Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
12 changes: 6 additions & 6 deletions AddMSPApp/huntress.app.xml
Original file line number Diff line number Diff line change
@@ -1,15 +1,15 @@
<ApplicationInfo xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" ToolVersion="1.8.3.0">
<Name>install.ps1</Name>
<UnencryptedContentSize>8859</UnencryptedContentSize>
<UnencryptedContentSize>17583</UnencryptedContentSize>
<FileName>huntress.intunewin</FileName>
<SetupFile>install.ps1</SetupFile>
<EncryptionInfo>
<EncryptionKey>0wrFiLHex//63XQZEbX535qvhQE5+MiZmfPho1CMrT4=</EncryptionKey>
<MacKey>UOlXFsrh+Pq6ZZNmg2+gzuTCSDAxQNUDVkc6oR5SVAY=</MacKey>
<InitializationVector>x0cPnMjK6AZARRPhOfC5pg==</InitializationVector>
<Mac>z+N/v0mfq8T871kS07/QZ1Lgay2hRabSxwDWRKz3fG4=</Mac>
<EncryptionKey>m7JyMp35G+Kxi3slrppvQYJdgmgPJOkTHZGLHBCnFuY=</EncryptionKey>
<MacKey>DxBAhgMG5nEedy933yQgx2mzTJbyku/ax8HEMYFRMQE=</MacKey>
<InitializationVector>hdOmI6VtHXWZq1Xr2icByw==</InitializationVector>
<Mac>I6tLz8+o06fRsbbKpcE0J/PMA8/2l+B1jyHWarM8NUM=</Mac>
<ProfileIdentifier>ProfileVersion1</ProfileIdentifier>
<FileDigest>z8JuA/5iCrLM1cRkhL3di5eDysNsab62E812KGsrkbY=</FileDigest>
<FileDigest>1bcXqEVxloLAnoEW6rHcFW/wJE4TVVfrtSLq9TGV4Ho=</FileDigest>
<FileDigestAlgorithm>SHA256</FileDigestAlgorithm>
</EncryptionInfo>
</ApplicationInfo>
Binary file modified AddMSPApp/huntress.intunewin
Binary file not shown.
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
{
"name": "CopilotLimitedMode",
"disabled": true,
"label": "Set Copilot Limited Mode",
"cat": "Copilot (M365) Standards",
"tag": [],
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -111,6 +111,7 @@
},
"SpoofQuarantineTag": {
"type": "select",
"creatable": true,
"multiple": false,
"label": "Spoof quarantine tag",
"required": true,
Expand Down Expand Up @@ -157,6 +158,7 @@
},
"MailboxIntelligenceQuarantineTag": {
"type": "select",
"creatable": true,
"multiple": false,
"label": "Mailbox intelligence quarantine tag",
"required": true,
Expand Down Expand Up @@ -203,6 +205,7 @@
},
"TargetedUserQuarantineTag": {
"type": "select",
"creatable": true,
"multiple": false,
"label": "Targeted user quarantine tag",
"required": true,
Expand Down Expand Up @@ -249,6 +252,7 @@
},
"TargetedDomainQuarantineTag": {
"type": "select",
"creatable": true,
"multiple": false,
"label": "Targeted domain quarantine tag",
"required": true,
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
"impact": "High Impact",
"helpText": "Configures the Microsoft Defender for Endpoint connector with Intune, enabling compliance evaluation for mobile and desktop platforms and controlling partner-data blocking per platform.",
"executiveText": "Establishes the link between Microsoft Defender for Endpoint and Intune so device risk data feeds compliance policies - a foundational Zero Trust control.",
"docsDescription": "Reads the MDE mobile threat defense connector live (one small singleton, no cache) and grades every platform toggle. Two classic rules hold: connecting Windows forces the Windows partner-data block on (Microsoft enforces it), and the MDE attach flag always grades true. Remediation enables the connector first, then writes the FULL settings object.",
"docsDescription": "Reads the MDE mobile threat defense connector live (one small singleton, no cache) and grades every platform toggle. Three rules hold: connecting Windows forces the Windows partner-data block on, connecting macOS forces the macOS partner-data block on (Microsoft enforces both), and the MDE attach flag always grades true. Remediation enables the connector first, then writes the FULL settings object.",
"impactColour": "error",
"addedDate": "2026-08-16",
"powershellEquivalent": "Graph API - deviceManagement/mobileThreatDefenseConnectors",
Expand Down Expand Up @@ -88,13 +88,13 @@
},
"ConnectMac": {
"type": "switch",
"label": "Connect macOS devices to MDE",
"label": "Connect macOS devices to MDE (forces the macOS partner-data block on)",
"omitWhenBlank": true,
"default": false
},
"macDeviceBlockedOnMissingPartnerData": {
