#defending-azure-path

1 messages Β· Page 1 of 1 (latest)

shrewd dagger
#

πŸ₯³

upper cedar
#

πŸ₯³

inland parcel
#

let's go πŸ›« πŸ™‚

deep karma
#

Aight let's give this a whirl.

rocky orbit
#

πŸŽ‰

subtle pecan
#

the discount code, is it only going to be active till 18th this week?

cinder skiff
#

Why it's not possible to pay in USD not GBP 😦

wide dome
#

MS Sentinel: Just Looking labs are good, was my first time testing Sentinel. thm thanks

subtle pecan
#

Sentinel is the best siem and the easiest one to use imo, once you get into grips with it. I use it every day for work.

glad grail
#

It's part of THM premium, right?

narrow monolith
#

πŸ₯³

subtle pecan
#

2 rooms are free rest is business

#

Although I am planning to use the discount to claim both the aws and azure path.

dim hedge
#

I'm getting confuse with promo 50%, which subscription or package that need to choose for that?

glad grail
subtle pecan
#

XDR: Introduction I think there are some permissions that are lacking for the labs

#

not sure why stuff is greyed out for me.

proud patrol
#

I am bit confused with this 50% discounted code. I can't find it. I am premium as well.

lusty smelt
#

Yeah I'd love to see a link to that discount. I'm fine with paying the three month business/cloud plan if I could see what this discount entails.

subtle pecan
#

review so far: Introduction to Sentinel βœ… XDR: Introduction❌

dim hedge
#

Who we can contact for that promo clarification?

lusty smelt
#

Facepalm, we're all overlooking that the promo is in the images for the announcement

dim hedge
#

Can we pay now and start the lab later?

lusty smelt
#

For individuals it's three months of access

#

Comes out to $187.50 USD with the promo for anyone curious

subtle pecan
#

are the creators of these azure rooms even in discord. Its a joke that the labs are not even working and stuff is greyed out.

fervent current
#

$62.50/month with the discount. I understand the cost is to cover Microsoft licensing and Azure storage. If I'm already paying an annual subscription for THM, wouldn't it be cheaper to buy the Microsoft licensing myself?

west field
#

If I get certfication I will take job?

deep karma
fervent current
shrewd dagger
dim hedge
#

I'm not clear here, if we have monthly subscription - paid,do we still need to pay for this learning path?

#

It mentioned in the monthly payment all learning path

trail pagoda
wide dome
#

on XDR: Introduction task 8 , in the lab we do not have permission to create custom role, are we just suppose to follow the screenshots?

rancid garden
#

can anyone tell me where to find Workflow Id for an incident in sentinel?

wide dome
fair wave
#

What's the usual waiting period for write-ups? πŸ˜Άβ€πŸŒ«οΈ

trail pagoda
subtle pecan
#

when u follow the labs u cannot click anything because its greyed out

#

I am a bit worried now whether the labs u pay for are like this. The annoying thing about THM is that I think they have a no -refund policy

#

which is a bit stupid if the labs u are paying them for are not working.

wide dome
# subtle pecan Yeah this is what annoyed me

I am also want to know the level of the labs, if they just basic / easy level before making any decision to purchase, and there is no info regarding the other rooms, as you need to pay first to see them

rocky bay
#

having problem with MS Sentinel: Just Looking room. It's been almost 50 minutes and still can't get any incidents

subtle pecan
# wide dome I am also want to know the level of the labs, if they just basic / easy level be...

well I am not really bothered whether its good or bad really because my work will pay for it. Planning to buy tomorrow, before discount ends. But I can understand if u are paying out of your own pocket it can be a gamble in case it turns out to be bad. If my work did not pay for it then I probably might leave it out most likely. If you want to learn about Azure security that is for free then u can get 90 day free sentinel access and the SC-200 course for free by Microsoft.

rocky bay
#

having problem with MS Sentinel: Just Looking room. It's been almost 50 minutes and still can't get any incidents

wide dome
rocky bay
#

ok

radiant kiln
wide dome
radiant kiln
umbral iceBOT
#

Gave +1 Rep to @radiant kiln (current: #5 - 1856)

quiet tiger
#

in room MS Sentinel: Just Looking after ingesting log i geting permission error saying don't have permission as per subcription etc any idea why or it's just a bug

wide dome
quiet tiger
umbral iceBOT
#

Gave +1 Rep to @wide dome (current: #154 - 53)

lilac ridge
#

Heya, anyone got past XDR: Defense Evasion Task 5?
I'm stuck on the SHA1 hash...I have 2 different hashes in the demo environment, but none is working.
Just wanted to nake sure that I am just picking the wrong hashes and the task is working.

lilac ridge
#

Forget what I've said. I am just incompetent :)

warped patio
#

Is there a coupon available

#

for this

#

400 dollar is a bit expensive

#

do u get access to an entire tenant ?

#

NVM FOUND THE CODE BY SCROLLING UP LOL

#

it expires tomorrow lucky me

subtle pecan
#

I feel bad for the guys who bought aws path way back for the amount they charged back then. Now they are giving both paths for just half price kekw

oblique sedge
#

nice room πŸ™‚

torpid wadi
#

Can anyone please share the recording of today's webinar about defending Azure?

rocky bay
#

What is EDR visibility limited to?

safe sandal
torpid wadi
neat fox
#

It's most likely been recorded

lone cliff
#

how long this path will be free?

torpid wadi
torpid wadi
neat fox
#

It will probably be on yt

trail pagoda
wide dome
weak bane
#

I am a beginner in the cloud. Is it worth it to buy 3 month access with a discount? I plan to write SC 900 next month.

#

Could anyone give advice please? πŸ₯Ί

inland parcel
quiet niche
#

am i missing something...i have ingested the logs but when i go into the log part the queries is blank?

fair wave
#

You haven't written a query yet, are you trying to query any of the tables?

quiet niche
#

no just setting up first

tame otter
umbral iceBOT
#

Gave +1 Rep to @wide dome (current: #147 - 57)

quiet niche
#

i reloaded the room but now i have a permission restriction in logs, do i need to now subscribe?

wide dome
quiet niche
umbral iceBOT
#

Gave +1 Rep to @wide dome (current: #145 - 58)

stray mulch
#

In MS Sentinel: Investigate module, is anyone getting the issue where the alertRules and deploy-workspace deployments are failing? alertRules is saying "Maximum rules count per tenant exceeds the allowed limit 10000. please contact support if this an intentional action." Any advice?

quiet niche
radiant kiln
quiet niche
#

figured out what i was doing wrong i wasnt inside the eastus-sentinel space for logs πŸ€¦β€β™‚οΈ

subtle pecan
#

hang on, must one have completed the starting labs to continue the labs in the next exercise?

