Skip to content
Azure to the Max

Azure to the Max

I already have a case open for that.

    • About the Author
    • Log Analytics Index
    • Disclaimer
  • PR for Detecting Faulty Notepad++ Upgrades

    Introduction: I might be a bit behind the wave here, but I wanted to provide something to the community that has helped in my world. As I am sure many folks are already aware, there were a host of vulnerabilities recently found and patched in Notepad++. Those include CVE-2023-40031, CVE-2023-40036, CVE-2023-40164, CVE-2023-40166 which you can…

    Max

    October 13, 2023
    Intune, Proactive Remediations, Windows
    Intune, Notepad++, PowerShell, Proactive Remediations, Vulnerability, Windows
  • 8/10/23 News: Updates and Future Plans

    This is the first in what will likely be many “News:” articles of mine. These are pretty much exactly what they sound like, just simple newsletters regarding what I have been working on, some things that have received some updates and adjustments, and what you can expect coming up. Updates: Fast Startup: System Usage &…

    Max

    October 8, 2023
    News and Updates
    Azure, Log Analytics, PowerShell
  • Log Analytics for Windows Endpoint System Usage & Authentication Monitoring Part 1.6: Deploying the Script

    Introduction: With your data ingesting and workbooks deployed, we are now ready to start deploying the collector via Proactive Remediations in Intune. This will likely be the final article in this series, at least for now. In this section, we will cover… Requirements: This should be pretty obvious, but you need to have completed the setup…

    Max

    September 9, 2023
    Intune, Log Analytics, Proactive Remediations, Windows, Windows Events
    Intune, Log Analytics, PowerShell, Proactive Remediations, Windows, Windows Events
  • Log Analytics for Windows Endpoint System Usage & Authentication Monitoring Part 1.5: Importing the Workbook

    Introduction: With your data now ingesting into Log Analytics, granted the collectors not yet deployed, we are ready to begin setting up our workbooks to further confirm data is coming in properly. Note: It would be a good idea to have at least a few devices manually ingest some data before starting this process. In this…

    Max

    September 9, 2023
    Azure, KQL, Log Analytics, Windows Events
    Azure, Log Analytics, Workbook
  • Log Analytics for Windows Endpoint System Usage & Authentication Monitoring Part 1.4: Sample Data, Tables, DCRs, Initial Ingestion

    Introduction: We have now covered what this solution does and its cost, at least from an ingestion standpoint. Now, we will finally be deploying something! In this article, we will generate our sample data, use it to create our new tables and DCRs, grant the appropriate permissions on those DCRs, and perform an initial ingestion!…

    Max

    September 9, 2023
    Azure, Function App, Log Analytics, Windows, Windows Events
    Azure, DCR, Function App, Log Analytics, Windows
  • Log Analytics for Windows Endpoint System Usage & Authentication Monitoring Part 1.3: Configure Event Auditing and Power Settings

    As explained, the System Usage monitoring makes use of Windows Event logs for data gathering. While the Event Log has a ton of useful information by default, some events only log when enabled via an additional policy. Additionally, some won’t log at all until certain power settings are changed (See part 1.1, startup and shutdown…

    Max

    September 8, 2023
    Intune, Log Analytics, Policy, Windows, Windows Events
    Intune, Policy, Settings Catalog, Windows, Windows Events
  • Log Analytics for Windows Endpoint System Usage & Authentication Monitoring Part 1.2: Cost

    Introduction: Following my initial articles describing what is collected, how it is displayed, and the quirks that the collector has, this article will cover the cost of this solution. Before we start, please know that I am no Azure cost “expert.” I can point you in the right direction and provide examples, but you need…

    Max

    September 5, 2023
    Azure, Log Analytics, Windows, Windows Events
    Azure, DCR, Function App, Intune, Log Analytics, PowerShell, Proactive Remediations, Windows
  • Log Analytics for Windows Endpoint System Usage & Authentication Monitoring Part 1.1: Technical Details and Limitations

    Introduction: In my initial article of this series, I mentioned that there are several asterisks, footnotes, limitations, and caveats to understand with this solution. To elaborate a bit further, this article explains more about how this works, the details of the events we capture, what we don’t/can’t capture for one reason or another, and what…

    Max

    August 31, 2023
    Log Analytics, Windows, Windows Events
    Azure, DCR, Events, Log Analytics, PowerShell
  • Log Analytics for Windows Endpoint System Usage & Authentication Monitoring Part 1.0: Overview

    Introduction: For those of you familiar with my work on Log Analytics, you know that I have at several times throughout several articles touted the ability for PowerShell to pull Windows Events, including those from the Security log which the now old Log Analytics agent could not do. And, unfortunately, the new AMA has other…

    Max

    August 27, 2023
    Azure, Intune, KQL, Log Analytics, PowerShell, Windows, Windows Events
    Azure, DCR, Intune, Log Analytics, PowerShell, Proactive Remediations, Windows
  • PowerShell DCR Log Analytics for Windows Endpoints Part 1.9: Deploying the Collector Script via Proactive Remediations

    Introduction: With your data ingesting and workbooks deployed, we are now ready to start to deploy the collector out via Proactive Remediations in Intune. This will likely be the final article in this series, at least for now. To be clear, I mean just the Windows Endpoints series for App/Device/Admin Inventory. There are quite a…

    Max

    August 13, 2023
    Azure, Intune, Log Analytics, Proactive Remediations
    Azure, DCR, Intune, Log Analytics, Proactive Remediations
←Previous Page
1 2 3 4 5 6 … 9
Next Page→

Blog at WordPress.com.

  • Subscribe Subscribed
    • Azure to the Max
    • Already have a WordPress.com account? Log in now.
    • Azure to the Max
    • Subscribe Subscribed
    • Sign up
    • Log in
    • Report this content
    • View site in Reader
    • Manage subscriptions
    • Collapse this bar