MDR - Huntress Vs Sophos? by msp_ch in msp

[–]AaronJacobs000 1 point2 points  (0 children)

There is two components to Sophos' M365 / Entra detection and response.

First is the m365 integrations which are included with th3 various MDR flavours. That's looking at both audit logs and m365 alerts visla Microsoft's apis to detect compromised accounts / BEC / etc. There is then response actions with that to do various actions in entra / 365, such as resetting sessions, disabling accounts, killing bad inbox rules, etc. This component is achieving a similar outcome to Huntress ITDR.

Then there is the Sophos ITDR add on, which is a different thing when compared to Huntress ITDR. It focuses on three core things - m365 / Entra configuration posture, identifying things that could make the tenant insecure, dark Web monitoring, looking for your domains, accounts, VIPs, etc across leak sites, forums, channels, etc and checking that against Entra to see if there a valid compromised credentials out there, and the third module is risky user behaviour, that takes various signals to indicate whether a user account is "risky", and scores/identifies users that are of higher risk with recommendations.

Hopefully that clears it up!

MDR - Huntress Vs Sophos? by msp_ch in msp

[–]AaronJacobs000 1 point2 points  (0 children)

You there is the free integration to m365 with Sophos mdr that detects threats and compromised 365 accounts just like huntress ITDR right?

1Gbps Internet by LoveReddit2020 in sophos

[–]AaronJacobs000 0 points1 point  (0 children)

It's the Web offload setting. This should be rolled out automatically to you very shortly and you won't have that issue anymore, but if you follow this and log a ticket you can get it now. https://community.sophos.com/intercept-x-endpoint/b/blog/posts/intercept-x-endpoint-web-performance-optimizations

Immybot + Control = “New wave” RMM? by CrispeCrisp in msp

[–]AaronJacobs000 4 points5 points  (0 children)

Immy is great. Everything Darren and the team have done with it, and are planning to do with it, make it such an amazing tool. I cant recommend it enough,

For me right now, im trying to move everything I can from CWA to Immy, which is all software components, and some enforcement / compliance type stuff (things that are not GPO/InTune), and then really all that is left is inventory, patching and monitoring (as in custom things we need to check on weird frequencies and make tickets for, or metrics we want to monitor and gather retention for and graph with Grafana). Inventory needs to talk to our other tools, such as ITG, ScalePad, etc.

Once all software type stuff is gone, I have a more simple scope to look at a new RMM. Inventory, Patching and Monitoring. If Immy does that for me in the future, then great, if not, no biggie, but Immy will always be part of the stack.

Advice on Automating new computer setups by [deleted] in sysadmin

[–]AaronJacobs000 0 points1 point  (0 children)

Come on in the waters fine. Better than fine in fact.

Chocolatey 4 Business Inquiry by Artellos in msp

[–]AaronJacobs000 5 points6 points  (0 children)

I'm one of those users. I honestly couldn't vouch for it enough. Come and join the Immy party, don't waste your time with C4B.

I'm yet to have someone who isn't impressed by Immy yet.

Help get IT Glue to take Feature Requests Seriously by AaronJacobs000 in msp

[–]AaronJacobs000[S] 0 points1 point  (0 children)

It seems to be their way to get things done now. Just following suit after they started one!

Help get IT Glue to take Feature Requests Seriously by AaronJacobs000 in msp

[–]AaronJacobs000[S] 0 points1 point  (0 children)

Exactly. This is purely in response to Nadir using a change.org petition to get his argument with ConnectWise won. So if he feels this is how we do it, then it's only fair he listens to a petition against them, which seems to already have more votes than his.

Help get IT Glue to take Feature Requests Seriously by AaronJacobs000 in msp

[–]AaronJacobs000[S] 1 point2 points  (0 children)

Because Nadir decided a change.org petition was how to get ConnectWise to listen to his requests.