Ru Campbell profile picture

Follow Ru

Ru Campbell

Petri Contributor

Ru (Ruairidh) Campbell is a Microsoft MVP and Microsoft security solutions architect, helping customers with security, compliance, identity, and modern device management. Specializing in Azure AD, Enterprise Mobility + Security, and Microsoft Defender.

LATEST

Security

Five Tactics Towards Achieving Zero Trust with Microsoft Entra ID (Azure Active Directory)

Last Update: Jun 03, 2024

For any modern enterprise that uses Microsoft Entra ID (previously Azure Active Directory) to manage user and service access to cloud resources, it’s hard to escape the term Zero Trust (ZT), which implies that your organization must have a layered approach to security. In this article, you’ll learn about five Microsoft Zero Trust tactics for…

View Article

Understanding Microsoft Information Protection

Last Update: Sep 04, 2024

There are a lot of compliance-based services across Microsoft 365’s licensing options. At the highest level, a Microsoft 365 E5 subscription for a tenant gives administrators a ton of toys to play with. The naming, marketing, and placement of the capabilities you get can be fuzzy. In this article, we’ll tackle Microsoft Information Protection (MIP),…

View Article

Using Microsoft 365 Defender Threat Analytics to Improve Security

Last Update: Sep 04, 2024

In this article, I’m going to describe how to use Microsoft 365 Defender Threat Analytics to improve security in your organization. Over three Petri articles, we’ve dived into what Microsoft Defender for Endpoint (MDE) is, how you can migrate to it, and how it should be configured. Part 1: Understanding Microsoft Defender for Endpoint and…

View Article

Microsoft Defender for Endpoint – Important Service and Endpoint Settings You Should Configure Right Now

Last Update: Sep 04, 2024

Microsoft Defender for Endpoint (MDE) is much more than a traditional antivirus service. Now being offered in Plan 1 and Plan 2, the full offering you get with Plan 2 not only provides antivirus capabilities but also extended detection and response, attack surface reduction rules to harden the OS against common threat mechanisms, and threat…

View Article

How to Install the New Microsoft Defender for Endpoint Agent on Windows Server 2012 R2 and 2016

Last Update: Sep 04, 2024

New protection capabilities for Microsoft Defender for Endpoint (MDE) customers landed in public preview, Oct 7th 2021, for Windows Server 2012 R2 and Windows Server 2016.  With the public preview, Windows Server 2012 R2 and 2016 gain ‘functional equivalence‘ to Windows Server 2019, thanks to a new agent that is being described as the ‘unified…

View Article

Guide: How to Plan for Microsoft Defender Endpoint Deployments and Migrations

Last Update: Sep 04, 2024

When approaching a rollout of Microsoft Defender for Endpoint (MDE) for your organization, it can be difficult to know where to start.  In my last article, MDE was explained at a high level: what it is and why you should care.  This time, we will get into the weeds of how to actually plan for…

View Article

Understanding Microsoft Defender for Endpoint and How It Protects Your Data

Last Update: Sep 04, 2024

Microsoft Defender for Endpoint (MDE, previously known as Microsoft Defender Advanced Threat Protection) is Microsoft’s endpoint security platform that goes far and beyond the traditional anti-malware engine and firewall to protect against the modern cybersecurity threats an organization faces.  An evolving solution since it was first announced in 2016, MDE is part of the Microsoft…

View Article

Guide: Limit Microsoft 365 Access to Corporate Devices with Conditional Access

Last Update: Sep 04, 2024

World events since March 2020 have highlighted one of the key benefits of Office 365 and cloud-based SaaS services in general: they are available any time, any place, on any device.  As the world was forced to work from home, Office 365 apps such as Teams, Outlook, SharePoint, and OneDrive could easily be accessed outwith…

View Article

How to Migrate Group Policy Windows Firewall Rules to Intune

Last Update: Sep 04, 2024

As you make the move from Microsoft on-premises infrastructure to the cloud, you’ll move from Group Policy management of your endpoints to MDM management.  This move isn’t always a “lift and shift” process because there isn’t always a 1-to-1 relationship between the settings available in Group Policy and those in Intune.  Additionally, you need to…

View Article

How to Manage Local Administrators and Groups with Intune

Last Update: Sep 04, 2024

When we think about administrative rights on Intune-enrolled Windows 10 devices, we need to consider two possible device states for that device: Azure AD joined (AADJ), or Hybrid Azure AD joined (HAADJ).  This is due to the different administrative roles available at the directory level. For Azure AD joined devices, at the time of performing…

View Article

How to Control Intune Enrollment with Enrollment Restrictions

Last Update: Feb 10, 2025

Enrollment restrictions are sets of rules assigned to Azure AD groups.  There are two types of enrollment restrictions: device type and device limit.

View Article

How to Automatically Hybrid Azure AD Join and Intune Enroll PCs

Last Update: Sep 04, 2024

On-premises Active Directory domain-joined PCs have typically been managed with tools such as Group Policy.  At larger scales, you may have Configuration Manager or third-party tools.  The availability of Intune (part of Endpoint Manager) in Microsoft 365 subscriptions such as Business Premium and E3 has opened up an alternative.  The benefit many are seeing over…

View Article
Go to page