-
-
Notifications
You must be signed in to change notification settings - Fork 263
Description
Are you sure the Security measure is not already implemented?
- Yes, I have checked and the Security measure I'm suggesting to be implemented is not duplicate. 🫡
Please explain your new Security measure suggestion
Do not require run as admin to just import CSV logs from MDE
This is a Security app, and really decent and way better than Microsofts own tools. Any Application though as a security guy I am not typically going to trust as admin, let alone allow it to log into my security panel. However being able to export the logs out of MDE and then load them in and create policies is a great feature. However, I am not sure why i would ever need to be running the application as an administrator to just import these CSV's i downloaded. Also, you may have, and actually should have different people have different access to certain systems.
So for example, the security operator in defender can be querying those logs from defender advanced hunting and then export the CSV for the team managing Intune to deploy. They may not be the same people as this allows separation of duties.
To reproduce launch the application as a standard user not admin. The Click on MDE Advanced Hunting this instantly wants to run as admin. I didn't, I did launch it in a windows Sandbox as admin to see what was in there and yeah as Local and being able to load CSV exports is really an awesome feature. But not something you need to be running as admin for.
BTW Running the app as admin on a machine takes on the Admin profile. So You have to manually go load dark mode. etc.