Product
high
threat
Malicious Use of Microsoft Intune Device Management Configuration Policies
2 rules 3 TTPsAttackers can abuse Microsoft Intune device management configuration policies, typically used for legitimate remote device management, to disable defenses and evade detection on managed devices.
exploited
Intune
azure
device_management
policy
defense_evasion
2r
3t
critical
advisory
Microsoft Intune Bulk Device Wipe Detection
2 rules 1 TTPA high volume of 'wipe ManagedDevice' events from the Intune admin portal within a short period (5+ per hour) indicates a potential large-scale data wiping attack against managed endpoints.
Intune
cloud
microsoft-intune
data-wipe
impact
2r
1t