"type": "switch",
"label": "Block macOS if partner data unavailable",
"label": "Block macOS if partner data unavailable (Microsoft forces this on when Connect macOS is on)",
"omitWhenBlank": true,
"default": false
},
Expand All @@ -112,7 +112,7 @@
},
"windowsDeviceBlockedOnMissingPartnerData": {
"type": "switch",
"label": "Block Windows if partner data unavailable",
"label": "Block Windows if partner data unavailable (Microsoft forces this on when Connect Windows is on)",
"omitWhenBlank": true,
"default": false
},
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -56,6 +56,7 @@
},
"QuarantineTag": {
"type": "select",
"creatable": true,
"multiple": false,
"label": "Quarantine Tag",
"required": true,
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,13 @@
"type": "textField",
"label": "E-mail to receive the alert",
"helperText": "Ignored when the alert state is Removed.",
"required": true
"required": true,
"validators": {
"pattern": {
"value": "^[^\\s@]+@[^\\s@]+\\.[^\\s@]+$",
"message": "Must be a valid e-mail address"
}
}
},
"AllowExtraAddresses": {
"type": "switch",
Expand Down
25 changes: 25 additions & 0 deletions Config/BaselineStandards/Defender Standards/SpamFilterPolicy.json
Original file line number Diff line number Diff line change
Expand Up @@ -82,6 +82,7 @@
},
"SpamQuarantineTag": {
"type": "select",
"creatable": true,
"multiple": false,
"label": "Spam quarantine tag",
"required": true,
Expand Down Expand Up @@ -140,6 +141,7 @@
},
"HighConfidenceSpamQuarantineTag": {
"type": "select",
"creatable": true,
"multiple": false,
"label": "High confidence spam quarantine tag",
"required": true,
Expand Down Expand Up @@ -198,6 +200,7 @@
},
"BulkQuarantineTag": {
"type": "select",
"creatable": true,
"multiple": false,
"label": "Bulk quarantine tag",
"required": true,
Expand Down Expand Up @@ -256,6 +259,7 @@
},
"PhishQuarantineTag": {
"type": "select",
"creatable": true,
"multiple": false,
"label": "Phish quarantine tag",
"required": true,
Expand All @@ -277,6 +281,7 @@
},
"HighConfidencePhishQuarantineTag": {
"type": "select",
"creatable": true,
"multiple": false,
"label": "High confidence phish quarantine tag",
"required": true,
Expand All @@ -302,6 +307,26 @@
"required": true,
"default": 7
},
"BulkMovesEnabled": {
"type": "select",
"multiple": false,
"label": "Bulk moves enabled (deliver bulk mail below the threshold to the Promotions folder - Preview)",
"options": [
{
"label": "Do not configure",
"value": ""
},
{
"label": "On",
"value": "On"
},
{
"label": "Off",
"value": "Off"
}
],
"default": ""
},
"IncreaseScoreWithImageLinks": {
"type": "switch",
"label": "Increase score with image links",
Expand Down
4 changes: 4 additions & 0 deletions Config/BaselineStandards/Entra (AAD) Standards/AdminSSPR.json
Original file line number Diff line number Diff line change
Expand Up @@ -36,6 +36,10 @@
"read": {
"cacheType": "AuthorizationPolicy"
},
"writeTarget": "authorizationPolicy",
"writeTargetProperties": {
"allowedToUseSSPR": "%allowSSPR%"
},
"remediate": {
"executor": "GraphRequest",
"requests": [
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,8 @@
"url": "/api/ListAppApprovalTemplates",
"labelField": "TemplateName",
"valueField": "TemplateId",
"queryKey": "StdAppApprovalTemplateList"
"queryKey": "StdAppApprovalTemplateList",
"templateView": { "title": "App Approval Template" }
}
},
"appids": {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,10 @@
"read": {
"cacheType": "AuthenticationMethodsPolicy"
},
"writeTarget": "authenticationMethodsPolicy",
"writeTargetProperties": {
"policyMigrationState": "%migrationState%"
},
"remediate": {
"executor": "GraphRequest",
"requests": [
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -81,6 +81,11 @@
"read": {
"cacheType": "AuthenticationMethodsPolicy"
},
"writeTarget": "authenticationMethodsPolicy",
"writeTargetProperties": {
"reportSuspiciousActivitySettings.state": "%reportSuspiciousActivity%",
"systemCredentialPreferences.state": "%systemCredential%"
},
"remediate": {
"executor": "GraphRequest",
"requests": [
Expand Down
Loading