#

I thought each cloud instance is for its own lab

#

MS Sentinel: Ingest Data ---> I thought this was its own lab but seeing I created sentinel in the previous lab, I thought it would be there in the next cloud instance its not there. So I need to go back and create the sentinel workspace all over again to do this lab?

subtle pecan
umbral iceBOT
#

Gave +1 Rep to @radiant kiln (current: #5 - 1857)

quiet niche
#

do you need to subscribe when your limit exceeds 10k?

radiant kiln
#

The issue you are facing is most likely because you haven't waited for the workspace and event ingestion deployment to be finished before deploying the rules

stray mulch
radiant kiln
quiet niche
# radiant kiln

i get this error: Maximum rules count per tenant exceeds the allowed limit 10000. please contact support if this an intentional action.

(Code: BadRequest)

#

my deploy has the error at the top, the logs were successful all under the error notification

radiant kiln
quiet niche
#

MS Sentinel: Just Looking

radiant kiln
# quiet niche MS Sentinel: Just Looking

Okay that was my assumption, that's why me previous message regarding making sure to have the ingest events and deploy workspace action being finalized first.
In task 2 it's descripted to press the Ingest Logs action first, and to not press the Deploy rules button yet

#

So having pressed only the Ingest Logs action. Go to your deployments tab and wait until the ingestEvents and deploy-workstation actions have been completed

#

In the image I shared above, you see that these actions are still in the deploying state

#

You have to wait until these have finished. Then move on to task 3 and follow along with the Ingest Logs action

quiet niche
radiant kiln
rose sequoiaBOT
radiant kiln
# quiet niche

Okay I see now what you mean. Let me try myself real quick

#

Okay something is wrong here. I need to forward this to get looked into. Thx for bringing it up @quiet niche πŸ‘

umbral iceBOT
#

Gave +1 Rep to @quiet niche (current: #1847 - 2)

quiet niche
umbral iceBOT
#

Gave +1 Rep to @radiant kiln (current: #5 - 1858)

stray mulch
#

MS sentinel: investigating

radiant kiln
stray mulch
#

Yeah but let me do it one more time and make sure it’s not me doing something wrong

#

Yeah still getting that error

steady sinew
#

In the "MS Sentinel: Just Looking", Azure is not deploying the rules due to maximum rules count per tenant reached. "Maximum rules count per tenant exceeds the allowed limit 10000"

ripe vault
#

can someone help

#

plz

pulsar portal
#

Still getting the error, is there a fix yet?

radiant kiln
turbid sky
mighty dock
# radiant kiln You get that same issue there too? Let me check

I am also seeing an error after ~20 mins in room Sentinel: Investigating. Same screenshot as @quiet niche from yesterday. I tried with about 4 different lab joins and got the same error each time about maximum rules count per tenant over 10k.

I will move on and come back to this one, thanks Fontaene

umbral iceBOT
#

Gave +1 Rep to @radiant kiln (current: #5 - 1860)

remote lotus
#

KQL advanced queries (task 3). The cloud instance reads like the logs are dynamic, but the query required to answer the question expects specific results. The cloud details pop out doesn't have any associated actions/deployments. When checking the resource groups I'm welcomed with a permissions error.

remote lotus
#

KQL advanced queries task 8 has the same issue. There is no deploy lab option, even though task 7 states there will be.

radiant kiln
radiant kiln
subtle pecan
#

looks like I am going to have to switch to the aws learning path now for the time being till the issue is fixed varg

#

when can we expect a fix? days? weeks?

subtle pecan
#

I thought maybe the KQL labs might be doable at least while the other issues persist but looks like its not

#

I think we all deserve an extension of the 3 months for issues with any labs, based on how long it takes to fix it.

radiant kiln
subtle pecan
radiant kiln
main flare
#

Hi team, is it possible to get a 50% discount voucher in the next 24 hours? I would get it for myself, I am already an annual subscriber. I thought the discount was valid until the end of the month, but now I see the official promo ended on Friday 😣

subtle pecan
#

also it does not really mean anything if u are an annual subscriber, I doubt THM would give u any special treatment considering some of us in here have only got 3 months of this content and stuff is not working already and they are not giving us any compensation such as extra days. If their environments die tomorrow we wont get a refund at all. So I would not be too worried on missing out.

radiant kiln
subtle pecan
#

Monthly Membership Subscriptions: Monthly subscriptions to TryHackMe are billed in advance and are non-refundable for the subscription period they are purchased for. The subscription renews automatically at the end of the term if not cancelled before the renewal. When you purchase a subscription, you agree to a renewal charge for the service, whether it is monthly or annually. This is explained on the Why Subscribe page where you select your plan. If you choose to cancel your subscription, you will still have access to the service for the remainder of your billing cycle, but you will not receive a refund.

#

Annual Membership Subscriptions: Annual subscriptions have a 7-day cooling-off period, during which you may request a full refund, provided you have not accessed or downloaded any course materials. To be eligible for a refund, the request must be made no later than 7 days after the purchase date. After this period, or if course materials have been accessed or downloaded within the initial 7 days, refunds will not be granted.

radiant kiln
# subtle pecan Monthly Membership Subscriptions: Monthly subscriptions to TryHackMe are billed ...

These 2 policies seem to apply to the regular subscriptions, not to like the cloud packages. But either way. Stating "stuff is not working already and they are not giving us any compensation such as extra days. If their environments die tomorrow we wont get a refund at all." indicating THM would not care and thus neither would compensate or extent the packages is just outright an assumption of you.

subtle pecan
#

If stuff is not working for all users are we entitled to a refund or extra days or is my assumption wrong?

radiant kiln
#

You can be assured we are trying our best to keep everything working and are trying to solve issues as fast as possible.

main flare
#

Thanks @subtle pecan and @radiant kiln for the follow up 😣🀞🏻

umbral iceBOT
#

Gave +1 Rep to @subtle pecan (current: #695 - 8)

subtle pecan
#

If the info is not in the article my assumption is its not the case, that is where I am coming from.

radiant kiln
umbral iceBOT
#

Gave +1 Rep to @radiant kiln (current: #5 - 1861)

flat sandal
# stray mulch In MS Sentinel: Investigate module, is anyone getting the issue where the alertR...

You can analyse raw logs. Link to the ps1 script You can find inside Azure lab, don't know if it's alowed to post it here. Inside this ps1 script there link to raw logs, lor example disable_accounts.csv. Inside it You can find answers for Q2, Q4 and Q5. Unfortunatelly Q3 "Check out this IP's geolocation. What is the city?" doesn't match with the answer, but this is the only left unaswered for me atm. Hope it helps.

