SIEM Playlist - Released
1:22
21 день тому
Azure Monitor | What Azure Monitor Agent?
15:50
Microsoft Azure Log Analytics Worksapce
16:53
7 місяців тому
КОМЕНТАРІ
@YouKayTen
@YouKayTen День тому
Thanks for this. Brilliant for Admin roles. Is there a way we could leverage PIM to delegate access on behald of another user as a role? E.g. EA on behalf of CEO? (or anything else within Microsoft universe)
@QUOTES-lf1wt
@QUOTES-lf1wt 3 дні тому
Does a DEM ACCOUNT Requires LICENSE AND SPECIFIC ROLES
@sohailsameerkhan3232
@sohailsameerkhan3232 5 днів тому
CAN YOU PLEASE CREATE A VIDEO ON HOW TO TROUBLESHOOT THE CAP. MFA POLICIES AND WHAT ARE THE TICCKETS CAN BE ARISE?
@quescott8363
@quescott8363 10 днів тому
Thanks for your videos, is there a way to export and import adfs configuration from one server to the next? Like claim descriptions, AD claims , CPT, RPT, ...everything.
@systechadmin8368
@systechadmin8368 14 днів тому
Nice PPT
@tcanbarasan
@tcanbarasan 15 днів тому
How to get the token with the c# console app without GUI user login?
@jithinksunil7025
@jithinksunil7025 15 днів тому
Nice explanation
@BindasBadshah
@BindasBadshah 15 днів тому
This episode alone deserve to be your subscriber. The way you have explained it has answered my 3 year old questions.
@imwhtim
@imwhtim 15 днів тому
This is something new i came to know that Sentinel use Dedicated Schema. Thanks for such a wonderful video
@imwhtim
@imwhtim 16 днів тому
This series is a Gem, I would also request you to please create a series on SOAR also.You're really helping us understand all this tech security stuff better, which is super important.
@mohamedgharbeya2627
@mohamedgharbeya2627 16 днів тому
You are teaching is amazing and make it very clear and easy to understand. i bet you are a teacher thank you for sharing
@amitbahuguna3270
@amitbahuguna3270 16 днів тому
More videos on postman
@user-Azuredragon
@user-Azuredragon 17 днів тому
The concept is perfect. Thanks one more thing if you can add with the deployment of this DCR and Azure Monitor with custom Data source custom performance logs instead of basic for VMs with help of Azure policy, alert and action group in this series
@ajitjawale217
@ajitjawale217 19 днів тому
Excellent explanation
@mr.mallela5557
@mr.mallela5557 19 днів тому
what is diffrence between DCR created in Monitor vs Sentinel. when we create DCR through Sentinel its deffirent and not showing options like Basic or Custom. as shown in the Video after created DCR with DNS and Hello Buinness events how to get into the sentinel alerts.? Thank in Advance. Great detailed video btw. . Keep it up the amazing work. :)
@ranjeetrana3455
@ranjeetrana3455 20 днів тому
One thing sir, folder which u created ll be applicable for all devices..
@Mike-jo4cc
@Mike-jo4cc 22 дні тому
Sorry @Concepts Work but you didnt show anything but texts. Show us the monitor blade in Azure Portal in the virtual machine overview window.. Do you see the monitor coverage enabled or disabled AFTER you enable Windows event logs in Data collection rules??? You CANNOT use the new Azure Monitor Windows agent when you enable Windows event logs in Data collection rules!
@ConceptsWork
@ConceptsWork 22 дні тому
Hello Mike, it gives up immense pleasure when we see such deep insightful feedback on our videos. Thank you so much for giving us your time and watching our content. Let me help you understand couple of things. When you create DCR just to capture logs, which in our case windows performance and events, then the data ingestion happens to Events table in the log analytics workspace. However, when you talk about Monitoring coverage, there is a default DCR which is created and it has a different mapping altogether for data ingestion, in this scenario the data ingestion takes place in the table named as "InsightsMetrics". Similarly, when you create a DCR from sentinel console the data will be ingested to "SecurityEvents" table. The behavior of DCR and data ingestion is completely different for all the services. As the video suggests, advanced logging for windows, which means you are capturing data which is not related to performance. I hope this helps. However, there are still three videos pending, I will try to showcase this. Here are some references for data flow section for all the three scenarios. If you get some time, please watch our DCR structure video as well, which we will be releasing this weekend. Data flow for event table (DCR created directly) "dataFlows": [ { "streams": [ "Microsoft-Perf" ], "destinations": [ "la-257108454" ] }, { "streams": [ "Microsoft-Event" ], "destinations": [ "la-129300856" ] } ], Data flow for DCR created from Monitoring settings blade. "dataFlows": [ { "streams": [ "Microsoft-InsightsMetrics" ], "destinations": [ "VMInsightsPerf-Logs-Dest" ] } ] Data flow for DCR created from sentinel console. "dataFlows": [ { "streams": [ "Microsoft-SecurityEvent" ], "destinations": [ "DataCollectionEvent" ] } ], Thank you once again, for watching our content so closely, much appreciated.
@aragaorj
@aragaorj 22 дні тому
Is it possible to publish an OWA from a Hybrid Exchange Server with Entra Application Proxy? I don't find clear information about this on the web.
@ShaikhAfroz
@ShaikhAfroz 22 дні тому
Great work, and thank you
@ConceptsWork
@ConceptsWork 22 дні тому
Thanks for watching!
