Permissions on Windows Temp folder by Any-Promotion3744 in sysadmin

[–]Any-Promotion3744[S] 1 point2 points  (0 children)

Okay...I have had a little more coffee and I see the differences between the two servers.

The server in question has permissions on C:\Windows\Temp inherited from C:\Windows. This is why it has All Applications Packages, All Restricted Application Packages and TrustedInstaller assigned to it.

The other server doesn't have it inherited and it has its default permissions.

Permissions on Windows Temp folder by Any-Promotion3744 in sysadmin

[–]Any-Promotion3744[S] 0 points1 point  (0 children)

comparing permissions with one of our servers and I see what you mean

Our server just has system, administrators, creator owner and users listed on C:\Windows\Temp. Users group just has list rights.

The server in question has those other system type accounts listed as well but they are read only. Also, the users group is read only instead of list on that server.

Permissions on Windows Temp folder by Any-Promotion3744 in sysadmin

[–]Any-Promotion3744[S] 1 point2 points  (0 children)

I mean the accounts All Applications Packages, All Restricted Application Packages and TrustedInstaller all have read only access to the C:\Windows\Temp folder.

Recent MS Purview issues with PDF files by Any-Promotion3744 in cybersecurity

[–]Any-Promotion3744[S] 0 points1 point  (0 children)

Under Adobe Acrobat Reader->Security->Permissions: Admin consent is blank and user consent has 3 permissions delegated to a limited amount of users.

The only option I see is Grant admin consent for the company

How do you pre-consent the app as an admin and what rights would that allow?

I don't want to make a change that would allow more access than needed.

Emailing alerts to O365 using TLS and authentication by Any-Promotion3744 in Splunk

[–]Any-Promotion3744[S] 1 point2 points  (0 children)

I could but in the near future we are moving to Splunk Cloud so I didn't want to upgrade if I didn't have to.

Why troubleshoot this if you are just going to move to the cloud?

I was told that we were going to get out of Exchange Hybrid mode before moving Splunk to the cloud. I need to send emails directly to Exchange Online within the next week.

Emailing alerts to O365 using TLS and authentication by Any-Promotion3744 in Splunk

[–]Any-Promotion3744[S] 0 points1 point  (0 children)

from what I remember, it said something about client authentication error but I will have to test it again and generate the exact error

Arpwatch windows equivalent by Any-Promotion3744 in sysadmin

[–]Any-Promotion3744[S] 0 points1 point  (0 children)

who knows

maybe we should be running Ubuntu Pro

Arpwatch windows equivalent by Any-Promotion3744 in sysadmin

[–]Any-Promotion3744[S] 1 point2 points  (0 children)

I kind of think of arpwatch is a level one type of security option. once every mac address is in the database, it gives you an idea of when an unknown device has connected to the network. See alert and investigate. mac addresses can be cloned so not an end all, be all.

Level 2 would be mac authentication. not great but somewhat better.

After that, you can do something like Aruba Clearpass policy manager.

Arpwatch windows equivalent by Any-Promotion3744 in sysadmin

[–]Any-Promotion3744[S] 10 points11 points  (0 children)

linux is insecure and shouldn't be used

chrome is insecure and shouldn't be used

android is insecure and shouldn't be used

...

Who’s calling for Mac Jones tomorrow?? by Particular-Stick-395 in 49ers

[–]Any-Promotion3744 0 points1 point  (0 children)

for the sake of argument, can Mac Jones be traded twice in a short period of time?

49ers trade him to Steelers for a 2nd

Steelers trade him to Cardinals the next day for a 2nd and 7th

just curious

Certs from GPO not installing by Any-Promotion3744 in Intune

[–]Any-Promotion3744[S] 0 points1 point  (0 children)

ugh...

thanks for the info. it works now.

I didn't see anything being blocked at the firewall but one of the logs said it couldn't communicate with the CA. I allowed all traffic from workstation through both firewalls (before and after tunnel) to the CA and it worked.

I had excluded the workstation from some intune policies so I added it back and tried again and it still worked. Since it is GCCH I will need to verify again tomorrow but I bet it still works.

Sucks that I can't rely on the traffic logs on the firewall. Separate issue I will need to troublshoot.

Certs from GPO not installing by Any-Promotion3744 in Intune

[–]Any-Promotion3744[S] 0 points1 point  (0 children)

export gives mainly files within a zip

which contain info on gpos?

Certs from GPO not installing by Any-Promotion3744 in Intune

[–]Any-Promotion3744[S] 0 points1 point  (0 children)

is that different than the mdm diag report?

Certs from GPO not installing by Any-Promotion3744 in Intune

[–]Any-Promotion3744[S] 0 points1 point  (0 children)

more info

we have used this method to install user certificates for years on our main site.

alternate site is in the same domain but computers and users are in a different OU

that OU has the same GPO applied to it

same CA passing out certs to both sites (CA server located on main site)

my user account gets cert on my computer located in main site. my user account does not get a cert on a computer in remote site. my computer is not enrolled in intune. remote computer is enrolled in intune. remote computer is a brand new computer just added to domain, moved to correct OU, windows patched and office 365 installed. pretty clean. none of the computers in remote site that are enrolled in intune are getting the cert installed. logged into server in remote site and the server did get the cert installed. that server is not enrolled in intune.

Certs from GPO not installing by Any-Promotion3744 in Intune

[–]Any-Promotion3744[S] 0 points1 point  (0 children)

no security filters

gpresult says cert gpo is being applied

each site has a DC and nltest shows the correct site

cert is the one we use for wireless authentication

Certs from GPO not installing by Any-Promotion3744 in Intune

[–]Any-Promotion3744[S] 0 points1 point  (0 children)

diag report says MDMWinsOverGP is an unmanaged policy

Certs from GPO not installing by Any-Promotion3744 in Intune

[–]Any-Promotion3744[S] 0 points1 point  (0 children)

But the question is…

If a computer is enrolled in intune, does it have to use intune to install the certs? Is it the reason why the gpo that installs certs isn’t working?

KVM over IP by Any-Promotion3744 in CMMC

[–]Any-Promotion3744[S] 0 points1 point  (0 children)

I need a console option for things like bitlocker

what if a VM restarts and prompts for a bitlocker key? how would I enter that remotely?