#

And clearly this question is messed-up. EDIT: It's all ok now πŸ™‚

#

Question 2 is working correctly.

radiant kiln
shrewd dagger
#

Hello everyone, the following three rooms have been made private for maintenance:

MS Sentinel: Just Looking
MS Sentinel: Investigate
MS Sentinel: Detect

We'll post an update once they become available again. πŸ™

viscid sparrow
#

KQL Basic Queries lab, I am trying to do Task 9, It does not tell me which custom date to use to query the logs... Like Task 3 did, I tried to use the dates shown in the little animated images but had no luck with those times... Help?

flat sandal
flat sandal
flat sandal
#

Just click on "Run" button besides SecurityEvents_CL and You should see the logs.

viscid sparrow
#

I tend to run in to this a lot too, I have been running the lab for about 10 minutes so far and the logs have all been ingested/deployed based on the deployment screen in the resource group...

viscid sparrow
#

Now it's showing up... No clue, this stuff is buggy from what I can see, and having to pay for it...

flat sandal
#

You can also check here, as mentioned in the Task 9: Lab deployment may take about 4 minutes. You can check the deployment status via Resource groups -> Select the available resource group -> Settings -> Deployments.

#

sometimes indeeed You hace to wait more time, but it's a place where You can check if everything is up and ready

flat sandal
viscid sparrow
#

That's moot, I am doing all the rooms and they all have the same issues, and they're not all free.

flat sandal
viscid sparrow
#

Again, moot.

radiant kiln
#

And if so, you said it happens in all rooms, by that you mean all KQL rooms, or also like all Sentinel rooms?

viscid sparrow
# radiant kiln And if so, you said it happens in all rooms, by that you mean all KQL rooms, or ...

My main issue was no matter what custom date I set it to it was saying there were no logs, I refreshed several times and after about 20 minutes of messing around the logs finally showed up.

As for the permissions errors those happen as well… It’s happened to me in the Sentinel room, KQL room and the first Challenge. I even went to check and make sure my permissions were showing in Azure.

radiant kiln
viscid sparrow
#

Yes, I waited for that, took about 5 minutes.

#

But it was about 15 minutes after that.

#

They all showed the green "deployed" icon in the Deployment Tab

radiant kiln
viscid sparrow
#

Yeah no clue, I tried the lab twice, the second time I was messing with it the way the other user suggested, but clicking on the SecurityEvents_CL and clicking "run"

radiant kiln
#

For the other issue regarding the permissions error. Did you make sure to log out of the previous lab account first?

viscid sparrow
#

But I messed with the custom date a bunch and no dice, then suddenly it showed up in the "3 days" time set up.

radiant kiln
#

Ye maybe if you can try again, and let me know in case it still happens, that might be easier to troubleshoot

viscid sparrow
#

Yeah, it happened both after I logged out of the task3 lab, I logged into the task 9 after, and the permissions were wonky, then I tried again after an hour (and that other user suggested a workaround) and both labs had been exited for quite a while.

#

I was able to finish the lab the second go around, just took a bit.

#

like I said eventually (like 20 minutes later) it populated some logs.

radiant kiln
viscid sparrow
#

Alright, appreciate it.

subtle pecan
umbral iceBOT
#

Gave +1 Rep to @viscid sparrow (current: #1848 - 2)

umbral iceBOT
#

Gave +1 Rep to @shrewd dagger (current: #17 - 541)

quiet niche
#

cant wait to finish the Sentinel room, first insight to this SIEM

subtle pecan
#

KQL (Kusto): Advanced Queries - Excellent room, as a person who uses Sentinel every day, a lot of the stuff is already familiar to me, However I found functions very interesting.

#

Lab was very good as well upvote

subtle pecan
#

XDR: Prevent, Detect, and Mitigate Defense Evasion Attacks- I am unable to follow along with task 6 lab due to insufficient permissions

severe widget
main flare
mighty dock
#

What is the "Request tenant environment" button at the top of some of the rooms (like XDR: Defense Evasion) supposed to do? Nothing seems to happen if I click it.

viscid sparrow
#

@radiant kiln This is the Advanced KQL lab. As you can see I am getting no results, I even went as far back as June 2024 (the images show July 2024) and still getting no events.

#

Working now... but I had to wait well after the logs finished deploying.

errant perch
radiant kiln
subtle pecan
#

I am gutted that the challenge room is privated as its something I wanted to do, hoping it gets fixed soon and put back

mighty dock
#

I was disappointed that you can just click Complete in the final room instead of having to prove any type of skill

#

Half the questions in the "labs" were ridiculously easy yay or nea questions, cmon guys.

fathom maple
#

Hi, I am trying to finish the Defending Azure learning path, but I am constantly getting zero logs to review -- even when I adjust the time frame.

#

Can anyone assist me?

#

I verified four times that I used the provided credentials.

radiant kiln
fathom maple
#

Azure: Can you GA

#

I have completed all of the challenges

radiant kiln
fathom maple
#

Maybe I uploaded the wrong screenshot

#

Gimme a sec

#

There isn't an active log analytics workspace

radiant kiln
fathom maple
#

I see, thanks

#

I will try tomorrow

#

If the challenge is to take over Azure to become the Global Admin, why is the learning path called Defending Azure?

viscid sparrow
subtle pecan
#

and I am curious to see THM response to that

wheat pecan
#

Hi there, did anyone attend the bootcamp yesterday? Do they post the recording of the session anywhere? Unfortunately I thought it was today at 4pm so I missed it entirely.

subtle pecan
neat fox
umbral iceBOT
#

Gave +1 Rep to @neat fox (current: #55 - 168)

sharp oracle
#

Will this path help prepare you for the SC-200 since that focusses heavily on sentinel etc

subtle pecan
#

the SC-200 exam is more of a where is this in Sentinel where is that in defender

#

rather than scenario sort of based questions of incidents.

#

@neat fox the sentinel challenge room is now public and the other 2 rooms are still privated. But it still has" We are currently investigating an issue with the Analytics rules and therefore the room will not work as expected" banner on the room. Is it fixed now or still getting fixed?

neat fox
#

Not too sure about this. @shrewd dagger Do you know?

sharp oracle
umbral iceBOT
#

Gave +1 Rep to @subtle pecan (current: #597 - 10)

sharp oracle
#

I think it will at least create the base

radiant kiln
subtle pecan
hasty locust
#

it says failed to load.

subtle pecan
#

MS Sentinel: Just Looking - Completed. Relatively easy, I would like to see a harder challenge with a full blown investgation that requires us to use kql queries to investigate and not just rely on analytic rules

mental citrus
#

Is there any kind of a video tutorial for setting up in the defending azure labs? I was finally able to launch the labs properly for Defending Azure, but now moving into KQL I'm at a standstill. I try selecting "Microsoft Sentinel" but it keeps rolling back to "Welcome to Azure!". I've closed and signed out of the labs and relaunched several times but since there are no tutorials covering the initial steps I can't tell if I'm just missing something

radiant kiln
# hasty locust

Yes, you are not supposed to connect that data connector (the Entra ID one), it's just to walk you through. In task 7 you'll be asked to connect a data connector on your own, which will have all prerequisites satisfied πŸ™Œ

subtle pecan
#

"can you GA" I have found the user flag, why is it not working!!

