Skip to content

IT Dev Lab

Learnings and musings of a Microsoft Identity & Security consultant

IT Dev Lab

Learnings and musings of a Microsoft Identity & Security consultant

  • Home
  • Post Series
    • WDAC
  • Links library
  • About
    • Home
    • Andrew
    • Page 3
WDAC

WDAC 3033 error workarounds

Andrew 16 September 2022 0 Comments

On a Windows Defender Application Control (WDAC) project one issue you may encounter is driver .dll or .sys files that are digitally signed, but the certificate has now expired. The…

Intune PowerShell

Trigger an Intune sync on a device with PowerShell

Andrew 16 August 2022 0 Comments

Recently in doing a device remediation exercise it was necessary to run some PowerShell code on a device via Intune – this is easily done using the built in scripts…

Intune PowerShell

Proxy authentication required for Intune scripts

Andrew 9 August 2022 0 Comments

I’ve been developing PowerShell scripts in Intune a lot recently for cleaning up various machine issues in an application control project and recently encountered an issue where a PowerShell script…

Microsoft 365

Office Cloud Policy priority of policies

Andrew 9 August 2022 0 Comments

Recently when deploying Microsoft Office Macro controls using the Office cloud policy service the deployment approach was to create two policies – the first blocking the use of macros, and…

PowerShell

Invoke-RestMethod response headers

Andrew 5 August 2022 0 Comments

In developing some scripts recently I discovered that the Invoke-RestMethod cmdlet (in PowerShell version 5 at least) doesn’t provide the values of the response headers. The workaround I had to…

Home network Today I Learned

useful Ubuntu firewall commands #TIL

Andrew 3 August 2022 0 Comments

I’ve started experimenting with Ubuntu again recently with a Raspberry Pi4 that I have on my home network (running Ubuntu Server 20.04 LTS). I’ve had it with a view of…

Microsoft 365

Mail sent to the wrong Office 365 region. ATTR35.

Andrew 8 July 2022 0 Comments

I encountered this error for a system relaying mail via Microsoft 365, sending mail to users within the organisation was working as expected however the sending system was getting the…

Uncategorized WDAC

Confirm what WDAC policies are present on a device

Andrew 18 May 2022 0 Comments

Windows Defender Application Control (WDAC) is an application control system integrated into Windows 10/11 and is used within Enterprise to whitelist trusted applications, allowing them to run, and blocking either…

KQL Today I Learned

#TIL KQL parse_path() function

Andrew 5 May 2022 0 Comments

Working with Sentinel and Log Analytics is nearly a daily task for me of late, and working with WDAC of late interrogating file paths was something I was finding very…

Microsoft 365

Microsoft 365 dkim=fail (no key for signature)

Andrew 3 May 2022 0 Comments

Recently I was working on a migration project moving a number of domains from a 3rd party mail hygiene solution to Defender for Office 365 and as part of the…

Posts pagination

1 2 3 4

« Previous Page — Next Page »

You Missed

WDAC

WDAC Wedesday: Why anti-virus and EDR isn’t enough

Microsoft Entra MIM2016

Looking to migrate from MIM to Microsoft Entra?

Sentinel WDAC

January 2024 WDAC Advanced Hunting changes

WDAC

Creating a policy with the WDAC Wizard

IT Dev Lab

Learnings and musings of a Microsoft Identity & Security consultant