Skip to content

IT Dev Lab

Learnings and musings of a Microsoft Identity & Security consultant

IT Dev Lab

Learnings and musings of a Microsoft Identity & Security consultant

  • Home
  • Post Series
    • WDAC
  • Links library
  • About
Intune PowerShell

Trigger an Intune sync on a device with PowerShell

Andrew 16 August 2022 0 Comments

Recently in doing a device remediation exercise it was necessary to run some PowerShell code on a device via Intune – this is easily done using the built in scripts…

Intune PowerShell

Proxy authentication required for Intune scripts

Andrew 9 August 2022 0 Comments

I’ve been developing PowerShell scripts in Intune a lot recently for cleaning up various machine issues in an application control project and recently encountered an issue where a PowerShell script…

Microsoft 365

Office Cloud Policy priority of policies

Andrew 9 August 2022 0 Comments

Recently when deploying Microsoft Office Macro controls using the Office cloud policy service the deployment approach was to create two policies – the first blocking the use of macros, and…

PowerShell

Invoke-RestMethod response headers

Andrew 5 August 2022 0 Comments

In developing some scripts recently I discovered that the Invoke-RestMethod cmdlet (in PowerShell version 5 at least) doesn’t provide the values of the response headers. The workaround I had to…

Home network Today I Learned

useful Ubuntu firewall commands #TIL

Andrew 3 August 2022 0 Comments

I’ve started experimenting with Ubuntu again recently with a Raspberry Pi4 that I have on my home network (running Ubuntu Server 20.04 LTS). I’ve had it with a view of…

Microsoft 365

Mail sent to the wrong Office 365 region. ATTR35.

Andrew 8 July 2022 0 Comments

I encountered this error for a system relaying mail via Microsoft 365, sending mail to users within the organisation was working as expected however the sending system was getting the…

Uncategorized WDAC

Confirm what WDAC policies are present on a device

Andrew 18 May 2022 0 Comments

Windows Defender Application Control (WDAC) is an application control system integrated into Windows 10/11 and is used within Enterprise to whitelist trusted applications, allowing them to run, and blocking either…

KQL Today I Learned

#TIL KQL parse_path() function

Andrew 5 May 2022 0 Comments

Working with Sentinel and Log Analytics is nearly a daily task for me of late, and working with WDAC of late interrogating file paths was something I was finding very…

Microsoft 365

Microsoft 365 dkim=fail (no key for signature)

Andrew 3 May 2022 0 Comments

Recently I was working on a migration project moving a number of domains from a 3rd party mail hygiene solution to Defender for Office 365 and as part of the…

Windows

Script clearing a Windows event log

Andrew 20 April 2022 0 Comments

To assist in troubleshooting an issue I needed to clear a specific Windows event log, so my immediate thought was PowerShell! Yes there is a cmdlet Clear-EventLog, however it appears…

Posts pagination

1 2 3 4

« Previous Page — Next Page »

You Missed

Microsoft Entra MIM2016

Looking to migrate from MIM to Microsoft Entra?

Sentinel WDAC

January 2024 WDAC Advanced Hunting changes

WDAC

Creating a policy with the WDAC Wizard

WDAC

Application control with Microsoft WDAC

IT Dev Lab

Learnings and musings of a Microsoft Identity & Security consultant