#

@neat fox

#

take THM users money and break the rooms thanks

#

@inland parcel can I dm you the user flag cause I think u have completed the room looking at the scoreboard, so you can check whether the user flag I have is the correct one

subtle pecan
umbral iceBOT
#

Gave +1 Rep to @inland parcel (current: #1 - 4772)

neat fox
radiant kiln
subtle pecan
#

It seems there is another flag that was placed in that room, please can we stop adding unnecessary rabbit holes.

radiant kiln
subtle pecan
radiant kiln
mental citrus
radiant kiln
mental citrus
subtle pecan
#

can you GA, would be useful to have commands provided with task 6 -9. Asking users to do it themselves when the path is about defending is not good

radiant kiln
# mental citrus

Hey there! Sorry for the delay. Is this the Demo Log Analytics URL you try to open where you get that error?

#

If so, it opens just fine for me.
If you tried to open some other page like Sentinel, that's not where you supposed to go to. But instead just navigate to the provided URL

mental citrus
#

I'm launching the lab from the link within the module

#

And Then the lab takes me here:

#

So im unclear on where I should be finding the logs shown in the screenshots in the instructions if I'm not supposed to go into sentinel

viscid sparrow
#

missing_space

mental citrus
#

That's the info as of this evening, although it was a diff lab ID yesterday

#

This was it last night

subtle pecan
#

Just to let u guys know its better to use cloud shell or your own VM for the tasks, the attackbox discconects mid-way for no apparent reason and then u have to start all over

left flower
#

Hi all,
any hints for this challenge in room Azure: Can you GA?
What is the user flag?

inland parcel
umbral iceBOT
#

Gave +1 Rep to @inland parcel (current: #1 - 4790)

willow epoch
turbid sky
indigo arch
radiant kiln
mental citrus
hasty locust
#

bruh icant acces the cloud

#

like dude what is this

stray mulch
#

same issue here bodi

#

been like that for about a week or so

hasty locust
#

when is it going to be fixed

stray mulch
#

wish i could tell u, send an email to their support email maybe the more ppl that do that the faster they will fix it

hasty locust
#

i dont get it

#

why are there no resuslts found

left flower
umbral iceBOT
#

Gave +1 Rep to @willow epoch (current: #2857 - 1)

willow epoch
radiant basin
# hasty locust

a lot of the tables are empty so you cant get any results, which is making the practical aspects pointless as you cant experiment the KQL. Up until now I've been able to guess the answers either through looking at the screenshots or google but my current question needs the ProtectionStatus table which is empty as google and chatgpt have nothing. So i cant go any further. I also can no longer access AWS after less than a week of my 3 month subscription. So I dont get it either

subtle pecan
#

any update on the other 2 private rooms? when can we expect a fix?

radiant kiln
radiant kiln
charred hearth
#

Having a lot of issues with the Defending Azure path. I am never able to return to my original subscription:

charred hearth
#

How is this supposed to work? If I completed the Sentinel room days ago shouldn't the lab open up my pre-existing instance and not a brand new one?

hasty locust
#

same gang

radiant kiln
leaden jolt
#

Hello, I have an Azure penetration test scheduled for next month.
I wanted to ask if the Azure learning path on TryHackMe is considered effective preparation for real-world Azure pentesting, or should I complement it with other resources?

inland parcel
leaden jolt
# inland parcel I always prefer to combine multiple resources , THM's Azure path is really good ...

I'm preparing for an Azure penetration test, and I noticed that the TryHackMe Azure path seems to be more blue-team focused.
I’ve completed PWN labs and other CTF-style content, but I’m looking for stronger, hands-on resources tailored specifically for Azure offensive security.
Do you have any recommendations similar to THM but more focused on red teaming or real-world Azure attack scenarios?

inland parcel
umbral iceBOT
#

Gave +1 Rep to @inland parcel (current: #1 - 4841)

subtle pecan
#

try pwnedlabs they have good stuff from what I have been hearing.

leaden jolt
subtle pecan
leaden jolt
#

Thanks bro ❀️

charred hearth
radiant kiln
# charred hearth So just to confirm, in order to avoid re-doing tasks (re-deploying Sentinel) you...

No you don't have to complete one or more rooms in a single session. All you pretty much have to do is log in with a new account each time you are asked to deploy a new lab. E.g. one room/lab might has no workspace whatsoever because you are supposed to create it on your own, while the next room/lab/task might already has the workspace created and ingests logs that you need. That's why you need different accounts because of different environments/permission that are needed throughout the different labs

proud olive
exotic finch
# radiant basin a lot of the tables are empty so you cant get any results, which is making the p...

Seconding this, in the same situation where no data populates on the VMComputer table. Can change the date back years and nothing populates. All the other questions have either a screenshot for the demo Microsoft table just incase something goes wrong. Not sure why they didn't set up their own data to use for these examples, the rest of the room has them.
This question actually needs the data populate it seems, so I'm waiting for a resolution on this as well. Specifically, Task 3 of KQL: Advanced Queries room.

radiant kiln
proud olive
#

In the kql advanced queries, specifically, for the question 2 in the task 3. No results in the table protectionstatus and vmcomputer

exotic finch
radiant kiln
exotic finch
#

Thanks for the update and resolution Fontaene.

umbral iceBOT
#

Gave +1 Rep to @radiant kiln (current: #5 - 1863)

timber cape
#

Are these 3 modules gone or will be back?

radiant kiln
timber cape
#

MS Sentinel: Just Looking
MS Sentinel: Investigate
MS Sentinel: Detect

radiant kiln
kind dew
#

2 KQL rooms I completed 100% show 85%. I reset both, did it all over again and it still generate the completion screen, the header shows 100%, but when exiting keep 85%.

I wish I hadn’t invested in this learning path. Do not recommend.

There is also the issue related to 2 MS Sentinel rooms that simply disappeared.

fossil mortar
#

I have the same issue with the KQL intro and KQL Basic rooms. Says 87% and 85% completed, but all tasks are done in both rooms.

inland parcel
#

@kind dew @fossil mortar I've forwarded mesaage to staff , they will reach out to you asap πŸ™‚

radiant kiln
kind dew
umbral iceBOT
#

Gave +1 Rep to @inland parcel (current: #1 - 4899)

hasty locust
#

how am i supposed to complete kql advanced room when the database is messed up

radiant kiln
hasty locust
#

On the "Combining Multiple Columns From Different Tables" query, what row is excluded from the ProtectionStatus table?

