Skip to content

IT Dev Lab

Learnings and musings of a Microsoft Identity & Security consultant

IT Dev Lab

Learnings and musings of a Microsoft Identity & Security consultant

  • Home
  • Post Series
    • WDAC Wednesday
  • Links library
  • About
WDAC

WDAC Wedesday: Audit mode advantage

Andrew 28 October 2025 0 Comments

Happy WDAC Wednesday! Application control solutions are very powerful, they are like a gate keeper, and determine what installed applications are allowed to run. Applying tighter controls on endpoints, using…

WDAC

WDAC Wedesday: Why anti-virus and EDR isn’t enough

Andrew 21 October 2025 0 Comments

Happy WDAC Wednesday! Welcome to a new series with the aim of detailing and demistifying Microsoft’s Application Control for Business (ACFB), a powerful solution used to allow or block applications…

Microsoft Entra MIM2016

Looking to migrate from MIM to Microsoft Entra?

Andrew 9 March 2024 0 Comments

If you’re an organisation utilising Microsoft Identity Manager (MIM) Microsoft have recently released a Microsoft Learn article that maps capabilities of MIM to those in Microsoft Entra, and is a…

Sentinel WDAC

January 2024 WDAC Advanced Hunting changes

Andrew 12 December 2023 0 Comments

Microsoft today published an update advisory for Windows Defender Application Control (WDAC) Advanced Hunting changes that could have an impact if you have any hunting rules or dashboards in place.…

WDAC

Creating a policy with the WDAC Wizard

Andrew 4 December 2023 0 Comments

The goal of this post is to step through the process of using the WDAC Wizard to create a sample WDAC policy and deploy it to a test Windows 10…

WDAC

Application control with Microsoft WDAC

Andrew 20 November 2023 0 Comments

This blog post will be the first (of many) in a series relating to Microsoft WDAC and how to understand, implement and manage it. In the current cyber security landscape…

Microsoft 365

Mark of the Web and trusting SharePoint Online

Andrew 19 November 2023 0 Comments

A common measure in corporate environments is to block macros files downloaded from the internet, which is implemented as a security measure to prevent users from inadvertently executing malicious. How…

Sentinel Uncategorized

Deploying Sentinel analytic rules from DevOps

Andrew 18 October 2023 0 Comments

There is a Microsoft Sentinel feature currently in public preview that allow you to deploy custom Sentinel content from DevOps or GitHub, such as analytic rules. The linked article provides…

Exchange Online Microsoft 365

Exchange Online SPF and domain validation

Andrew 29 May 2023 0 Comments

When on-boarding a domain to Exchange Online there is support documentation available detailing the DNS entries required for the domain to be successfully validated. One item not explicitly stated in…

Logic Apps

Logic Apps and Concurrency Control awareness

Andrew 26 May 2023 0 Comments

If you’ve ever had strange, unexplainable behaviour in a Logic App loop that uses variables chances are the cause will be the Concurrency Control setting, which is turned off by…

Posts pagination

1 2 … 4

Next Page »

You Missed

WDAC

WDAC Wedesday: Audit mode advantage

WDAC

WDAC Wedesday: Why anti-virus and EDR isn’t enough

Microsoft Entra MIM2016

Looking to migrate from MIM to Microsoft Entra?

Sentinel WDAC

January 2024 WDAC Advanced Hunting changes

IT Dev Lab

Learnings and musings of a Microsoft Identity & Security consultant