Microsoft Defender for Endpoint security and EDR telemetry offer a powerful fail safe for organizations. Nathan Taylor and Nick Ross look at the technical advantages of enabling passive mode to maximize Microsoft 365 licensing. They examine how this configuration allows businesses to retain their preferred third-party EDR while gaining access to Microsoft identity signals and SmartScreen phishing protection.
The conversation highlights the value of the Microsoft XDR portal for threat hunting and how additional telemetry improves the accuracy of Security Copilot. By utilizing the built in sensor for Endpoint DLP and web content filtering, IT leaders can simplify their security stack without sacrificing performance.
What You’ll Learn:- How to configure passive mode to prevent antivirus conflicts on Windows devices
- The specific telemetry benefits for Security Copilot and incident response
- Ways to implement Endpoint DLP to track data exfiltration to USB or personal email
- Why the Defender for Business vulnerability management tool outperforms basic checklists
- The truth about using block mode as a secondary detection engine for known threats
- Steps for testing this setup with a pilot group using Intune profiles
About the Guest:
Nick Ross is the CEO of CloudCapsule and a three-time Microsoft MVP specializing in Microsoft 365 security and automation. As the creator of the T-Minus 365 YouTube channel, he has built a following by breaking down complex Microsoft topics into practical guidance for MSPs, IT professionals, and SMBs.
Nick's career spans leadership roles at CloudCapsule, Sourcepass, Summit Technology, and Pax8, where he helped shape products and services across the Microsoft ecosystem. Known for his hands-on approach to security assessments, remediation, identity protection, and Microsoft best practices, Nick is dedicated to helping organizations secure and optimize their Microsoft environments.
Episode Highlights:
[00:02:45] The Concept of Passive Mode Nick explains that passive mode allows Microsoft security tools to coexist with third-party software like CrowdStrike. This setup ensures you still receive the benefits of threat and vulnerability management included in your current subscription without causing system instability.
[00:05:12] Connecting Identity to the Endpoint Nathan points out that Microsoft sees both sides of a connection, linking logins to the actual device. This visibility provides better detection for man in the middle phishing attacks that standalone EDR tools might miss.
[00:08:58] Preparing for the Era of AI AI tools require a massive amount of data to provide accurate results for security teams. Enabling the Defender sensor ensures Security Copilot has the telemetry needed to assist with complex incident response tasks.
[00:11:00] Endpoint DLP for Data Governance Nick describes how the Defender sensor tracks sensitive data movement, such as files being copied to USB drives or personal Gmail accounts. This functionality works natively in the operating system without requiring additional heavy agents.
[00:15:30] Automating the Configuration Most modern Windows devices detect an active third-party antivirus and switch to passive mode automatically. However, using specific registry keys is a best practice to ensure servers and workstations remain stable during the process.
[00:27:14] Consolidating the Security Stack Moving security signals into a single portal like Microsoft Lighthouse or the XDR dashboard reduces operational overhead. It allows teams to triage alerts from multiple clients or departments from one central location.
Episode Resources:
Standard security is a checklist. True resilience is a graph. If you want to understand how to use your security data to create a proactive defense strategy, reach out to the Sourcepass MCOE team: https://sourcepassmcoe.com/demystifying-microsoft-contact
Nick Ross on LinkedIn
Nathan Taylor on LinkedIn
Quotes- "I like to think about it in the sense of the funnel. If SentinelOne does its job and it analyzes some event or action on the endpoint and says, 'hey, I don't think this is malicious,' then Microsoft could come in at the end of that and still say, 'this is malicious' and take action and block events."
- "ASR rules are super powerful and they can actually stop a lot, but they are super disruptive in legacy environments.”
- “So with modern clients, you can audit it for about forty-five days and probably see that nothing's gonna really break, and then enforce that, which gives you a lot of protections."
- "AI is always better with more data. And so if you're running security copilot and CrowdStrike, you probably still want passive mode because the data that Security Copilot gets through Sentinel and through collecting all those back end pieces of telemetry is going to help you someday with incident response."
- "Nothing turns a high-end computer into potato like two antiviruses fighting over a computer.”
Demystifying Microsoft is handcrafted by our friends over at: fame.so