Skip to content

[Suggestion]: Don't require run as Administrator for importing MDE csv files #895

@JeffsRealm

Description

@JeffsRealm

Are you sure the Security measure is not already implemented?

  • Yes, I have checked and the Security measure I'm suggesting to be implemented is not duplicate. 🫡

Please explain your new Security measure suggestion

Do not require run as admin to just import CSV logs from MDE

This is a Security app, and really decent and way better than Microsofts own tools. Any Application though as a security guy I am not typically going to trust as admin, let alone allow it to log into my security panel. However being able to export the logs out of MDE and then load them in and create policies is a great feature. However, I am not sure why i would ever need to be running the application as an administrator to just import these CSV's i downloaded. Also, you may have, and actually should have different people have different access to certain systems.

So for example, the security operator in defender can be querying those logs from defender advanced hunting and then export the CSV for the team managing Intune to deploy. They may not be the same people as this allows separation of duties.

To reproduce launch the application as a standard user not admin. The Click on MDE Advanced Hunting this instantly wants to run as admin. I didn't, I did launch it in a windows Sandbox as admin to see what was in there and yeah as Local and being able to load CSV exports is really an awesome feature. But not something you need to be running as admin for.

BTW Running the app as admin on a machine takes on the Admin profile. So You have to manually go load dark mode. etc.

Metadata

Metadata

Assignees

Labels

AppControl Manager 🛡️Any item labeled with this is related to the AppControl Manager application.Suggestion ⚡Label used to describe New Security Measure Suggestions

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions