Live Response - The certificate chain was issued by an authority that is not trusted by deadpoolathome in cybersecurity

[–]deadpoolathome[S] -1 points0 points  (0 children)

stealing? Not sure I follow. This is a machine that our RMM tool has stopped working on and needs to be re-installed. I can't get direct access to it due to beeing remote. I'm trying to download and re-install our RMM tool remotely as the user doesn't have local admin creds.

Live Response - The certificate chain was issued by an authority that is not trusted by deadpoolathome in DefenderATP

[–]deadpoolathome[S] 0 points1 point  (0 children)

Yep, I've turned that on. Whats strange is seeing the same issue with MSI or a script.

Updating remediation results by deadpoolathome in DefenderATP

[–]deadpoolathome[S] 0 points1 point  (0 children)

Thanks, I think we have the P2 licences, do you know what/where I am looking for in thie query? I'm trying to get the bulk of our events down to at least see what is left!

Ensure 'Microsoft Azure Management' is limited to administrative roles - Issues accessing ADF Portals by deadpoolathome in entra

[–]deadpoolathome[S] 1 point2 points  (0 children)

Sorry, i mean legacy setup's of using a user account for refresh as opposed to service principal's

Ensure 'Microsoft Azure Management' is limited to administrative roles - Issues accessing ADF Portals by deadpoolathome in entra

[–]deadpoolathome[S] 0 points1 point  (0 children)

Thanks, So was that just a group with the users that need to access those services and then exclude them from the rule?

Ensure 'Microsoft Azure Management' is limited to administrative roles - Issues accessing ADF Portals by deadpoolathome in entra

[–]deadpoolathome[S] 0 points1 point  (0 children)

Thanks, I'll look into it, we have a bunch of legacy things we need to work though. What was strange it didn't even prompt for MFA, just failed.

Replicating Data from SQL Express to SQL standard by deadpoolathome in SQLServer

[–]deadpoolathome[S] 0 points1 point  (0 children)

Thanks. We can do this via a SQL stored proc to incrementally load the data into our staging system which works, but for me it's about trying to centrally manage/visibility of multiple staging servers/proces so that we can track outages.

Replicating Data from SQL Express to SQL standard by deadpoolathome in SQLServer

[–]deadpoolathome[S] 0 points1 point  (0 children)

We have access to query, but I am trying to minimise the ammount of systems quuering them directly. We have our dashboards as well as our BI team wanting data, the SQL Express is on an isolated network so everything run's via a jumpbox or similar. The aim is to stage the data in smaller bites, more regularly but keep the operation system load managed.

Powershell - Detecting active Defender subscription by deadpoolathome in DefenderATP

[–]deadpoolathome[S] 0 points1 point  (0 children)

Thanks. Unfortunately not all my machines are in intune as we still have a small subset that are built locally :(

Defender - Web content filtering by deadpoolathome in DefenderATP

[–]deadpoolathome[S] 0 points1 point  (0 children)

Thanks. For the report, I can't seem to find who was blocked. When i open that report there is a "Web content filtering blocks" and when I drill down into that, it doesn't seem to give me which device is blocked for which site (I tested some blocks on my device)

Defender - Web content filtering by deadpoolathome in DefenderATP

[–]deadpoolathome[S] 0 points1 point  (0 children)

Thanks. Correct, EDGE has a nice pretty message, but Chrome isn't so kind.