Intune: Windows Firewall Public - Log Successful Connections
π 2025-10-30
β’
β±οΈ 2 minuten lezen
β’
π’ Should-Have
πΌ Management Samenvatting
Log successful Public firewall connections - audit trail of allowed traffic on public WiFi (forensics: 'what did laptop access on hotel WiFi?').
Aanbeveling
CONDITIONAL (if compliance requires)
Risico zonder
Low
Risk Score
3/10
Implementatie
5u (tech: 2u)
Van toepassing op:
β Windows 10 β Windows 11
Public WiFi successful logging = forensics: Use case: Incident investigation: 'Did compromised laptop exfiltrate data on airport WiFi?' β check successful connections β large transfer to unknown IP = YES, Compliance: Network access audit (PCI-DSS requires network logs), Data exfiltration detection: Successful connections to external IPs (SIEM alert on anomalies). Trade-off: HIGH log volume (every HTTPS, VPN, email connection logged) β requires large log size (32MB+) + SIEM forwarding.
PowerShell Modules Vereist
Primary API: Microsoft Graph API Connection:Connect-MgGraph Required Modules: Microsoft.Graph.DeviceManagement
Implementatie
Log public successful: Policy: Log successful connections: Yes, Log volume: HIGH (all allowed traffic on public WiFi), Use case: Forensics, compliance, data exfiltration detection, SIEM: Forward to Log Analytics (filter anomalies - large transfers, unusual destinations).
Gebruik PowerShell-script enable-public-network-firewall-enable-log-success-connections-is-set-to-enable-logging-of-successful-connections.ps1 (functie Invoke-Monitoring) β Controleren.
Remediatie
Gebruik PowerShell-script enable-public-network-firewall-enable-log-success-connections-is-set-to-enable-logging-of-successful-connections.ps1 (functie Invoke-Remediation) β Herstellen.
Compliance & Frameworks
BIO: 12.04.01 -
ISO 27001:2022: A.12.4.1 -
Automation
Gebruik het onderstaande PowerShell script om deze security control te monitoren en te implementeren. Het script bevat functies voor zowel monitoring (-Monitoring) als remediation (-Remediation).