#

i tried everything cant find the answer

hasty locust
#

oh and what is this

#

when i clikc on logs this pops up

radiant kiln
radiant kiln
hasty locust
#

Lab-02: Discover

subtle pecan
umbral iceBOT
#

Gave +1 Rep to @kind dew (current: #2875 - 1)

subtle pecan
#

I am getting my license expensed back from work at least this month. Feel sorry for the people who paid out of pocket and did not get what they expected.

radiant kiln
#

And then also logged in with the new creds from task 8?

radiant kiln
hasty locust
#

yo anyone here done the azure ga romm?

hasty locust
#

on the ms sentinel just looking room. the incidents are not loading and they are not here

#

is it common

foggy fox
radiant kiln
charred hearth
#

I'm confused about the "Defending Azure" learning path. All of the rooms I've completed are "Free". What exactly did I pay for?

inland parcel
charred hearth
umbral iceBOT
#

Gave +1 Rep to @inland parcel (current: #1 - 4952)

jade pumice
#

Hey guys can someone give me a hint how to connect as the target app to the azure tenant in the room "can you ga?" on defending azure?

whole cape
#

Hi guys, just trying to log into the Lab of β€žAzure: Can you GA?β€œ but always get the error β€žuser might not have enough permissionβ€œ
Is there anything I can do or try?

elfin hamlet
#

Hi Everyone, I am stuck at XDR: Defense Evasion task 5 where it refers to incident: Attempt to turn off microsoft defender Antivirus protection but when I login with the provided credentials there is no incident like that. Is it a known bug?

swift frigate
radiant basin
elfin hamlet
#

I solved it yesterday finally but with an alert different from what is mentioned in task.. There is a malware alert which can help for this question. Give it a try. πŸ™‚

radiant kiln
radiant kiln
median swallow
#

Hey everyone, is it just me or are there no logs showing up when I connect to the environment in KQL (Kusto): Basic Queries or KQL (Kusto): Introduction? Just want to make sure I'm not missing anything.

maiden beacon
#

In "Can you GA?", if Azurehound is needed/recommended, would it make sense to include it into the AttackBox tools?

radiant basin
#

They have updated one of the questions in the XDR: Defense Evasion Lab. the new question is "What is the value for Malware detected?", the answer is 4 characters long. I have no idea what value it is looking for, initially I thought it was the risk level which is High but that is not correct, than I thought it might be a processID but none of the ones I have tried have worked. The only mention of value on the whole page is in reference to registry values, which doesn't match 4 character limit. Any ideas as to what value I am looking for?

radiant kiln
fast sorrel
#

XDR: Defense Evasion
Room 5
Question
What is the value for Malware detected?

Anybody know how to find this answer? been stuck for a good 20 minutes

This question makes zero sense for me ... @radiant kiln

radiant kiln
fast sorrel
#

thank you, passed the answer you changed πŸ™‚

elfin hamlet
#

Is deploy rules bug fixed for MS Sentinel: Just looking room? I am still facing the error after deploying rules in that room

elfin hamlet
#

Resolved- I had to leave lab. Ingest logs and wait to deploy rules.

white prairie
white prairie
radiant kiln
proud olive
#

Hi, anyone in Azure Challenge (Can you GA?)? IΒ΄m getting an error when I try to log in with the user

charred laurel
odd dome
#

I do get same error as you are describing when trying to log in with cloud credentials in "Azure: Can you GA?"

charred laurel
#

@radiant kiln What's up

radiant kiln
#

cc @charred laurel

elfin hamlet
#

I am facing the same issue with Can you GA room. I was able to login last night but it is not working now.

charred laurel
warped steppe
#

is defending azure paid even if we have premium? Same for the AWS one?

warped steppe
celest shoal
#

Hello, how do I get telemetry into the tenant in the "KQL (Kusto): Advanced Queries" in "Defending Azure/KQL lab? I went to "Demo Log Analytics," but I'm not getting any data in the query. I couldn't find a "Start" button like in previous labs.

proud olive
#

Hi, any hint for the task 7 to generate a new client secret in the room: Azure: Can you GA?

white prairie
#

Hey folks! I've completed 4 sections of the course and received a certificate stating that I've completed 5 (!) sections, including Microsoft Entra ID, which is not available for me.

Do others experience the same issue with Section 5, or is it working fine for everyone?

I submitted a ticket to the support 2 days ago, but haven't heard back yet.

untold socket
#

Hello I am at the Azure XDR Evasion Room and Stuck on Task 5: What is the value in the Malware detected field? --> I tried all 4 log numbers out or do I missunderstood something?

celest shoal
#

Hello, how do I get telemetry into the tenant in the "KQL (Kusto): Advanced Queries" in "Defending Azure/KQL lab? I went to "Demo Log Analytics," but I'm not getting any data in the query. I couldn't find a "Start" button like in previous labs.

elfin hamlet
#

Hi, I saw there were few modules which were added related to Entra in Defending Azure path but it is not visible anymore. Is it temporarily hidden?

hasty locust
#

guys what happened to the entra id module

#

why did it disappear

daring sinew
hasty locust
#

this is what i see

#

@daring sinew

radiant basin
# hasty locust <@958383130102870026>

they have disappeared for me too.
when the rooms were up, they were just blank templates with an inactive Join button
maybe they will return with content but I didn't need to do them to get the certificate when they were there

inland parcel
#

@hasty locust @radiant basin I think they're only available for business users now

lilac jackal
#

hi guys im new here i need hackers and spammer friends

proud olive
#

Hi, any hint for the task 7 to generate a new client secret in the room: Azure: Can you GA? I run the commands but I don't have the privileges to do it

deep karma
#

Hey all, can I please get a nudge regarding Task 5 of XDR: Defense Evasion as I am stuck on the third question, it's not clear what they're asking.

deep karma
# inland parcel wdym ?

What I mean is that I am kid of tearing my hair out regarding what we're meant to be looking for here. I have been looking through the logs in the Security portal and nothing sticks out to me here.

inland parcel
deep karma
#

Sure give me a moment please.

#

It's just this question. I seem to find a response that meets that style

#

I have been following the steps to this: Attempt to turn off Microsoft Defender Antivirus protection but it doesn't seem to stick out to me

#

When I am going through the incident reports

deep karma
deep karma
deep karma
inland parcel
# deep karma

Can you go to process tree for a more detailed view ?

deep karma
inland parcel
deep karma
#

Oh right, gimme a sec

deep karma
inland parcel
deep karma
#

Ok I am in there now

#

I can see the Command line values and everything else

inland parcel
deep karma
inland parcel
deep karma
#

Ok, but the thing is here is that, there are multiple Attempt[s] to turn off Defender AV protection, I do apologise if I sound dumb here, but should I start from the top and work down? I have attached a screenshot of what I mean

deep karma
#

Right then

deep karma
deep karma
deep karma
#

God, I am blind lmao

whole shale
#

i dont understand, what is the value "malware detected" 🫠

inland parcel
deep karma
vernal ravine
#

Does anyone experience error while installing content hub solution? how do you solve it?

inland parcel
whole shale
mental citrus
mental citrus
shy elm
#

Looking for an assist on Task 6 of "Can you GA?"

