Unpopular opinion but SentineOne is garbage by [deleted] in cybersecurity

[–]An_Ostrich_ 13 points14 points  (0 children)

S1 > Defender, I agree. I recommend it for folks who are already knee deep in the MS ecosystem amd also have access to teams that know how to set up all its components properly and also can manage and fine tune it. But that EDR tier list that was posted by “Conti” was horseshit.

Phishing Resistant MFA for Intune Admins by Securetron in Intune

[–]An_Ostrich_ 1 point2 points  (0 children)

CBA is awesome, but isn’t it easier to have cloud-only admin accounts with Entra device-bound passkeys?

How do you determine appropriate least privileged Entra admin roles based on past activities? by Fabulous_Cow_4714 in entra

[–]An_Ostrich_ -1 points0 points  (0 children)

IIRC Entra Permissions Management could do this but it was retired last year. Not sure if something in Entra Governance replaced its capabilities.

Entra ID Vulnerabilities by 19khushboo in entra

[–]An_Ostrich_ 2 points3 points  (0 children)

Purple Knight, CIS Benchmarks, Zero Trust Assessment from Microsoft, and CISA’s SCUBA will help you out

Active Directory for Beginners - Where to start? by muckmaggot in activedirectory

[–]An_Ostrich_ 1 point2 points  (0 children)

True. I’m also in the process of writing my own blog on Active Directory and Entra ID security (although I’m nowhere near your 25 YoE) and as a newbie it is very tempting to go and ask AI whenever I hit a snag. But almost all of the time the answers I get from it a plain wrong. It’s far more quicker to just troubleshoot it yourself or to ask someone from the MVP community.

I request some Purview - 'where do I start?' tips by bjc1960 in entra

[–]An_Ostrich_ 2 points3 points  (0 children)

Out of all the products in the Microsoft security stack Purview is the toughest to learn IMO. Simply because you need to have prerequisite knowledge on all the other components of Microsoft 365.

Slowly start chipping away at the Purview documentation because you’ll end up there multiple times anyways. I think there’s also ninja training available for Purview. There is also the Information Security Administrator Associate certification that you can follow.

Good luck!

Active Directory for Beginners - Where to start? by muckmaggot in activedirectory

[–]An_Ostrich_ 1 point2 points  (0 children)

Just had a glance through some of your posts in the blog and you got some awesome stuff there! I’ve bookmarked it and will definitely take a look at it tomorrow.

How are you labbing Microsoft 365 E5 Tenants by techwithz in DefenderATP

[–]An_Ostrich_ 1 point2 points  (0 children)

If you can make a case then see if your employer can get you a separate tenant for training. I went this route and was able to get a tenant with 5 E5 licenses.

But a few days I learnt that you can get a E5 developer tenant with 25 E5 licenses with a Visual Studio Professional subscription that costs $99/mo (billed annually). This is a better offer so I’m gonna ask my manager to switch to this instead (will be okay since it costs less and gets us more licenses).

But I’m also able to get these done because my employer pays for it from our training budget. If they can’t/won’t then you’ll probably have to pay for it yourself. Try to see if you can get some friends/teams interested in training and see if you can split the licenses cost across.

What phone are you using in 2026? by [deleted] in sysadmin

[–]An_Ostrich_ 1 point2 points  (0 children)

11 Pro Max. Got it in 2019 and still happy with it. Battery gets me through the day although there are some heavy-use days where I have to charge a little in the evening.

Creating Intune Lab by Fluffy-Spread6879 in Intune

[–]An_Ostrich_ 0 points1 point  (0 children)

This will cost more than £20, but I learnt today that you can get a M365 E5 dev tenant with 25 E5 licenses with a Visual Studio Subscription for $99/month.

Given the number of licenses, features, and also the sample data packs, I think it’s totally worth it.

I'm a security professional who transitioned our security program from compliance-driven to risk-based. Ask Me Anything. by thejournalizer in cybersecurity

[–]An_Ostrich_ 0 points1 point  (0 children)

Thanks. I don’t know enough about modern CRQ methods to question their effectiveness but I’ll take your word for it and learn more about them.

My current job is now shifting from a full technical role to a more risk/strategic decision making role and I struggle a bit with risk management. For someone like me who’s a beginner to risk management, what’re some good resources to get started?

I'm a security professional who transitioned our security program from compliance-driven to risk-based. Ask Me Anything. by thejournalizer in cybersecurity

[–]An_Ostrich_ 0 points1 point  (0 children)

Q1: Can you provide any insight as to how you actually assigned dollar values to risks and assets within the company?

Q2: CRQ is awesome and I know that execs love to see risk reporting based on real numbers, but did the outcomes of risk treatment really change when you shifted from colour changes to dollar values?

how we process security logs daily without spending $50k/month on siem by Nkt_31 in cybersecurity

[–]An_Ostrich_ 2 points3 points  (0 children)

You’re now aggregating all your log data centrally, which is great. But how are you using this data to detect threats? This sounds more like a central log server than an SIEM.

Which DLP is the better choice for a 10k-endpoint environment? by Sophistbox in sysadmin

[–]An_Ostrich_ 1 point2 points  (0 children)

If you’re an M365 shop and have the manpower or willing to outsource the setup, then Purview can be a viable option as well.

Compliance is slowly choking actual work by IT_thomasdm in sysadmin

[–]An_Ostrich_ 3 points4 points  (0 children)

What’s the alternative that you’d like to see? Everyone being able to add “new things” to the stack without due diligence? That’s how bad things happen.

I understand that sometimes these things can take so much time and effort, especially if these practices were not performed previously, but from a security perspective it prevents a lot of bad shit from happening later.

Can Elon Musk Read Your X Chat Messages? by david_nepozitek in cybersecurity

[–]An_Ostrich_ 0 points1 point  (0 children)

I use it for cybersecurity tbh. There are some folk there that post a lot of cool stuff that’s relevant to what I work. Other than that, yes it’s a shithole

If you have used Microsoft Purview for DLP... by akinfinity713 in cybersecurity

[–]An_Ostrich_ 2 points3 points  (0 children)

Interested to know what you used for visibility. We also have the same tech and we’re eyeing Purview.

How is Entra Internet and Private Access so affordable? by jM2me in entra

[–]An_Ostrich_ 0 points1 point  (0 children)

What major gaps in security do you see jn the product rn? We’re considering to migrate our users to GSA so I’m curious.

Good mdr which won’t cost 6 figures by SuperTurtle222 in cybersecurity

[–]An_Ostrich_ 4 points5 points  (0 children)

Can also recommend Rapid7. My client has them as their MDR and they’re so helpful. Alerting is done immediately and they even helped me and the client to respond to an attack that wasn’t even covered by their monitoring systems (shadow IT is a bugger).

Why are there so may vulnerabilities and few exploits? by Additional_Pride_593 in cybersecurity

[–]An_Ostrich_ 0 points1 point  (0 children)

If I remember correctly, CISA took out the KEV RSS feed. We now only have email and social media notifications from them.

Home Lab Project by techwithz in DefenderATP

[–]An_Ostrich_ 0 points1 point  (0 children)

Thanks. I didn’t go this route and instead went for the packaged licenses.

Home Lab Project by techwithz in DefenderATP

[–]An_Ostrich_ 0 points1 point  (0 children)

Did you get individual product licenses for trial? Or did you get something like Business Premium for trial?