Skip to content

Commit 5b431bc

Browse files
authored
Merge branch 'main' into patch-9
2 parents 8befc3e + 6172694 commit 5b431bc

7 files changed

+10
-9
lines changed

ATPDocs/security-assessment-edit-misconfigured-acl.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ ms.date: 11/20/2023
55
ms.topic: how-to
66
---
77

8-
# Security assessment: Edit misconfigured certificate templates ACL (ESC4) (Preview)
8+
# Security assessment: Edit misconfigured certificate templates ACL (ESC4)
99

1010
This article describes Microsoft Defender for Identity's **Misconfigured certificate template ACL** security posture assessment report.
1111

ATPDocs/security-assessment-edit-misconfigured-ca-acl.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ ms.date: 11/14/2023
55
ms.topic: how-to
66
---
77

8-
# Security assessment: Edit misconfigured Certificate Authority ACL (ESC7) (Preview)
8+
# Security assessment: Edit misconfigured Certificate Authority ACL (ESC7)
99

1010
This article describes Microsoft Defender for Identity's **Misconfigured certificate authority ACL** security posture assessment report.
1111

ATPDocs/security-assessment-edit-misconfigured-enrollment-agent.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ ms.date: 11/20/2023
55
ms.topic: how-to
66
---
77

8-
# Security assessment: Edit misconfigured enrollment agent certificate template (ESC3) (Preview)
8+
# Security assessment: Edit misconfigured enrollment agent certificate template (ESC3)
99

1010
This article describes Microsoft Defender for Identity's **Misconfigured enrollment agent certificate template** security posture assessment report.
1111

ATPDocs/security-assessment-edit-misconfigured-owner.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ ms.date: 11/14/2023
55
ms.topic: how-to
66
---
77

8-
# Security assessment: Edit misconfigured certificate templates owner (ESC4) (Preview)
8+
# Security assessment: Edit misconfigured certificate templates owner (ESC4)
99

1010
This article provides an overview of Microsoft Defender for Identity's **Misconfigured certificate templates owner (ESC4)** security posture assessment report.
1111

ATPDocs/security-assessment-edit-overly-permissive-template.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ ms.date: 11/20/2023
55
ms.topic: how-to
66
---
77

8-
# Security assessment: Edit overly permissive certificate template with privileged EKU (Any purpose EKU or No EKU) (ESC2) (Preview)
8+
# Security assessment: Edit overly permissive certificate template with privileged EKU (Any purpose EKU or No EKU) (ESC2)
99

1010
This article describes Microsoft Defender for Identity's **Overly permissive certificate template with privileged EKU** security posture assessment report.
1111

ATPDocs/security-assessment-enforce-encryption-rpc.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ ms.date: 11/20/2023
55
ms.topic: how-to
66
---
77

8-
# Security assessment: Enforce encryption for RPC certificate enrollment interface (ESC11) (Preview)
8+
# Security assessment: Enforce encryption for RPC certificate enrollment interface (ESC11)
99

1010
This article describes Microsoft Defender for Identity's **Enforce encryption for RPC certificate enrollment** security posture assessment report.
1111

defender-xdr/advanced-hunting-deviceinfo-table.md

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ ms.custom:
1818
- cx-ti
1919
- cx-ah
2020
ms.topic: reference
21-
ms.date: 01/16/2024
21+
ms.date: 12/04/2024
2222
---
2323

2424
# DeviceInfo
@@ -39,7 +39,7 @@ For information on other tables in the advanced hunting schema, [see the advance
3939

4040
| Column name | Data type | Description |
4141
|-------------|-----------|-------------|
42-
| `Timestamp` | `datetime` | Date and time when the event was recorded |
42+
| `Timestamp` | `datetime` | Last date and time recorded for the device |
4343
| `DeviceId` | `string` | Unique identifier for the device in the service |
4444
| `DeviceName` | `string` | Fully qualified domain name (FQDN) of the device |
4545
| `ClientVersion` | `string` | Version of the endpoint agent or sensor running on the device |
@@ -89,8 +89,9 @@ You can use the following sample query to get the latest state of a device:
8989
```kusto
9090
// Get latest information on user/device
9191
DeviceInfo
92+
| extend IngestionTime = ingestion_time()
9293
| where DeviceName == "example" and isnotempty(OSPlatform)
93-
| summarize arg_max(Timestamp, *) by DeviceId
94+
| summarize arg_max(IngestionTime, *) by DeviceId
9495
```
9596

9697
## Related topics

0 commit comments

Comments
 (0)