AzureTracks

Practical Azure and Microsoft 365 security walkthroughs

Andrew

  • How to Find Users With & With-Out MFA Quickly

    How to Find Users With & With-Out MFA Quickly

    Wondering where to get started finding all the users in your Entra ID that do not have MFA enabled? Here’s some quick PowerShell to get you started and easily identify what users may be missed by your conditional access policies.

    Read article

  • How do I Start Threat Hunting with Microsoft Sentinel?

    How do I Start Threat Hunting with Microsoft Sentinel?

    Join me as I explore getting started with threat hunting using Microsoft Sentinel and KQL to jump-start our investigations. We will dive into a world where we look for anomalies in the data and try to identify potential threats before they can escalate within our environment.

    Read article

  • Azure Updates – Number 96 – August 10, 2024

    Azure Updates – Number 96 – August 10, 2024

    A summary update on Azure news that includes updates released from Microsoft Azure related to Azure, Architecture, Compute, Security Copilot and Sentinel topics. Save time digging around to find recent releases and changes.

    Read article

  • Using KQL with Azure Arc Machine Status

    Using KQL with Azure Arc Machine Status

    In this post we take a look at using KQL to observe machine status of Azure Arc managed machines. We will look at a couple of examples of how to create some helpful queries and then using those to enable monitoring in Microsoft Sentinel. As organizations adopt a more cloud-centric management model, it is becoming…

    Read article

  • Azure Updates – Number 95 – July 27, 2024

    Azure Updates – Number 95 – July 27, 2024

    A summary update on Azure News that includes updates released from Microsoft Azure related to Azure, Architecture, Compute, and Sentinel topics. Every update is linked to it’s original Microsoft Azure, Microsoft Sentinel or other blog source. Hopefully this will save you some time digging around to find recent releases and changes.

    Read article

  • Using Azure Dashboard with Sentinel

    Using Azure Dashboard with Sentinel

    In this post, I explore using Azure Dashboard to help summarize Sentinel reporting and to provide an enhanced method for non-technical users to understand the current incidents in Microsoft Sentinel. We will look at creating Azure Dashboards, KQL queries, displaying data in a meaningful way, and how to grant users permission to see the dashboard.

    Read article

  • Azure Updates – Number 94 – July 13, 2024

    Azure Updates – Number 94 – July 13, 2024

    A summary update on Azure news that includes updates released from Microsoft Azure related to Azure, Architecture, Compute, Security Copilot and Sentinel topics. Save time digging around to find recent releases and changes.

    Read article

  • Find Failed Create Operations in Azure using KQL

    Find Failed Create Operations in Azure using KQL

    Today, we embark on a thrilling quest through the Azure cosmos to uncover the secrets of failed create operations using Kusto Query Language (KQL). This quick post will equip you with the knowledge to track down those elusive “create” mishaps and help find clues behind these operations quickly.

    Read article

  • Azure Updates – Number 93 – June 29, 2024

    Azure Updates – Number 93 – June 29, 2024

    A summary update on Azure news that includes updates released from Microsoft Azure related to Azure, Architecture, Compute, Security Copilot and Sentinel topics. Save time digging around to find recent releases and changes.

    Read article

  • Unveil Delete Operations in Azure using KQL

    Unveil Delete Operations in Azure using KQL

    In this blog post, we’ll explore how to wield the mighty KQL to uncover those elusive “delete” actions within your Azure environment. Whether you’re a seasoned cloud explorer or just dipping your toes into the Azure waters, this guide will equip you with the knowledge to track down those vanishing resources.

    Read article