Sign in

Devfender

@devfender.bsky.social
538 followers 826 following 336 posts

The dev who defends using defender | Cybersecurity Automation Architect | Microsoft MVP | Microsoft Security Advocate www.linkedin.com/in/jay-kerai-cyber // github.com/jkerai1

PostsRepliesMedia
Devfender @devfender.bsky.social · 26/09/2026
Thwarted by my own Genius
011
Devfender @devfender.bsky.social · 21/09/2026
So Security Operator can disable users, password reset and revoke refresh tokens now learn.microsoft.com/en-us/entra/...
000
Devfender @devfender.bsky.social · 13/09/2026
I am not a fan of the Intune built-in baselines but tbh this is quite yoinkable: FW rules to block node in program files and appdata
010
Devfender @devfender.bsky.social · 13/09/2026
So who has tried local AI agent diagnostic in #Intune ? (Properties catalog -> Local AI Agent) #AI #ShadowAI #MDM
110
Devfender @devfender.bsky.social · 11/09/2026
I spent way too much debugging why an endpoint would connect to Microsoft identity endpoints after ruling out networking, GSA, DNS, FW Rules. Turns out I had this "enable firewall protection of Microsoft Endpoints" in TenantRestrictions. I had WDAC enabled and running but no app tagging rule.
000
Devfender @devfender.bsky.social · 07/09/2026
Maybe time to add .mobileconfig to your anti-malware attachment filter in MDO For the record its not in the CIS L2 Benchmark for MDO #MDO #Phishing #DefenderForOffice #CIS #Security #Malware #Attachment #Microsoft
000
Devfender @devfender.bsky.social · 27/08/2026
So you can do Tenant Restrictions in a Edge for business policy now though I struggle to see the use-case over doing it the Intune or GSA way. #Intune #Edge #GSA #Tenant #TenantRestrictions
110
Devfender @devfender.bsky.social · 25/08/2026
Wait a minute that product was retired! The weird part is my greenfield tenant and sub is still compliant with the setting. #Azure
000
Devfender @devfender.bsky.social · 21/08/2026
Even in KQL supports it btw
010
Devfender @devfender.bsky.social · 21/08/2026
The year is 2027 and all policies have an emoji now for max readability #Entra
110
Devfender @devfender.bsky.social · 19/08/2026
Anyone ever noticed Microsoft graph command line tools doesn't show up as a first party Microsoft app despite the docs mentioning it is? My app governance policy disabled it which is how I noticed this. #entra #microsoft
110
Devfender @devfender.bsky.social · 10/08/2026
Don't forget you can also monitor MCP Servers also in Defender for Cloud Apps
010
Devfender @devfender.bsky.social · 03/08/2026
Spun up a new tenant and this default has also Also seems to worded slightly differently?
000
Devfender @devfender.bsky.social · 23/07/2026
That's new. Don't believe its in the docs. (AADSTS135018)
000
Devfender @devfender.bsky.social · 06/07/2026
No better feeling than denying a PIM request for a role thats over privileged for the task.
000
Devfender @devfender.bsky.social · 04/07/2026
Spotted another Crypto Scam in a Cyber Discord server. Noticed the fake crypto site had a chat bot so I decided to Prompt inject it: I made it admit it was a scam that had fake endorsements, fake reviews and non-existent support emails (no MX record lol)
100
Devfender @devfender.bsky.social · 17/05/2026
Got a phishing email from ana[.]9424663@aluno[.]mg[.]gov.br. Goes to check Gov[.]br using my JayQuery Browser Extension....no DMARC record at all. seriously wtf.
000
Devfender @devfender.bsky.social · 28/04/2026
From now on any new domain I acquire is going straight to DNSSEC and SMTP Dane. So easy to do
100
Devfender @devfender.bsky.social · 21/03/2026
This image perfectly describes PIM self approval with no authentication context
000
Devfender @devfender.bsky.social · 27/02/2026
The pick of destiny! @skotheimsvik.no
021
Devfender @devfender.bsky.social · 23/02/2026