#

And or Task 7 I can't figure out how I am able to get the permissions to provide a new client secret

#

Overall pretty confused by this room as I'm not sure how I'm supposed to escalate from my current user as the THM provided credentials to either Kenneth's account or to the IT Ops app

#

From a long time THM user this room is pretty poor, especially when its a red teaming room dropped in the middle of a blue team paid course.

shy elm
#

@inland parcel any chance you could assist me here? I saw you are Rank 5 for completion of this room. Would really appreciate it

inland parcel
shy elm
#

I figure I need to create a new client secret for the itops app but I can't see how I have the permissions to influence a secret for the app

inland parcel
#

?

shy elm
#

I found what you're referring too

#

Thanks for the tip

inland parcel
#

Just please keep the wording appropriate , we're not alone in this channel πŸ™‚

shy elm
#

Right, sorry.

inland parcel
rose sequoiaBOT
inland parcel
inland parcel
lean vector
#

Needing a push in the right direction here. In the XDR:Lateral Movement walkthrough I am stuck on Task 5 - Question 2

What is the investigation status for the alert: 'Winlnk' malware was detected? It appears empty to me

celest shoal
lean vector
median swallow
#

Hey, can I get a hint on the way to generate a new client secret -> Azure: Can you GA?

inland parcel
whole shale
whole shale
inland parcel
whole shale
#

i dont understand, what is the value "malware detected"

inland parcel
whole shale
inland parcel
whole shale
inland parcel
umbral iceBOT
#

Gave +1 Rep to @inland parcel (current: #1 - 5492)

silent plover
#

I need help with room XDR: Lateral Movement in TASK5. I did everything according to the lab scenario choose "Last 6 months" and " Find and click "Multi-stage incident involving Execution & Lateral movement on one endpoint" (Incident Id: 42)" but there is no Incident id:42 in my lab !!

silent plover
#

How am I supposed to finish the paid content on time without it showing up in the lab environment correctly? Because if it does not show up, I can’t answer the questions asked.

wheat kiln
dawn nest
#

Would people recommend this lab rather than setting up my own environment and paying for it? I’m thinking about setting up my own resources but wondering if this is better. Obviously cost would be lower for my own

#

Does this path have full simulations and log data to look through?

#

Are there entire attack paths to see in sentinel?

mental citrus
#

I'm running into issues getting the logs to ingest when I launch the lab for "MS Sentinel: Just Looking" .

I go through the steps of select "Cloud Details" > Join Lab... wait 5 min... > "Actions > Injest Logs"... but then I give it time to finish and see from "Deployments" that it's succeeeded, but then when I go to "Logs" there's nothing there. Is there an obvious step I'm missing?

#

Just to clarify, I've closed and relaunched this lab multiple times to the same result. That's when I don't get other random errors that cause me to logout, leave the lab, and then launch again to retry

fast sorrel
#

@inland parcel
It’s not possible to complete XDR: Lateral Movement

I tried to reset the whole room, but still no luck

inland parcel
fast sorrel
#

Should I add a bug report, or how can I get this completed

inland parcel
#

but it is already counter as completed

lavish perch
#

Hi,

I'm looking at going for the SC200 cert and noticed the Defending Azure add on subscription. Would this be enough to achieve the sc200?

inland parcel
woven stag
#

hey ! Just wanted to inform you that the lab account provided in "XDR intro" room isn't working anymore . It shows that it is locked

light sentinel
chilly patrol
#

Hey all, I keep getting 'This page was moved to Defender portal, please connect your workspace to the Defender portal" errors on several of the Microsoft Sentinel rooms. Specifically on the Configuration > Analytics page, I can't create a rule and can't figure out how to view that in Defender?

sharp trout
#

Hey all, I've come from finishing the AWS path but cannot seem to start the Azure Environment. Going to Cloud Details still has all of the AWS stuff in it, Generating throws an error Room is not cloud room or is missing OU, Resetting environment just takes it back to the previous AWS state.
Did anyone have this issue?

chilly patrol
#

Yeah the way you create environments is different

chilly patrol
sharp trout
#

Oh right, I see now

#

Thanks for that

chilly patrol
#

Bumping my earlier message, in case anyone has a solution -

Hey all, I keep getting 'This page was moved to Defender portal, please connect your workspace to the Defender portal" errors on several of the Microsoft Sentinel rooms. Specifically on the Configuration > Analytics page, I can't create a rule and can't figure out how to view that in Defender?

verbal elm
sharp trout
#

Same Issue 2 weeks on without acknowledgement, disapointing considering we're paying top $ for this content

inland parcel
sharp oracle
#

i get this when clicking on section 5 entra ID, and for my colleague section 5 does not exist

#

we bought the cloud licenses today

inland parcel
sharp oracle
#

Thank you kgb, might be bugged for me then

sharp oracle
sharp trout
#

Hey all, I cannot seem to get ANY data in any of the KQL Rooms, I start and deploy the lab per the instructions, I also increase the time filter to date back to January and wait 20+ minutes for everything to get deployed.
In all rooms / labs, I do not get a single result.
Has anyone else experienced this?

sharp trout
jade marsh
verbal elm
#

Hello. I am stuck on Task 7 in "Azure: Can you GA" room in this path. I'm not sure what object it is looking for in a powershell script. The "Echo AI" hint hasn't pointed in me in the right direction yet. Any guidance would be greatly appreciated. Thanks.

sharp oracle
#

is there anywhere i can see until when i have access

verbal elm
verbal elm
sharp trout
#

Has anyone had this issue with XDR: Lateral Movement not showing up as complete on your learning path, despite the room being complete? I reset the room and resubmitted all the Q's again, same issue.

inland parcel
sharp trout
#

Thanks !
It's annoying my completionist mentality

sharp oracle
verbal elm
runic plover
#

Hello everyone πŸ‘‹!
I have a quick question regarding the room: Azure: Can you GA?
I task 5, I am not able to find the last questions asnwer and would like to require a hint on where to find it.
For me, under "App roles" says: no app roles have been added. Any other way to find this?

runic plover
#

Sadly no, and would really need it to complete the path haha

sharp oracle
#

im having the same issue, still didnt quite figure it out

#

also this one in MS sentinel just looking:

#

reset the env and it still came back

#

i think so

radiant kiln
#

You around by chance @runic plover?

runic plover
radiant kiln
# runic plover Yasss. Whats up?

I'm about to change the settings for the XDR: Operation Global Dagger to be accesible also with the cloud addon. Just one question: If you try access the room, what kind of screen do you receive? Like something along the lines of saying "You need a business subscription", or something else? Or even just a blank screen?

runic plover
#

(Sorry on company PC, no discord allowed lol)

radiant kiln
runic plover
radiant kiln
umbral iceBOT
#

Gave +1 Rep to @runic plover (current: #274 - 34)

runic plover
#

Exactly

radiant kiln
#

Room should now be accessible to cloud addon users @runic plover πŸ™Œ

runic plover
umbral iceBOT
#

Gave +1 Rep to @radiant kiln (current: #5 - 1908)

runic plover
#

Very nice!

