4.2 Onboarding via GPO and local script, MDE from Zero to Hero

แชร์
ฝัง
  • เผยแพร่เมื่อ 5 ก.ย. 2024
  • Welcome to Microsoft Defender for Endpoint - From Zero to Hero, Module 4.2 - Onboarding via GPO and local script
    In this video you will see the following:
    1 - Onboarding devices via local policy
    2 - GPO configuration
    3 - Onboarding devices via GPO
    **COURSE OUTLINE**
    I have plans to record 20+ videos and the course outline is not set in stone. Below are the modules already available and the ones on the horizon:
    1. Product Overview - www.youtube.co....
    1.1 - Minimum requirements and licensing - • 1.1 Minimum requiremen...
    2 - Design & key decisions
    2.1 Design: MDE settings deployment - • 2.1 Design: MDE Settin...
    2.3 - Design - Best practise for full scan - • 2.3 - Design - Best pr...
    2.10 Device tag overview - • 2.10 Device tag overvi...
    2.11 Deploying device tag via portal, GPO and Intune - • 2.11 Deploying device ...
    2.12 - Device auto-tagging via Logic Apps - • 2.12 Device auto-taggi...
    3 - MDE deployment
    3.1 - Initial setup and advanced settings - • 3.1 Initial setup and ...
    3.2 - Deploying settings via MEM - • 3.2 Deploying AV sett...
    3.3 - Deploying settings via GPO - • 3.3 Deploying AV setti...
    4 - Onboarding
    4.1 - Onboarding overview - • 4.1 Onboarding overvie...
    4.2 - Onboarding via GPO and local script - • 4.2 Onboarding via GPO...
    4.3 - Onboarding via Microsoft Endpoint Manager - • 4.3 Onboarding via MEM...
    4.4 - Onboarding via helper script - • 4.4 Onboarding via hel...
    4.5 - Auto Onboarding via Defender for Cloud
    5 - Migration from 3rd party solution - • 5 .1 Migration from 3r...
    6 - Monitoring
    6.1 - Alerts and incidents management - • 6.1 Alerts & incidents...
    6.2 - Ransomware attack investigation - • 6.2 Ransomware attack ...
    6.3 - Dealing with Ransomware via Sentinel automation - • 6.3 Dealing with Ranso...
    7 - Integration with SIEM (Security Information and Event Management)
    8 - Troubleshooting
    8.1 - Troubleshooting mode deep dive - • 8.1 Troubleshooting mo...
    8.2 - Troubleshooting PowerShell output issue - • 8.2 Troubleshooting Po...
    My Microsoft Defender for Endpoint - From Zero to Hero playlist can be accessed from
    • Introducing my Defende...
    Please consider subscribing to my channel for the latest updates and upcoming modules.
    Thanks for supporting this project, I hope you enjoy and learn a lot
    Thanks for watching
    Jackson Felden
    Reference: How to create and manage the Central Store for Group Policy Administrative Templates in Windows at learn.microsof...
    #MicrosoftDefenderForEndpoint #MDE #CyberSecurity

ความคิดเห็น • 11

  • @EqDior
    @EqDior 2 หลายเดือนก่อน

    isnt the onboarding script the same for each OS? The only differences is the msi file that is needed for 2012 and 2016. Awesome Video by the way!

  • @tzuriisrael6716
    @tzuriisrael6716 ปีที่แล้ว +2

    thanks, I enjoyed your video, can you do a video on how to remediate vulnerabilities in Defender the basics to using scripts step by step etc... thanks

  • @shat1478
    @shat1478 หลายเดือนก่อน

    It is helpful video, cheer!! but I have some issue on my branch offices with onboard by GPO... it seems client computers can't run WindowsDefenderATPOnboardingScript.cmd has block on UNC path file.. have you faced issue like this ?

  • @IamHere2007de
    @IamHere2007de 11 หลายเดือนก่อน

    Great video.
    Let’s say you start a pilot deployment for Windows servers. Which servers would you add first without having issues and which servers should I be careful with?

  • @tanu14188
    @tanu14188 8 หลายเดือนก่อน

    Very good and simple to understand ... Thanks :)

  • @lawaluthman5536
    @lawaluthman5536 4 หลายเดือนก่อน

    always very good

  • @drlorafrancis
    @drlorafrancis ปีที่แล้ว

    But, what if we already have a AV solution and you need to uninstall that AV solution before you onboard the MDE for Desktops or Servers, then how would you do that? I am not sure you would see it, but if you do see this question, please do respond. Can you offboard the existing AV solution like SEP or Trend and then use MDE for Windows 10/11 or Servers?

  • @VenkateshKadiri66
    @VenkateshKadiri66 ปีที่แล้ว

    I have Windows Server 2012 (not R2) but the onboarding package is available only for R2. Can I use the same?

  • @mr.tsunyin251
    @mr.tsunyin251 ปีที่แล้ว +1

    Is there ways to use group policy to install the msi also? So all the onboard process can be automated. Thx

    • @jacksonfeldencloudsecurity
      @jacksonfeldencloudsecurity  ปีที่แล้ว

      Hi there,
      yes, there is, please check details at learn.microsoft.com/en-us/troubleshoot/windows-server/group-policy/use-group-policy-to-install-software
      I haven't been using GPO to deploy the MDE client because GPO doesn't provide great reports about the deployment status.
      I've been using Microsoft Configuration Manager instead.