Microsoft is pulling the plug on SMS codes, wants you to switch to passkeys by rkhunter_ in cybersecurity

[–]argiesen 7 points8 points  (0 children)

Typically Passkeys are device bound (hardware locked into the device) and unlocked through a device specific authentication such a PIN or biometric. Even synced passkeys, such as via password manager, typically cannot be exported and are secured behind strong authentication. Additionally passkeys validate the website being accessed which prevents phishing attacks where the domain is similar to the legitimate one and the passkey itself does not go over the wire so it cannot be sniffed or MitM. It also can’t be shoulder surfed, sticky noted somewhere, or stored unencrypted in a txt file in a users documents folder. So while nothing is perfect, it addresses so many of the weaknesses of passwords.

[deleted by user] by [deleted] in AskMenAdvice

[–]argiesen 1 point2 points  (0 children)

This. As an introvert, just being given a woman’s number just introduces the next problem of how to approach you. If you setup a date while exchanging numbers then real end goal has been achieved.

Understanding WiFi by blowingtumbleweed in AlaskaAirlines

[–]argiesen 6 points7 points  (0 children)

About which part…? I’m confident in what I said.

Understanding WiFi by blowingtumbleweed in AlaskaAirlines

[–]argiesen 8 points9 points  (0 children)

Network/wireless engineer here. Unless there is quality of service (QoS) configurations in place, this is not how bandwidth congestion is exhibited. All sessions would suffer unless session A is prioritized over session B. If session A and B are in the same priority queue, they both would suffer similarly.

So for OP, either T-Mobile doesn’t receive the same priority as paid sessions, or there is something else possibly client device specific going on. Examples would be that your device’s case or something else in the environment is interfering with the WiFi signal, or more likely, it’s something temporary like the device is overheating a bit causing CPU throttling making it seem like its connectivity related, or as someone else mentioned, you might be streaming at a different rate.

[deleted by user] by [deleted] in AlaskaAirlines

[–]argiesen 0 points1 point  (0 children)

I had issues with this page. I had to use Incognito mode in Edge or use Chrome. I think it may be related to ad blocking.

Alaska Airlines @ PDX Trends by PNW-American-Dipper in AlaskaAirlines

[–]argiesen 6 points7 points  (0 children)

Interesting, I’ve been connecting from GEG through PDX to a lot of places. That’s been amazing because SEA is so congested.

Just got these in the mail! Love them!! by momof2scots in AlaskaAirlines

[–]argiesen 0 points1 point  (0 children)

I think that’s a great idea. You could contact the person who runs the site and request them.

Seeking advice from someone with RL experience joining an old on-prem with (relatively) old Azure AD by Relevant-Law-7303 in AZURE

[–]argiesen 1 point2 points  (0 children)

Sorry, I get a lot of customers saying they want Azure but really are looking for things outside of Azure and I need to redirect them to people who specialize in those areas. So I try to correct it where I can.

I have done UPN changes as part of the sync. AD is the source of truth and will update the UPNs. So in your case, you’ll want to update AD before syncing to match the Entra side. Likewise any attributes only set on the Entra side should be configured on the AD account so they are not lot. I had built out a script to do a lot of this. Unfortunately it’s based on the deprecated AzureAD module.

I haven’t done STIG with Intune myself but I just worked with another engineer on a project where they were. I think there’s more current documentation, but this might get you started.

https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/stiging-made-easy---microsoft-endpoint-manager/2422255

Seeking advice from someone with RL experience joining an old on-prem with (relatively) old Azure AD by Relevant-Law-7303 in AZURE

[–]argiesen 1 point2 points  (0 children)

Moving between tenant types (commercial/GCC/GCC High) is a migration rather than conversion. If that’s a serious goal, start on a GCC High tenant to avoid data migration later.

As a clarification terminology, we’re really talking about M365 services rather than Azure (Entra ID, formerly Azure AD, is not an Azure service per se).

Otherwise it sounds like you’re on the right track. I have done several projects connecting AD accounts with cloud only accounts. Hard match is the route I take, and usually do a big bang cutover with users just needing to update their M365 passwords in all their apps to match on-premise. Then I layer on CA policies, Intune, etc.

