How do I observe Windows Defender Alerts/Prompts on Server Core

We’ve got this situation that’s been going on for awhile where installing our product on our own server core production machine just hangs up. The ops guy is actually logged into the server over remote desktop, runs the installer, and watches it run for awhile and get stuck. (Trying to find out where it got … Read more

Defender for Identity health issues

I am having some difficulties in fixing health issues on my companies MDI instance. The error I am facing on all our virtualized domain controllers is : “Some network traffic could not be analyzed” According to Micorosft docs, they are suggesting to disable on the virtual network adapter the following : TsoEnable LargeSendOffload(IPv4) IPv4 TSO … Read more

Whitelist mailboxes from being blocked from sending emails due to the “User restricted from sending email” alert policy in microsoft365 security?

I have a couple of mailboxes that are periodically being blocked from sending emails due to the “User restricted from sending email” alert policy within the security and compliance center in microsoft 365. I can unblock them fine, but would like to see if there is a way to just whitelist them. I have set … Read more

Exchange Online – Reporting on blocked users

There is a feature in Exchange Online which blocks users from being able to send email when they send too many emails in a time period. It usually triggers either when a user sends a load of emails via Mail Merge or when their account gets compromised and it’s used to send a load of … Read more

Performance issues running VBScript code because of calls to th Antimalware Scan Interface (AMSI)

I am working with an application that processes a table and for each row it is creating a very simply visual basic script and executing it before other processes are executed. The Vbs script is just an If – Else statement with some simple logic that returns true or false. It turns out that the … Read more

Windows Defender for Antivirus – Customize Text Notification

Config Manager and client alerts We like to change the wording in the notifications for Windows Defender for Antivirus. Not sure this is possible. First area – Client, Change the wording on the local machine pop-up notification for Virus & Threat protection – Threat found notification. Can this be done? Second Area – ConfigManager, Change … Read more

Is it safe to delete Windows Defender Scans History Files?

OS: Windows 10 Pro (used as production server to host websites, and mail functions.) I’ve noticed that de-fragmenting my hard drive (using MyDefrag v4.3.1) it’s taking for ever to work itself through this C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store folder. Looking further into it I found that this folder is over 26 GB in size and is holding over … Read more

Windows Firewall – Protected network connections?

In Windows Defender Firewall, under Advanced Settings, there is a “Protected network connections” setting for each profile (Domain, Public, Private). An image of this setting: Protected network connections My goal is to block all connections on Wireless and let everything go on LAN. First I thought, that this is a great idea, enable the Firewall … Read more

MMC crash during remote firewall management

Using MMC, I’m attempting to remotely manage the Windows Defender Firewall on our Hyper-V Server 2019 instance (no GUI, CLI only). The NetBIOS name is SERVER1. The Windows Defender Firewall Remote Management rules are enabled: Name : RemoteFwAdmin-In-TCP DisplayName : Windows Defender Firewall Remote Management (RPC) Description : Inbound rule for the Windows Defender Firewall … Read more