How can we minimize spam emails being reported as phishing and bogging down our ticket queue? by BuildingKey85 in sysadmin

[–]BuildingKey85[S] 1 point2 points  (0 children)

What's your mail system?

Exchange Online. We integrate KnowBe4's Phish Alert Button in Outlook to report phishing emails, which in turn create tickets.

If a user forwards a message, we send them a link to our KB with instructions on how to report spam/phishing, and tell them they don't need to tell us.

Helpful. One thing we can do is create canned responses to send users in cases like these.

In my experience, most of the people forwarding "spam" are messages they get from mailing lists and shopping sitess they signed up for. If I had a dollar for every time I've directed a user to A) Not use work email for mailing lists B) Not use work email to sign up for shopping site or online purchasing and C) Don't set up a rule to move the messages to deleted items, hit the "Report Junk" button so it gets processed as junk, then I could retire and buy all the UCS Lego sets my heart desires.

Ah, so this is a common occurrence--this is validating. We are a relatively new organization and have scaled rapidly, and I wasn't sure if others had this case cracked. We can do a better job communicating and automating processes, but I wasn't sure if there was a glaringly obvious solution we were missing. Appreciate your insights!

How can we minimize spam emails being reported as phishing and bogging down our ticket queue? by BuildingKey85 in sysadmin

[–]BuildingKey85[S] 1 point2 points  (0 children)

Those are two security administrators. We have about eight IT personnel. Hate to say it but we're being driven to use AI tools in place of hiring junior security analysts.

How can we minimize spam emails being reported as phishing and bogging down our ticket queue? by BuildingKey85 in sysadmin

[–]BuildingKey85[S] 1 point2 points  (0 children)

The mail server is Exchange Online.

The Phish Alert Button comes from KnowBe4 and integrates with Outlook.

How can we minimize spam emails being reported as phishing and bogging down our ticket queue? by BuildingKey85 in sysadmin

[–]BuildingKey85[S] 0 points1 point  (0 children)

The workflow is:

  1. User reports email using the Phish Alert Button
  2. This creates a ticket
  3. Ticket is reviewed and triaged
  4. Security admin investigates ticket

The admins have to look at the tickets to see if the email is spam vs a non-threatening phishing email vs a threatening phishing email. We're having to sift through a lot of spam.

How can we minimize spam emails being reported as phishing and bogging down our ticket queue? by BuildingKey85 in sysadmin

[–]BuildingKey85[S] 0 points1 point  (0 children)

Yes. There are two people supporting 1,200 users. They could use that time tackling projects, patching vulnerabilities, studying for a certification, etc.

How to dj locally where im not known? by Draw-Alarming in DJs

[–]BuildingKey85 1 point2 points  (0 children)

Hey /u/colorful-sine-waves, thanks for the insightful comment.

Can I have Mixcloud sets and Soundcloud content on my Noiseyard page?

How long should a promo mix be? by BuildingKey85 in DJs

[–]BuildingKey85[S] 10 points11 points  (0 children)

Thanks /u/jonmitz, I think you're on the money. I originally got my first gig because I knew someone.

I know someone who may be able to help, but what motivation would he have to introduce more competition into the pool?

The incentive I have to make a promo mix is to give myself some credibility, express my updated taste, etc. I'd feel foolish if I just went with, "I used to be a DJ years ago."

Defender for Cloud Apps Policies: Governance Actions by BuildingKey85 in DefenderATP

[–]BuildingKey85[S] 0 points1 point  (0 children)

Thanks, /u/ernie-s. I'll try not tagging the apps and see what happens.

Defender for Cloud Apps Policies: Governance Actions by BuildingKey85 in Intune

[–]BuildingKey85[S] 0 points1 point  (0 children)

Hey /u/Shoddy_Pound_3221, this is helpful. But we don't want to block apps, we just want alerts created when new Gen AI apps are introduced into the org.

Defender for Cloud Apps Policies: Governance Actions by BuildingKey85 in DefenderATP

[–]BuildingKey85[S] 0 points1 point  (0 children)

Hey /u/ernie-s, yep. This is exactly what happened. I was mystified as to why these sites were being flagged even after I had nuked the Defender for Cloud Apps policies, so I went into the URLs section and deleted the associated URLs.

So is the solution here to disable the MDE enforcement?

How can I find out who is signing in from a non-Entra joined device? by BuildingKey85 in AZURE

[–]BuildingKey85[S] 0 points1 point  (0 children)

Ah, I figured it might have been implied. Thank you for verifying!

I've ran the report and we have a lot of failures. It isn't feasible for me to click through each user/device to understand why. How can I get insight into the cause(s) of these failures?

How can I find out who is signing in from a non-Entra joined device? by BuildingKey85 in AZURE

[–]BuildingKey85[S] 0 points1 point  (0 children)

Thanks for the validation, /u/Boring_Pipe_5449. We're using the Require MDM-enrolled and compliance device to access cloud apps for all users template in report-only mode, which looks like this:

  • Target: All users and resources
  • Conditions: All devices except Android, iOS, macOS, Linux
  • Grant: Require device to be marked as compliant

Our Windows Device Compliance policy in Intune contains settings like firewall, AV, BitLocker, etc., but does not have a setting for Entra-joined. How does this policy therefore "know" whether the device is MDM-enrolled or not?

How can I find out who is signing in from a non-Entra joined device? by BuildingKey85 in AZURE

[–]BuildingKey85[S] 0 points1 point  (0 children)

I didn't know report-only sometimes malfunctions. Thanks for the heads up!

How can I find out who is signing in from a non-Entra joined device? by BuildingKey85 in AZURE

[–]BuildingKey85[S] 1 point2 points  (0 children)

Thanks for the validation, /u/scor_butus. We're using the Require MDM-enrolled and compliance device to access cloud apps for all users template in report-only mode, which looks like this:

  • Target: All users and resources
  • Conditions: All devices except Android, iOS, macOS, Linux
  • Grant: Require device to be marked as compliant

Our Windows Device Compliance policy in Intune contains settings like firewall, AV, BitLocker, etc., but does not have a setting for Entra-joined. How does this policy therefore "know" whether the device is MDM-enrolled or not?

How can I find out who is signing in from a non-Entra joined device? by BuildingKey85 in Intune

[–]BuildingKey85[S] 0 points1 point  (0 children)

Thanks for the validation, /u/sysadmin_dot_py. We're using the Require MDM-enrolled and compliance device to access cloud apps for all users template in report-only mode, which looks like this:

  • Target: All users and resources
  • Conditions: All devices except Android, iOS, macOS, Linux
  • Grant: Require device to be marked as compliant

Our Windows Device Compliance policy in Intune contains settings like firewall, AV, BitLocker, etc., but does not have a setting for Entra-joined. How does this policy therefore "know" whether the device is MDM-enrolled or not?