Windows 10: Is there a way to get a device first seen date in defender for endpoint advanced hunting

Discus and support Is there a way to get a device first seen date in defender for endpoint advanced hunting in Windows 10 Gaming to solve the problem; I am looking to write a daily query that gets new devices that have not previously been seen before but am struggling to find an effective way to do... Discussion in 'Windows 10 Gaming' started by Will - cyber security, Nov 29, 2023.

  1. Is there a way to get a device first seen date in defender for endpoint advanced hunting


    I am looking to write a daily query that gets new devices that have not previously been seen before but am struggling to find an effective way to do this, any help would be greatly appreciated

    :)
     
    Will - cyber security, Nov 29, 2023
    #1
  2. Brink Win User

    Microsoft Defender for Endpoint now supports Windows 10 on Arm devices

    Source: https://www.microsoft.com/security/b...ows-10-on-arm/


     
    Brink, Nov 29, 2023
    #2
  3. AnkushDeb Win User
    I would like to remove device from Microsoft Defender for Endpoint portal

    I would like to remove device from Microsoft Defender for Endpoint portal without running any script on the end PC. The end PC is no more active but still showing in the ATP Portal. Need suggestion
     
    AnkushDeb, Nov 29, 2023
    #3
  4. Bryll P. Win User

    Is there a way to get a device first seen date in defender for endpoint advanced hunting

    Defender for Business onboarding endpoint device Error id: 15 Error level: 1

    Hi John,



    Thank you for writing us here in Microsoft Community.



    The error message "onboarding endpoint device Error id: 15 error level: 1 The service name is invalid" indicates that there is an issue with the service name that is being used to onboard the device to Microsoft Defender for Business.



    To resolve this issue, you can try the following steps:

    1. Make sure that you are using the correct service name for Microsoft Defender for Business. The service name should be "Microsoft Defender for Endpoint Onboarding" (without the quotes).

    2. Check if the service is running on the device. You can do this by opening the Services app (services.msc) and looking for the "Microsoft Defender for Endpoint Onboarding" service. If the service is not running, start it and try onboarding the device again.

    3. If the issue persists, try restarting the device and then attempt to onboard it again.



    Should issue persists, try following additional steps:

    • Check the Diagnostic Data Service: Ensure that the diagnostic data service is enabled and set to start
    • Check Internet Connection: Make sure your device has a stable internet connection
    • Check Microsoft Defender Antivirus Policy: Ensure that Microsoft Defender Antivirus is not disabled by a policy
    • View Agent Onboarding Errors in the Device Event Log: Click Start, type Event Viewer, and press Enter. Go to Windows Logs > Application. Look for an event from WDATPOnboarding event source
    • Stop the Service: Go to “Control Panel > Administrative Tools > Services”, find the service “Windows Defender Advanced Threat Protection Service”, right-click on the service and click “Stop”. This will stop the service and prevent it from running on the host
    • Create a new Windows user account: Select Start > Settings > Accounts and then select Family & other users. > Next to Add other user, select Add account. > Select I don't have this person's sign-in information, and on the next page, select Add a user without a Microsoft account. > Enter a username and Next > Go back to Family & other users > Change account type to Administrator > Restart computer to switch to new user account.
    If needed, you may check similar posts with answers from experts on Microsoft Q and A Questions - Microsoft Q&A and Community page Microsoft 365 Defender - Microsoft Community Hub



    We will leave this thread open for our MVPs or other members who are experts about this concern to share their answers.



    Honored to be part of your journey,

    Bryll

    Microsoft Community Agent
     
    Bryll P., Nov 29, 2023
    #4
Thema:

Is there a way to get a device first seen date in defender for endpoint advanced hunting

Loading...
  1. Is there a way to get a device first seen date in defender for endpoint advanced hunting - Similar Threads - device date defender

  2. Is there a way to get a device first seen date in defender for endpoint advanced hunting

    in Windows 10 Software and Apps
    Is there a way to get a device first seen date in defender for endpoint advanced hunting: I am looking to write a daily query that gets new devices that have not previously been seen before but am struggling to find an effective way to do this, any help would be greatly appreciated...
  3. Is there a way to get a device first seen date in defender for endpoint advanced hunting

    in AntiVirus, Firewalls and System Security
    Is there a way to get a device first seen date in defender for endpoint advanced hunting: I am looking to write a daily query that gets new devices that have not previously been seen before but am struggling to find an effective way to do this, any help would be greatly appreciated...
  4. ATP - Advance hunting queries

    in AntiVirus, Firewalls and System Security
    ATP - Advance hunting queries: HI Team,Can you please help me to find the Advance hunting query for the below requirementantimalware client version for specific OS versionRegards,Harish https://answers.microsoft.com/en-us/protect/forum/all/atp-advance-hunting-queries/06fff286-47df-4804-a056-00675a0cdcb7
  5. Microsoft Defender for Endpoint

    in AntiVirus, Firewalls and System Security
    Microsoft Defender for Endpoint: Hi Reader, Does Microsoft Defender for endpoint have application whitelisting functionality? Any recommended implementation article would be appreciated.Thank you....
  6. Microsoft Defender for Endpoint

    in Windows 10 Gaming
    Microsoft Defender for Endpoint: Hi Reader, Does Microsoft Defender for endpoint have application whitelisting functionality? Any recommended implementation article would be appreciated.Thank you....
  7. Microsoft Defender for Endpoint

    in Windows 10 Software and Apps
    Microsoft Defender for Endpoint: Hi Reader, Does Microsoft Defender for endpoint have application whitelisting functionality? Any recommended implementation article would be appreciated.Thank you....
  8. "Date Modified" no longer seen

    in Windows 10 Network and Sharing
    "Date Modified" no longer seen: I no longer see the "date modified" option when I'm trying to access recently saved files in Windows. This was so important to me for my work. Please help!! https://answers.microsoft.com/en-us/windows/forum/all/date-modified-no-longer-seen/9fdb3b86-22c2-4c9a-a658-28590270190b
  9. microsoft defender for endpoint

    in AntiVirus, Firewalls and System Security
    microsoft defender for endpoint: Hi fam, please help Microsoft Defender for Endpoint does not show alerts at all. please help what might be the problem. * Moved from Health & Band https://answers.microsoft.com/en-us/protect/forum/all/microsoft-defender-for-endpoint/1dfa5bbd-396a-4cb9-9f2d-d55ae4c1cf2c
  10. Defender ATP Multiple questions Rules/Definitions list, indicators, advanced hunting

    in AntiVirus, Firewalls and System Security
    Defender ATP Multiple questions Rules/Definitions list, indicators, advanced hunting: Hello, 1 Is it possible to getread the list of active defender rules/definitions? For example, the list of all file hashes that defender checks for? Or all the malware/virus samples defender already has protection for. I can search from the securitycenter but doing for each...