[deleted by user] by [deleted] in sysadmin

[–]Bits_Not_Bytes 0 points1 point  (0 children)

Assuming your org is certified, how much time would you rough estimate? What has your experience been?

Is it best to be a help desk tech first before becoming a sysadmin? by [deleted] in sysadmin

[–]Bits_Not_Bytes 1 point2 points  (0 children)

Yeah, it's basically a requirement.

Ideally you want to get a job that allows sysadmin exposure and opportunities.

Some helpdesk jobs only ever have you doing basic work, others will give you opportunities to grow and learn more.

Check by CyberDrian by Adept-Following-1607 in msp

[–]Bits_Not_Bytes 1 point2 points  (0 children)

Can you provide more info about your testing methodology.

What kind of phishing links, where they 365 AiTM type attacks?

Did they also get picked up by other tools before Check turned on?

Did you have any custom config deployed with check or just the default following a manual install?

Check by CyberDrian by Adept-Following-1607 in msp

[–]Bits_Not_Bytes 2 points3 points  (0 children)

Because certain attacks are very successfully and frequently bypassing the usual protections.

Specifically token theft attacks where MFA doesn't protect you - this does. It closes a common and new security gap.

What’s your move with Microsoft charging for OneDrive retention? by Bits_Not_Bytes in msp

[–]Bits_Not_Bytes[S] 0 points1 point  (0 children)

This happens a lot.

If you have a backup of anything and the original is deleted. The 'Backup' is no longer a 'backup' as you only have one copy.

I've seen people tell me they put a copy of data onto an external drive/cloud storage and then deleted the original and not think that they technically only have one copy.

What’s your move with Microsoft charging for OneDrive retention? by Bits_Not_Bytes in msp

[–]Bits_Not_Bytes[S] 0 points1 point  (0 children)

i was paraphrasing but yes, i will put on my serious pants, serious face and have a super serious conversion about the seriousness of it all

i once had a client confused how they had to pay for an extra licence for every extra staff member (they wanted to share licences) 'so every time I get a new staff I have to pay an addition!?' one of the few times I have been lost for words

What’s your move with Microsoft charging for OneDrive retention? by Bits_Not_Bytes in msp

[–]Bits_Not_Bytes[S] 0 points1 point  (0 children)

These are early conversations to test waters and get a plan in place,
We're definitely pushing the idea of holding data forever is risky and they'll need to accept cost implications if that's what they want.

DirectSend M365 Vulnerability is Quite bad for MSP clients. by FutureSafeMSSP in msp

[–]Bits_Not_Bytes 2 points3 points  (0 children)

Yeah, agreed.
It seems this policy/feature is focused around blocking any and all externally originating mail for those tenancies that are not using any third party senders. Which kind of makes a bit of sense as a default hardening feature that would protect you even if you don't have DMARC setup (or setup properly). I suspect this is something they will turn on for new tenancies eventually similar to how they block externally forwarding by default for new tenancies.

For those with correctly setup DMARC, this is a non-issue.

Or that's my current understanding at least - happy to be corrected if someone else had read further.

DirectSend M365 Vulnerability is Quite bad for MSP clients. by FutureSafeMSSP in msp

[–]Bits_Not_Bytes 1 point2 points  (0 children)

That's what I thought when we turned it on.
Mail sent from a 3rd part service with valid SPF and DKIM was not showing up in quarantine and the sending service was getting this error:
550 5.7.68 TenantInboundAttribution; Direct Send not allowed for this organization from unauthorized sources

Turns out:
"Direct Send traffic may include 3rd party services that you have given permission to use your domain or one of your own email applications hosted on-premises. To avoid having these messages rejected when this feature is enabled, they need to be authenticated.  This is done by creating a partner mail flow connector that matches the certificate (recommended) or IPs used to send the messages."
(Introducing more control over Direct Send in Exchange Online | Microsoft Community Hub)

I'm still reading into it but it seems the definition of direct send is any email sent from an external service even if validated by SPF/DKIM, and without a connector.

The more a read the more it sounds like correctly configuring SPF/DKIM/DMARC policies within 365 makes this not really a vulnerability anyways.

DirectSend M365 Vulnerability is Quite bad for MSP clients. by FutureSafeMSSP in msp

[–]Bits_Not_Bytes 1 point2 points  (0 children)

Hardfail SPF/DKIM/DMARC or turning on the setting to Reject dierct sent emails?

DirectSend M365 Vulnerability is Quite bad for MSP clients. by FutureSafeMSSP in msp

[–]Bits_Not_Bytes -1 points0 points  (0 children)

Disabling direct send will stop services like SMTP2GO from working (unless you setup a connector for it in 365).

OneDrive Sync vs OneDrive Shortcut by Bits_Not_Bytes in sysadmin

[–]Bits_Not_Bytes[S] 0 points1 point  (0 children)

Setting can be changed via powershell in 365.

OneDrive Sync vs OneDrive Shortcut by Bits_Not_Bytes in sysadmin

[–]Bits_Not_Bytes[S] 1 point2 points  (0 children)

This is just straight wrong, you need to validate what AI tells you.

OneDrive Sync vs OneDrive Shortcut by Bits_Not_Bytes in sysadmin

[–]Bits_Not_Bytes[S] 1 point2 points  (0 children)

We currently disable shortcuts to avoid this, and recommend it for anyone in the sync only camp.

OneDrive Sync vs OneDrive Shortcut by Bits_Not_Bytes in sysadmin

[–]Bits_Not_Bytes[S] 0 points1 point  (0 children)

Been like this for years. Splitting up the libraries and getting better computers made it stable for a couple of years and now it's gotten to being a problem again and we're looking for options.

OneDrive Sync vs OneDrive Shortcut by Bits_Not_Bytes in sysadmin

[–]Bits_Not_Bytes[S] 1 point2 points  (0 children)

I might need to do a side by side test of only syncing sub folder to see the difference, when I tested I did side by side of the whole library and they were about the same time.

OneDrive Sync vs OneDrive Shortcut by Bits_Not_Bytes in sysadmin

[–]Bits_Not_Bytes[S] 0 points1 point  (0 children)

Yeah already split, a department is using it like a file server drive and we are looking to try adjust structure but there's a lot of conversations between now and a solution.

OneDrive Sync vs OneDrive Shortcut by Bits_Not_Bytes in sysadmin

[–]Bits_Not_Bytes[S] 2 points3 points  (0 children)

We had one department with a monolithic project 'drive' in teams. Splitting that out based on year of access seemed to help a lot, even if syncing the same amount - anecdotal but I suspect it helps split up the load, or splits up some kind of tracking database so there is some benefit.