Skip to content

Commit 050895f

Browse files
authored
Merge branch 'main' into WI494055-offboard-devices-mde
2 parents 9e461e0 + 7988e8c commit 050895f

File tree

3 files changed

+13
-5
lines changed

3 files changed

+13
-5
lines changed

.github/workflows/AutoPublish.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,8 @@ permissions:
77

88
on:
99
schedule:
10-
- cron: "25 2,5,8,11,14,17,20,22 * * *" # Times are UTC based on Daylight Saving Time. Need to be adjusted for Standard Time. Scheduling at :25 to account for queuing lag.
10+
# - cron: "25 2,5,8,11,14,17,20,22 * * *" # Times are UTC based on Daylight Saving Time (~Mar-Nov). Scheduling at :25 to account for queuing lag.
11+
- cron: "25 3,6,9,12,15,18,21,23 * * *" # Times are UTC based on Standard Time (~Nov-Mar). Scheduling at :25 to account for queuing lag.
1112

1213
workflow_dispatch:
1314

defender-endpoint/respond-machine-alerts.md

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ ms.service: defender-endpoint
55
ms.author: painbar
66
author: paulinbar
77
ms.localizationpriority: medium
8-
ms.date: 09/01/2025
8+
ms.date: 11/05/2025
99
manager: bagol
1010
audience: ITPro
1111
ms.collection:
@@ -19,6 +19,7 @@ appliesto:
1919
- Microsoft Defender for Business
2020

2121
---
22+
2223
# Take response actions on a device
2324

2425

@@ -362,7 +363,9 @@ When an identity in your network might be compromised, you must prevent that ide
362363
> Blocking incoming communication with a "contained" user is supported on onboarded Microsoft Defender for Endpoint Windows 10 and 11 devices (Sense version 8740 and higher), Windows Server 2019+ devices, and Windows Servers 2012R2 and 2016 with the modern agent.
363364
364365
> [!IMPORTANT]
365-
> Once a **Contain user** action is enforced on a domain controller, it starts a GPO update on the Default Domain Controller policy. A change of a GPO starts a sync across the domain controllers in your environment. This is expected behavior, and if you monitor your environment for AD GPO changes, you may be notified of such changes. Undoing the **Contain user** action reverts the GPO changes to their previous state, which will then start another AD GPO synchronization in your environment. Learn more about [merging of security policies on domain controllers](/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/jj966251(v=ws.11)#merging-of-security-policies-on-domain-controllers).
366+
> As part of the active protection provided by Microsoft Defender for Endpoint, a distributed mechanism can apply LSA Policy to prevent compromised users from accessing machines in your organization. Currently, when this policy is applied on Domain Controllers, it may cause Group Policy synchronization activity across domain controllers.
367+
>
368+
> We are gradually rolling out a new solution by integrating with new OS APIs. This deployment will be phased and thoroughly tested to ensure stability and security. During this rollout, LSA Policy enforcement on your servers will be temporarily removed to prevent potential GPO sync. This change will remain in effect until the rollout is complete.
366369
367370
### How to contain a user
368371

defender-endpoint/troubleshoot-settings.md

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ manager: bagol
77
ms.reviewer: yongrhee
88
ms.service: defender-endpoint
99
ms.topic: troubleshooting-general
10-
ms.date: 04/01/2025
10+
ms.date: 11/06/2025
1111
ms.subservice: ngp
1212
ms.localizationpriority: medium
1313
ms.collection: # Useful for querying on a set of strategic or high-priority content.
@@ -16,11 +16,12 @@ search.appverid: MET150
1616
f1.keywords: NOCSH
1717
audience: ITPro
1818
appliesto:
19-
- Microsoft Defender for Business
19+
- Microsoft Defender for Business
2020
- Microsoft Defender for Individuals
2121
- Microsoft Defender Antivirus
2222

2323
---
24+
2425
# Troubleshoot Microsoft Defender Antivirus settings
2526

2627

@@ -52,6 +53,9 @@ To remove policy conflicts, here's our current, recommended process:
5253

5354
## Step 1: Understand the order of precedence
5455

56+
> [!NOTE]
57+
> Microsoft Defender for Endpoint attach configurations can be overridden by other configuration tools that write to the same registry location.
58+
5559
When policies and settings are configured in multiple tools, in general, here's the order of precedence:
5660

5761
1. Microsoft Defender for Endpoint security settings management

0 commit comments

Comments
 (0)