In case you missed it. App Control Manager now has an option to deploy a WDAC audit mode policy for RMM tools:
000
Devfender @devfender.bsky.social · 15/02/2026
Happy Sunday!
000
Devfender @devfender.bsky.social · 01/02/2026
Some new applied skills are out so ofc I had to go complete them to maintain my throne as Mr Applied skills See My video about applied skills here: www.linkedin.com/posts/micros...
000
Devfender @devfender.bsky.social · 18/12/2025
Security copilot won't let you deploy Overage SCUs only...Unless you deploy 1 SCU first then turn it down to 0 after.
010
Devfender @devfender.bsky.social · 05/12/2025
010
Devfender @devfender.bsky.social · 28/11/2025
Basically
010
Devfender @devfender.bsky.social · 14/11/2025
Are you autopatch or outta patch?
010
Devfender @devfender.bsky.social · 14/11/2025
Its Friday my dudes
010
Devfender @devfender.bsky.social · 11/11/2025
the math ain't mathing... Looks like some new applied skills are available and some have been retired. At least this time they are staying on my transcript wooo!
010
Devfender @devfender.bsky.social · 06/11/2025
Copilot coffee!
010
Devfender @devfender.bsky.social · 02/11/2025
Inviting Guests in your tenant via Access Packages? Ensure you have a flow to clear up these guests. Ensure Billing is enabled for Identity Governance for Guests. #Entra
021
Devfender @devfender.bsky.social · 25/10/2025
If you try to assign an Enterprise application to a Group in #Entra while in Entra Free, you will see a bizarre error relating to Active Directory. This is a cloud only Tenant!
011
Devfender @devfender.bsky.social · 19/10/2025
well thats an interesting phish
000
Devfender @devfender.bsky.social · 14/10/2025
Global Administrator's well known name is TenantAdmins if you ever see it in logs. This annoyed me when I first started in SOC and took me a while to figure out.
000
Devfender @devfender.bsky.social · 14/10/2025
Heads up if you are blocking M365 Copilot in Defender for Cloud Apps, it will also block your admin planes due to .cloud.microsoft being included #Defender #MDA #MCAS
000
Devfender @devfender.bsky.social · 09/10/2025
Wowzer hit 10k on LinkedIn I'm an influencer now Here's what I learnt about b2b sales.
010
Devfender @devfender.bsky.social · 07/10/2025
Instructions unclear. Send help
210
Devfender @devfender.bsky.social · 06/10/2025
Foiled by own custom MDA policy!
000
Devfender @devfender.bsky.social · 01/10/2025
Unreal to see this under my name! #MVPbuzz
010
Devfender @devfender.bsky.social · 20/09/2025
010
Devfender @devfender.bsky.social · 14/09/2025
When the portal says you aren't licensed for a feature but you are. #Korn #Microsoft
000
Devfender @devfender.bsky.social · 12/09/2025
These fields look new to me in SignInLogs
000
Devfender @devfender.bsky.social · 09/09/2025
000
Devfender @devfender.bsky.social · 08/09/2025
Definitely the coolest sounding Entra ID role #Entra
000
Devfender @devfender.bsky.social · 29/08/2025
000
Devfender @devfender.bsky.social · 20/08/2025
South Park Episode Malware. Large Obfuscated file! Looks like it tries to unpatch ETW Hash: 73044E540BC4D6A40E5ACE3DF86956759D1B1ECD3E30C076340DD40A02AC21BF 9DFAB3F5C1DF5A4D62E9F3BBDE96EBA1846620A3B413C07D6FA3160C925A5DCD
000
Devfender @devfender.bsky.social · 20/08/2025
I remember when people would complain that #MDO was bad but the reality was they added their own domain to TenantAllowBlockList in allow (which basically overrides all security) Thankfully, Microsoft have changed this feature a while back
000
Devfender @devfender.bsky.social · 19/08/2025
Its a tough life
110
Devfender @devfender.bsky.social · 15/08/2025
isTenantRestricted is new to me in SignInLogs...
000
Devfender @devfender.bsky.social · 12/08/2025
Important Defender License Gotcha: office365itpros.com/2025/08/11/m... Shared Mailboxes Must be licensed for MDO regardless of Plan 1 or 2.
130