Operational Collections 2.0
Automate security group membership based on device hardware, software, vulnerabilities, and other inventory data
Getting more data from the CA Insights and Reporting Workbook
Quick tip on using workbooks to create KQL queries and get more data than provided by the workbook
Super Advanced Auditing
Ensure all available audit records are collected to Unified Audit Log
Defender AutoConfig
A tool to assess and automate configuration in the Defender portal
One Full Scan
Improve Defender performance by performing one full scan
CAPremortem
A tool to assess historical impact of report-only policies
MDE Analyzer²
Automate analysis of MDE Client Analyzer output for common issues
Device cleanup
Comprehensive automation for device cleanup
Enable all auditable events
The defaults are better than they used to be, but you can still do better.
Trimarc Happy Hour
Lab - Certificate Authority Setup
Lab - Certificate Authority Setup
This step-by-step tutorial is ideal for those looking to experiment with Certificate Authority setups in a lab environment. Learn how to configure an offline CA using OpenSSL, use it to sign an Enterprise ADCS Intermediate CA, and publish CRLs in an Azure Static Web App.
Intune - Microsoft Tunnel VPN Gateway
Note This article was last updated on 01/30/2025 for readability and updated URLs. I am working on updating this for the UI changes that have been made to Intune :)
Azure Automation - Device Cleanup v2
Azure Automation - Device Cleanup v2
Note This article was last updated on 01/30/2025 for readability and updated URLs. We no longer need to manually load modules as shown, and this article will be completely overhauled to include backup of LAPS passwords and BitLocker keys to Azure Key Vault as well :)
Intune - Discover Defender AV exclusions using Proactive Remediation
Intune - Discover Defender AV exclusions using Proactive Remediation
Note This article was last updated on 01/30/2025 for readability and updated URLs. I am working on updating this for the UI changes that have been made to Intune :)
Intune - Block mounting of ISO files
Intune - Block mounting of ISO files
Note This article was last updated on 01/30/2025 for readability and updated URLs
AWS - Integrating PIM with Azure AD SSO for AWS Single-Account Access
AWS - Integrating PIM with Azure AD SSO for AWS Single-Account Access
Note This article was last updated on 01/30/2025 for readability and updated URLs
AWS - Integrating PIM with Azure AD SSO for AWS IAM Identity Center
AWS - Integrating PIM with Azure AD SSO for AWS IAM Identity Center
Note This article was last updated on 01/30/2025 for readability and updated URLs
Azure - Securing Subscriptions
Azure - Securing Subscriptions
Note This article was last updated on 01/30/2025 for readability and updated URLs
Azure Arc - Onboarding Servers with Group Policy
Azure Arc - Onboarding Servers with Group Policy
Note This article was last updated on 01/30/2025 for readability and updated URLs
Azure Automation - Advanced Auditing
Azure Automation - Advanced Auditing
Note This article was last updated on 01/27/2025 for readability and updated URLs, and the content itself will be updated in the near future :)
Lab - Server Build
Lab - Server Build
Back in May of last year, I started building a new server and had planned to fully share the process of putting it together, setting up the OS, templates, etc. Instead, we had a baby, remodeled and sold our home, moved over 1500 miles, and had job constraints that forced me to rush putting it together :( New home server :D Dell R630 with 2x 14 core E5-2680 v4 CPUs Already ordered 1.2TB SAS drives (best bang for buck currently at $20 each). Working on 32GB sticks as I can find them around $60. Goal is 8x 1.2TB drives, 2x 1TB NVMe via PCI-Express adapters, and 16x 32GB sticks :p pic.twitter.com/2p3jEdKOZG
Using transport rules as a security tool
Using transport rules as a security tool
Note Unfortunately, the images from this article were never able to be recovered, and it is unlikely I will be able to recreate them. Email security has come a long way, but there is still a lot of value in using this method if you don’t have access to better tools :)
Intune - Using Access Packages to Enable User Device Enrollment
Intune - Using Access Packages to Enable User Device Enrollment
Note This article was last updated on 01/27/2025 for readability and updated URLs, but content review and image updates are in process :)
Defender for Endpoint - Implementing ASR Rules
Defender for Endpoint - Implementing ASR Rules
Note This article was last updated on 01/27/2025 for readability and updated URLs, but content review is in process. New guidance is to enable the credential theft rule out of the box, and there are new rules to put in audit mode and add to the queries.
Intune - Edge in iOS Kiosk Mode
Intune - Edge in iOS Kiosk Mode
Getting a web app to run in Edge in Kiosk mode on iOS has been a journey, so here's a guide on how I did it :)
Azure AD - Integrating Azure AD logs with Azure Monitor
Azure AD - Integrating Azure AD logs with Azure Monitor
Note This article was last updated on 01/26/2025 for readability and updated URLs
MyStaff - Simplified Administrative Password Reset
MyStaff - Simplified Administrative Password Reset
Note This article was last updated on 01/26/2025 for readability and updated URLs. Unfortunately, images were not able to be restored from a previous hosting provider :(
Defender AV - Improving Windows Defender Update Efficacy
Defender AV - Improving Windows Defender Update Efficacy
Note This article was last updated on 01/26/2025 for readability and updated URLs. Unfortunately, images were not able to be restored from a previous hosting provider :(
OSINT - Using Shodan.io to protect your school district
OSINT - Using Shodan.io to protect your school district
Note This article was last updated on 01/26/2025 for readability and updated URLs. Unfortunately, images were not able to be restored from a previous hosting provider :(
Defender for Endpoint - Removable Storage Access Control
Defender for Endpoint - Removable Storage Access Control
Note This article was last updated on 01/26/2025 for readability and new images due to UI changes made in Intune. I tried to keep the original style and flow, and the original post content can be found in the Twitter link at the end. A new article will revisit this and add new capabilities.