentinel API to create watchlists lately. During my endeavors, I ran into an issue when trying to use some of the columns of my watchlist. … Continue Reading The issue of Log Analytics column names and spaces

Pushing the MMA Agent with MEM in a smart way
The Microsoft Monitor Agent has had quite a long history with a lot of use cases. In the past it was used to send data to SCOM/OMS products, but nowadays this is often used to send data to Log Analytics/Sentinel. The Issue Different teams in your organization might have the need to connect the endpoints … Continue Reading Pushing the MMA Agent with MEM in a smart way

Why you should use Logic Apps instead of Power Automate
Microsoft offers a few ‘no-code’ automation solutions within Azure/Microsoft 365. If we take a look at the moment popular ones: Logic Apps and Power Automate, it’s often difficult to decide which one you should be using for your automation task. When we put the two next to each other, you will see that they look … Continue Reading Why you should use Logic Apps instead of Power Automate

Configure Edge Chromium for a seamless end-user migration from Google Chrome with MEM
As you know by now, Edge Chromium is Microsoft’s newest browser which integrates Edge and Internet Explorer into the one browser to rule them all. There are a lot of valid reasons to migrate to it, but the most difficult part with is getting your users to adopt the new browser. In this blog post, … Continue Reading Configure Edge Chromium for a seamless end-user migration from Google Chrome with MEM

An introduction into the Graph API
Whenever you are managing a Microsoft 365 environment, you regularly come across repetitive tasks: Creating new Intune policies Setting up users Retrieving security data … For all these tasks, Microsoft 365 has the ability for some automation. During this blog post, I will walk you through how to get started with the Graph API and … Continue Reading An introduction into the Graph API

AzureAD – Device not recognized as Hybrid Joined
If you are working with Office 365, some organizations will have the requirement that Office 365 data is only available offline when users are using their company-provided devices. This means users cannot sync work data onto their personal computers. Configuration The configuration is pretty simple, this can be done through a simple Conditional Access policy: … Continue Reading AzureAD – Device not recognized as Hybrid Joined

Using a Lighthouse Service Principal within Azure DevOps
I just blogged on the website of The Collective about using a Lighthouse Service Principal from within Azure DevOps. We use this process internally to manage the Azure Sentinel environment of our customers. Check out the article here.

Hybrid vs Azure AD Join
When organizations are starting their journey to the cloud, they are most likely starting off by joining their Windows 10 machines to both their local Active Directory domain and Azure Active Directory in a Hybrid Azure AD Join. That way, they can enjoy the power of the cloud, while keeping all the legacy applications that … Continue Reading Hybrid vs Azure AD Join

Retire non-compliant devices through Power Automate
With the 2003 release of Microsoft Endpoint Microsoft, a new compliance setting was introduced to retire non compliant devices. It sounds like this would automatically retire non-complaint devices, but this is not the case. If a non-compliant has this setting assigned, the device shown up in the ‘Retire noncompliant devices’ section in the MEM portal. … Continue Reading Retire non-compliant devices through Power Automate

Assigning MDATP tags through the machine name & logged on user with Logic Apps
I recently published a blog on the website of The Collective (my employer), where I talk about assigning MDATP tags through Logic Apps. This article goes over a solution where tags are assigned according to the machine name and current logged on user of a MDATP device. I also touch on a few tips on … Continue Reading Assigning MDATP tags through the machine name & logged on user with Logic Apps

Choosing the right Android enrollment method
When starting off with Intune, choosing which Android enrollment you want to use, can be pretty difficult. During this blog post I will walk you through all the possibilities and help you make the right decision. Overview There are 6 different ‘enrollment’ method for Android devices within Intune: Mobile Application Management without Enrollment Device Administrator … Continue Reading Choosing the right Android enrollment method

Managing OAuth applications with MCAS
In one of my previous blogs, I already talked about the dangers of OAuth and why you should be managing these. Monitoring and managing OAuth applications is also possible with MCAS and actually provides some pretty good insights into the current applications you have and how you should handle new ones. Connect AAD apps to … Continue Reading Managing OAuth applications with MCAS