#

Hopefully I can figure out all the questions for the above to complete the path in 4 days lol

radiant kiln
#

I think you also asked about that. Should be accessible to cloud addon users now

runic plover
#

@radiant kiln i don't know if you are the right person to contact in these cases, but we have reached the 30th of September, meaning 2FA is required for Azure tenants. This means that we need to set up 2FA for each lab, is it OK to you a personal Auth app? Or will that not allow other people to login later?

#

Also, this takes time to do for each lab, meaning it already takes a lot of time to injest logs and wait for incidents, this is even longer. From the 1 hour window you loose around 15-20 minutes now just waiting πŸ˜…

#

Also, for all Incident analysis rooms ( MS sentinel: Just looking etc) all incidents have been moved to Microsoft Defender as well lol
Meaning room walk-throughs can become out of date very fast. An update on these would be appreciated

#

Also, the new room XDR: Credential Access has not been added to the Azure path yet, but is accessible. Could someone please add it to the path? Thx in advance. πŸ™‚

radiant kiln
# runic plover <@401153154634219543> i don't know if you are the right person to contact in the...

Yes, actually I thought the MFA postponing includes September 30th and the enforcement only starts on October 1st. At least that's how I read it on the Microsoft articles. Unfortunately there is no way around it anymore, meaning everyone has to add MFA to the account that is getting spun up. For all rooms that previously had a shared account, we are trying to implement the same credential generation as for the remaining rooms.

radiant kiln
runic plover
#

Yep, sadly the MS Sentinal: Just looking room is now impossible to complete as there is no access to Defender (not allowed by the administrator) 😞

runic plover
# runic plover Yep, sadly the MS Sentinal: Just looking room is now impossible to complete as t...

OK, so I was able to complete the room, although not as intended.
After spinning up the tenant, logging in generating both alerts and then the incidents, all investigation needs to be done in MS sentinel, that is not available anymore as it gets directed to Defender.
Here for me at least, only one incident was generated not all of them as needed, but they are available as alerts.
Due to these being alerts only, they do not contain all the information needed for the investigation, only core data.
But... if you go to the alert you want to investigate > open it > scroll down > Query results and open the tables, you can get all the information needed from this to answer the tasks.
To get an ever nicer view, you can copy the "view query" data and open a search in MS Sentinel > Logs > KQL section.

Hope this helps πŸ™ someone 😊

#

But the room deff needs to be updated to show/contain defender screenshots etc

runic plover
umbral iceBOT
#

Gave +1 Rep to @radiant kiln (current: #5 - 1909)

radiant kiln
umbral iceBOT
#

Gave +1 Rep to @runic plover (current: #267 - 35)

sharp oracle
#

Sooo we have to add MFA to the accounts?

#

we can use our own devices?

runic plover
#

So I checked the Apps and App registration pages ti determine after checking the user. But still can not figure it out lol
App roles is empty for me, so is roles and administrators

#

Found it.... it took me way to long. But did it haha
For anyone wondering, PRA helps a lot!

umbral iceBOT
#

Gave +1 Rep to @runic plover (current: #256 - 36)

sharp oracle
runic plover
dapper gale
radiant kiln
limber mortar
#

hello, for clarity..to access the labs and complete this path requires the cloud license for $375?

radiant kiln
limber mortar
umbral iceBOT
#

Gave +1 Rep to @radiant kiln (current: #5 - 1910)

runic plover
umbral iceBOT
#

Gave +1 Rep to @runic plover (current: #250 - 37)

swift frigate
#

I have previously subscribed to and completed an Azure Pass. I'm not a petrol tycoon so I can't afford to pay $375 for an additional room...

raw geode
#

Howdy. n00b here. I just completed Defending Azure and found another random room that I'm stuck on. It's overly-simple until the exploit stage. Not asking for the answer, but I would really like to know how to take the known password in (Azure: Eyes Wide Shut) to be able to get the flag. Any hints or help would be appreciated.

If the answer is: learn how to Red Team, n00b, that's totally acceptable.

sharp oracle
#

is there any way to remove this? since these are limited to the bussiness license. now i cannot complete the learning pathj

modern ridgeBOT
#

Done!

trail pagoda
#

Is it expected that the KQL lab is trying to force me to setup 2FA for the provided [ephemeral] Azure identity...?

trail pagoda
#

And now I'm in, but more errors πŸ™ƒ (Lab for https://tryhackme.com/room/kqlkustobasicqueries)

An error occured when trying to fetch resources. Additional details from the underlying API that might be helpful: Please provide below info when asking for support: timestamp = 2025-10-25T01:40:39.0818005Z, correlationId = 8fbfbd82-5ea8-4fd7-9eeb-8912a5fa13c1. (Code: AccessDenied) Access is denied to the requested resource. The user might not have enough permission. (Code: AccessDenied) Try refreshing the page. Your resources aren't affected by the issue, we're just having trouble showing this view right now. To see a list of resources, select Simplified View.

Anyone seen/got past this before?

TryHackMe

TryHackMe is a free online platform for learning cyber security, using hands-on exercises and labs, all through your browser!

trail pagoda
sharp oracle
#

microsoft is enforcing MFA for all accounts

unique pendant
#

I'm having the same issue I just downloaded a temp authenticator app(mauth by xinto) for these temp logins. after i'm done with lab I'll try to remove the MFA

trail pagoda
sharp oracle
#

i would just use microsoft authenticator

rose rapids
#

So we can't connect the Microsoft Sentinel Workspace to Microsoft Defender?

iron yew
#

i actually wanted to say that i have an annual subscription and i need to pay more money to access the cloud related rooms...

#

so annoying

ebon holly
#

Does anyone have a walkthrough for the Eyes Wide Shut room? I am getting stuck on the 3 to last step.

rose rapids
#

Did they change the tables in the Azure KQL demo?

