logo

Two MDO field reports every IT security lead should read

ID: 2f6bc437-ab49-5933-b9f8-2850bfc932f5

STIX ID: report--2f6bc437-ab49-5933-b9f8-2850bfc932f5

Feed Name: Security Boulevard

Date Published: 2026-04-21

Date Updated: 2026-04-22

Author: Audian Paxson

...
...

This post summarizes two field reports on Microsoft Defender for Office (Explorer and Quarantine), calling out operational transparency failures—limited query operators and odd Unicode matching in Explorer, opaque quarantine workflows, hidden RBAC menus, 30-day log/quarantine retention, and silent preset-policy overrides—and advises operators to audit policy stacks, forward logs for longer retention, sharpen KQL skills, and include transparency as an evaluation criterion when selecting email security tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.