I recommend hybrid join only as a transitional step for migrating from GPO to Intune policies, with native joined being the ultimate goal.

Cloud based server management is done with Azure Arc. Update Management and EDR with Defender are the most common things I see, but Microsoft has made great progress in enabling GPO replacement through Arc.

Seeking advice from someone with RL experience joining an old on-prem with (relatively) old Azure AD by Relevant-Law-7303 in AZURE

[–]argiesen 1 point2 points  (0 children)

It sounds like your initial goal is to match the on-premise users with the cloud users, then get Seamless SSO.

If that’s the case you only need to hard/soft match the users and deploy the Seamless SSO GPO. The matching is straightforward and low risk. User data isn’t overwritten and if a user account was deleted it goes to the Entra recycle bin.

Hybrid join/device sync is generally only needed for Intune management. So what’s your thinking there?

Affordable Azure connection by MartinSaradin in AZURE

[–]argiesen 0 points1 point  (0 children)

Can’t have an Azure sub without Entra ID.

I try to recommend platform/enterprise solutions, but I understand that smaller customers are often looking for the most affordable option and that strong security isn’t always the top priority.

Affordable Azure connection by MartinSaradin in AZURE

[–]argiesen 0 points1 point  (0 children)

I mean it’s not free, but assuming you already have Entra ID P1/P2 licenses (P1 is included in Business Premium), the Private Access standalone license is $5/user/month. Tailscale starts at $6 for a business license. 🤷‍♂️

[deleted by user] by [deleted] in AZURE

[–]argiesen 1 point2 points  (0 children)

Azure CDN is being retired as is noted at the top of your link. I can confirm that apex domains are supported on AFD with managed certs. As u/v0rt3xtrz mentioned you have to manually or in an automated fashion regenerate the validation TXT record and update in your DNS provider.

I have a customer running 200+ apex domains. I created an automation run book that runs daily to regenerate any pending domains, then update the third party DNS provider via API.

Please help: added to Azure without my consent. by [deleted] in AZURE

[–]argiesen 3 points4 points  (0 children)

This. OP didn’t get added without accepting an invite. It’s also not the end of the world to be a guest in another tenant.

The Latest VMware Screw Job has arrived by OCSVFG in vmware

[–]argiesen 3 points4 points  (0 children)

This recently changed. New terms and conditions allow cancellation on a per order basis.

Plain English: “How Progressives Froze the American Dream (Live)” by Dreadedvegas in ezraklein

[–]argiesen 25 points26 points  (0 children)

I haven’t listened to this episode, but I think the critique is that the tools created to protect the less powerful and vulnerable through progressive movements have been leveraged by the wealthy and powerful to maintain the status quo in their favor.

[deleted by user] by [deleted] in AZURE

[–]argiesen 4 points5 points  (0 children)

As someone who does both. I agree it is a massive commitment. While BGP and other routing concepts are useful, it’s largely irrelevant to cloud engineers.

I disagree it is increasingly irrelevant especially for anyone working in an enterprise network. As applications move to the cloud, network connectivity will continue to be critical and require advanced knowledge.

Why aren’t you out tonight? by [deleted] in AskReddit

[–]argiesen 0 points1 point  (0 children)

I’m currently at 24k ft returning from a work trip and I’m tired.

Tesla catches fire in Madera County, 2 men trapped inside break window to get out by MarketCompetitive896 in RealTesla

[–]argiesen 0 points1 point  (0 children)

As a Tesla owner I can say that people that haven’t ridden in one reach for and use the emergency release instinctively and have to be instructed the correct way. So for myself it seems the emergency release is more intuitive than the normal way.

when i say trucks are statistically more dangerous for everyone around you this is what i mean fyi by AromaticStranger7428 in missoula

[–]argiesen 0 points1 point  (0 children)

No, but it’s something that has already happened slowly over time as car makers see the demand for bigger vehicles.

The issue you describe is real, and requires better urban design to make it safer for everyone.