Requiring two MFA methods with the Combined Registration
Last month, the combined MFA and password reset registration portal has been made generally available. Previously, a user could register his security information on two separate locations, for MFA and for Self Service Password Reset. Self Service Password Reset Self Service Password Reset is a feature of Azure Active Directory which enables the user to … Continue Reading Requiring two MFA methods with the Combined Registration

Android Enterprise Dynamic Groups for Intune
Microsoft Endpoint Manager (Intune) currently supports fours different Android Enterprise enrollment methods: Work Profile Dedicated Device Fully Managed Fully Managed Devices with Work Profile (Corporate Owned – Personally Enabled (COPE)) Each method has it’s own purpose. Work Profile is mostly used for employees who want access to company resources using their own personal device. A … Continue Reading Android Enterprise Dynamic Groups for Intune

Sync Named Locations to MCAS IP Ranges using Azure Automation
Every Microsoft 365 Security engineer has the same struggle: maintaining corporate IP-address range needs to be done in two places. Once in trusted named locations in Azure AD and once in corporate ‘IP ranges’ in MCAS. It is really important to configure these both. In Azure AD, (trusted) named locations are used in Conditional Access … Continue Reading Sync Named Locations to MCAS IP Ranges using Azure Automation

Saving corporate IPs to Log Analytics with Logic Apps
Link to the ARM template for the full playbook can be found on Github. Microsoft cloud SIEM, Azure Sentinel, is an amazing product which can provide central logging and reporting for your organization. At The Collective we are heavily using this to improve the security posture of our clients. It’s tightly integrated with all the … Continue Reading Saving corporate IPs to Log Analytics with Logic Apps

Deploy Power App to a Managed Home Screen through MEM
As a lot of organizations are picking up Power Apps, I have seen more and more use for them. Some organizations are now developing Power Apps and having their end users consume those on mobile devices. As these apps are sometimes used in production environments, these apps often appear on Android Enterprise Kiosk devices. Pinning … Continue Reading Deploy Power App to a Managed Home Screen through MEM

Setting up calendar sharing in a multilingual company
A lot of companies want all their employees to have all calendars open by default. That way any employee can view the calendar of a colleague to check if he/she is available. We can set calendar permission in Office 365 pretty easy by running the command ‘Set-MailboxFolderPermission’. The recommend syntax is as follows: This command … Continue Reading Setting up calendar sharing in a multilingual company

Best Practices for Emergency Accounts
Break The Glass or emergency accounts are a necessity in the cloud world we live today. Every year Azure AD goes down for a few hours because of some Multifactor Authentication issue. This means none of your users are able to log in. As this is problematic, you need to take action to prevent these … Continue Reading Best Practices for Emergency Accounts

Creating a dynamic group with all AAD Premium licensed users
Dynamic Groups in Azure AD are truly an amazing feature. It lets you manage a large group of users without the need to manually add every one of them in a specific group. Some organizations only have AAD Premium licenses for a subset of users, using dynamic groups makes it really easy to scope your … Continue Reading Creating a dynamic group with all AAD Premium licensed users

Updating the flag status of an Exchange email through Powershell EWS
I was recently involved in a Exchange Migration that also involved an Enterprise Vault migration. The company in question currently had about 2000 archived that needed to be moved into the Exchange on-prem mailboxes before migrating them to Exchange Online. For that migration, we used Archive Shuttle from Quadrotech which does an amazing job migrating … Continue Reading Updating the flag status of an Exchange email through Powershell EWS

Automating 3rd Party application deployment in Intune with PatchMyPc
Patch My PC is probably the most known product for Automated Third Party Application Patch Management with SCCM integration. This is an amazing product that simplifies your Third Party Application deployment and patching. Last week Patch My PC announced theirpreview for Win32 Application Management for Intune. This means Patch My PC can now automate the … Continue Reading Automating 3rd Party application deployment in Intune with PatchMyPc
Loading…
Something went wrong. Please refresh the page and/or try again.