Operational Collections 2.0
Automate security group membership based on device hardware, software, vulnerabilities, and other inventory data
Getting more data from the CA Insights and Reporting Workbook
Quick tip on using workbooks to create KQL queries and get more data than provided by the workbook
Super Advanced Auditing
Ensure all available audit records are collected to Unified Audit Log
Defender AutoConfig
A tool to assess and automate configuration in the Defender portal
One Full Scan
Improve Defender performance by performing one full scan
CAPremortem
A tool to assess historical impact of report-only policies
MDE Analyzer²
Automate analysis of MDE Client Analyzer output for common issues
Device cleanup
Comprehensive automation for device cleanup
Enable all auditable events
The defaults are better than they used to be, but you can still do better.