#

I dont see the tables they are talking about in the KQL rooms

rose rapids
#

Can anyone verify the kennethallen password still works for the can you ga? room

rose rapids
rose rapids
#

The Azure DevSecOps room pipeline is failing because the Azure serive connection is using a service principal with an expired client secret

rose rapids
#

XDR: Operation Global Dagger I so no incident 49

#

*see

weak portal
rose rapids
#

What part you guys stuck on?

ebon holly
hybrid badge
#

HI , please someone if can help me, I am in room KQL (Kusto): Basic Queries , but whn i am trying to serach for the Log Analytics workspaces I am getting thsi info Please provide below info when asking for support: timestamp = 2025-11-27T16:50:49.9426659Z, correlationId = a430ef7c-bea6-4fa0-b35e-e879ebfda100. Try refreshing the page. Your resources aren't affected by the issue, we're just having trouble showing this view right now. To see a list of resources, select Simplified View., is there anything els, what I should do?

dusty coral
#

I'm trying to work through XDR: Defense Evasion and Task 4 wants me to investigate an Attempt to turn off Microsoft Defender Antivirus protection incident. However, there is no such incident in the lab; I see 12 incidents and none have that title. I similarly can't find any alerts like that

This means I can't answer the question "What is the value in the Malware detected field?", because I can't find an alert to check the field

dusty coral
#

Eventually I solved this by just finding out what the default value for the field is by looking at other logs, but that doesn't seem like the intended solution

trail robin
#

In the MS Entra ID: Introduction room how long does it typically take to request a tenant environment? Although it said that it can take up to 5 days, I'm hoping for a quicker deployment.
https://tryhackme.com/room/entraidintroduction

trail pagoda
#

Nice job THM team on skirting the MFA-setup hurdle πŸ₯³
(Temporary passwords seems to be working nicely πŸ’ͺ )

trim edge
#

Anyone else having issues with the Azure Rooms: Eyes Wide Shut and Hoppity Hop. The problem I am having is the Lab is not deploying

trim edge
#

Azure lab environment looks to be down, any THM support able to assist?

fast sorrel
#

Yea, down for me as well

#

It’s now also requiring mfa setup…

unique pier
unique pier
#

πŸ™

dusk tusk
#

Got the same problem on Azure rooms eyes wide shut and hoppity hop. Cannot deploy lab. Can login into Azure, tried edge en firefoox but deploy lab gives keeping errors. I emailed support yesterday, hopefully they will fix it soon.

young canopy
ionic pulsar
#

hii

#

anyone help me Azure: Can you GA?

ionic pulsar
#

@inland parcel could you please help me in kql in one task

inland parcel
trim edge
umbral iceBOT
#

Gave +1 Rep to @young canopy (current: #306 - 32)

fast sorrel
#

@inland parcel hi, can you remove MFA on the accounts, it asks me to setup mfa…

indigo ether
#

Hi I am interested in doing Defending Azure lab. But when I try to do the implementation of Microsoft Sentinel it ask me to purchase the labs $35 per month single seat

umbral iceBOT
#

Gave +1 Rep to @young canopy (current: #287 - 35)

inland parcel
rose sequoiaBOT
#
TryHackMe's Email

TryHackMe's support email address.

stark gust
#

Hello guys anyone can help on the room Azure:Can you ga?

#

Task 4

#

Which administrator role assignment of the target app can be abused for privilege escalation?

#

On this question when i go the administrator role of the target app it not match with the answer

surreal fog
#

Question: Can I buy the $35 Teams plan as an individual instead of the expensive $329 plan? There's this team's plan which seems to be a lot cheaper compared to the 3 month plan. So can I buy this as an individual to get access to the Cloud path?

trail pagoda
umbral iceBOT
#

Gave +1 Rep to @trail pagoda (current: #150 - 70)

surreal fog
#

Btw

#

I cannot find any logs data for KQL labs labs even for the last two months

#

nothing returning for the last 100 days even

#

When I try to go to Microsoft Sentinel, I get this error:

An error occured while trying to fetch resources.

#

this is the error:

An error occured when trying to fetch resources. Additional details from the underlying API that might be helpful: Please provide below info when asking for support: timestamp = 2026-02-08T08:52:12.2838041Z, correlationId = aafedc6c-5b42-4f6e-87ab-a5f6cb116397. (Code: AccessDenied) Access is denied to the requested resource. The user might not have enough permission. (Code: AccessDenied) Try refreshing the page. Your resources aren't affected by the issue, we're just having trouble showing this view right now. To see a list of resources, select Simplified View.

surreal fog
#

Is anyone able to access anything today?

trail pagoda
surreal fog
proper pawn
#

hey guys, quick question about the Azure Defending Pathway. it says something about needing a team plan what does that actually mean?is that different from the normal subscription? and do we have to pay extra for the pathway or is it included in the monthly fee?

velvet gull
wooden grove
#

Only Teams and Business can now buy the Cloud access ??? Before there was option for add on but now I cant find it....

velvet gull
#

U got to buy teams plan and add ur own account to the plan, support told me.

stable river
#

anyone know why the Entra ID section no longer exists ?

inland parcel
#

One new Entra ID just came out

radiant kiln
#

It does exist, but it's for business subscriptions only

storm lava
#

Just confirming for those wanting to do these cloud access rooms, we pay for a teams plan and add ourselves as the single seat? Do you need a premium account as well or can I go from free tier -> team plan for the cloud training?

elfin oar
#

for the ms sentinel: investigate room, the lab section, it said to wait 15 minutes to get things up and running but the deployment page still shows two failed items after 20 minutes. It says failed on alertRules and deploy-workspace-xxxxxx

#

also for this room investigate and detect, i keep seeing that maximum rules count per tenant exceeds allowed limit. I see other people a year ago had the same issue. what does this mean and can i complete any of these labs?

elfin oar
#

Anyone can help?

lament halo
#

Someone know how to join lab in Azure DevSecOps? it is failing with ecd26695a1a84b17a0e8397cefe35bc0 error id

faint oasis
#

anyone knows why it takes 3 weeks to get a tenant populated ?

autumn gyro
#

Just got the teams package. I’m trying to do the sentinel one. Am I supposed to do the whole thing in one sitting? Or when I start a new lab should it deploy with the required resources already built?

faint oasis
#

You will have a guide for each task you follow then you proceed

stable river
#

could I get a nudge fo Can you GA? pls

gleaming verge
#

Hello,

I'm currently doing the "XDR : Privilege Escalation" (path Defending Azure > Microsoft Defender XDR )
https://tryhackme.com/room/xdrprivesc

The exercise to play in the lab is supposed to be done on the incident type of "Multi-stage incident involving privilege escalation", to have a look at the "UAC bypass was detected" alert, but this incident isn't present on the list, neither the alert.

Is there anyone who faced this issue, too?

floral thorn
fathom maple
#

I have been working all weekend to complete the Azure Tapper challenge. I have been unsuccessful in setting up the MFA for Gumby. It seems to have been previously used, which may be preventing me from assuming Gumby. Can anyone reset the IAM config so that I can try to complete the challenge today?

fathom maple
gleaming verge
#

Same issue here

gleaming verge
floral thorn
fathom maple
floral thorn
#

No..

small moon
#

Same issue here, how to solv it or skip? Thanks

ember elm
#

Same issue as well been struggling a whole week with that mfa 😭

small moon
#

I just have contacted THM regarding this room , this is a hint: "The intended way to solve this challenge is through the CLI to bypass this". Good luck!

#

I have solved it.

floral thorn
#

How? Could you give us some hints?

trail pagoda
pseudo current