@user-vk8vy6hj7s
@user-vk8vy6hj7s 23 дні тому
@sergiolondono1514
@sergiolondono1514 23 дні тому
Hello conceptworks, Very good explanation of tokens, I just have a question: that is the default expiration for access token from Entra ID connect? What is the difference between refresh token and Primary Refresh Token PRT? Best regards,
@ConceptsWork
@ConceptsWork 22 дні тому
Refesh token is identity specific, however PRT is binded to each device.
@sergiolondono1514
@sergiolondono1514 22 дні тому
@@ConceptsWork: Perfect.. thanks for your quick answer. love your videos. you way to explain is excellent. I will join again to the community you are very very good.
@RichardGailey
@RichardGailey 23 дні тому
That was a fantastic set of videos on Arc, and really well explained. I especially like the way your deep dive in to specific areas that you know users may face issues. I also agree with the question that you have raised on Github, as I have noticed those permissions being automatically assigned elsewhere in our estate automatically.
@ConceptsWork
@ConceptsWork 22 дні тому
Glad it was helpful! Microsoft has confirmed this as by design, based on a vulnerability we reported.
@imwhtim
@imwhtim 23 дні тому
One more master piece of Video. Host awaited video series till now.
@ConceptsWork
@ConceptsWork 22 дні тому
Thanks for watching our content.
@ponjayaram8573
@ponjayaram8573 23 дні тому
Kindly create a playlist for Azure cloud (zero to advance).
@adeyemiakanfe7641
@adeyemiakanfe7641 26 днів тому
you are the best
@smaksood
@smaksood 29 днів тому
❤ Excellent 😃😃
@ConceptsWork
@ConceptsWork 22 дні тому
Thanks 😄
@3dogsgaming
@3dogsgaming 29 днів тому
How does one actually get analytics from a service or application that is causing an increase in egress from an Azure VM?
@khanhasan01
@khanhasan01 29 днів тому
Awesome - Explained very clearly.
@ConceptsWork
@ConceptsWork 22 дні тому
Glad it was helpful!
@dariush7272
@dariush7272 Місяць тому
Very good resources, thank you very much
@ConceptsWork
@ConceptsWork 22 дні тому
Glad it was helpful!
@anilpaila9797
@anilpaila9797 Місяць тому
Using the client credential flow token can i generate refresh token
@wahibakamoulcode
@wahibakamoulcode Місяць тому
Great explanation! Thank you
@apandey107
@apandey107 Місяць тому
You are best
@raiders18dr
@raiders18dr Місяць тому
Do you have, or would you be willing to make, a video on installing and configuring AMA on client endpoints instead of servers?
@ConceptsWork
@ConceptsWork 22 дні тому
Thanks for the request we will create one.
@runmadhu2161
@runmadhu2161 Місяць тому
FYI --- if you have 2 proxy server, you can execute tenant registration will be done only on 1 server. No need to execute registration on all proxy server.
@oindrilabandyopadhyay9055
@oindrilabandyopadhyay9055 Місяць тому
One question- why are you not passing the scope/permission within the $Body of the powershell script ?
@ConceptsWork
@ConceptsWork 22 дні тому
This video is created while using older endpoints, where the scope was not required.
@maheshk6507
@maheshk6507 Місяць тому
Nice explanation
@renukagandweed7265
@renukagandweed7265 Місяць тому
Great explanation
@tiagovfs
@tiagovfs Місяць тому
Thanks!
@ConceptsWork
@ConceptsWork Місяць тому
Thank you :-)
@RichardGailey
@RichardGailey Місяць тому
Again, another highly detailed video. Many thanks for the effort you put in to these.
@atkhan41
@atkhan41 Місяць тому
Quick Question: The machine which u r using for user portal and Says Multi-factor Authentication server, where you'll create this on DC?, on standalone machine? moreover what OS?
@Noursbear
@Noursbear Місяць тому
Question, can you also distribute policies such as conditional access/config policies to on prem pc's ? And would there be the same policies or is there s subset of policies just for on prem ? Because I presume the policies under Config Manager (SCCM) are different there. Thanks
@Noursbear
@Noursbear Місяць тому
just what I needed, I was wrongly lead to believe, by Microsoft^s documentation, that there was a new console available looking like the graphic, when everything is simply in the Endpoint (Intune console) portal.
@shat1478
@shat1478 Місяць тому
Thank for your help this was great ! One question.. Is there any way to stop running onboarding script if client onboarding successfully.
@-Subscribe-7
@-Subscribe-7 Місяць тому
your videos are very interesting and knowledgeable but you need to improve your voice qulaity it is very low and even turning on full volume of laptop hard to hear however if we install speakers then it can work. cheers !!!
@deepexplore6247
@deepexplore6247 Місяць тому
Can log analytics be used in scenarios if i have gather logs for application which is running on vm or enterprize application ??
@anandjam8994
@anandjam8994 Місяць тому
It's awesome, can you show example in Azure dashboard?
@ashu-r808k
@ashu-r808k Місяць тому
I have reviewed our mdatp check and identified some missing items. Could you please add them? Additionally, it would be helpful if you could create a shell script for all the commands. This would greatly assist in managing a large network and benefit many people. Thank you!
@satish3636
@satish3636 Місяць тому
Hello, can you create video for how to migrate existing log analytic setting using DCR Config Generator because few parameters are unable to find in new DCR Configuration.
@ConceptsWork
@ConceptsWork Місяць тому
Can you please share some more details on this.
@pravinkalotara244
@pravinkalotara244 Місяць тому
Thank you for this amazing content! Do we have more video in pipeline for Agent upgrade from Legacy to AMA?