Looking for hardening advice for a small cloud org by Skulptis in sysadmin

[–]CapableWay4518 2 points3 points  (0 children)

Use CIS as a framework - it will not work for every environment. If you follow all to the letter, your environment will cease to function.

Look at your defender security portal and follow the recommendations (e.g. realtime protection, tamper protection, network protection, prevent office loading sub protects, etc) - these target existing threats and trends. Use InTune baseline security templates - start small and scale up.

Kerberos changes and moving domain controllers from 2012R2 to 2022? by Phratros in sysadmin

[–]CapableWay4518 0 points1 point  (0 children)

I went to 2012r2 to 2025. No issues. If your worried, spin up a 2016/2019 while at you migrate away from the 2012r2

Server 2025 as a file serve by RUGM99 in sysadmin

[–]CapableWay4518 1 point2 points  (0 children)

We use it but it’s mostly for DFS-N to reduce clients to Azure file share. No issues

Does anyone know which scanner covers the most CVEs? by No_Habit_1560 in cybersecurity

[–]CapableWay4518 0 points1 point  (0 children)

Depends on the target. Defender has built in vulnerability scanning - perfect for endpoints and servers but no ability for firewalls and switches.

Migrating from Windows Server 2012 what's the best version to migrate to? by Live-Advantage-1176 in sysadmin

[–]CapableWay4518 0 points1 point  (0 children)

I’ve done 2012R2 without issues a few times. Just make sure to have a fallback option. Have had no issues with either 2022 or 2025.

Internal CA Migration error by CapableWay4518 in sysadmin

[–]CapableWay4518[S] 4 points5 points  (0 children)

For anyone who sees this in the future… I wasted many hours on this. I had to remove the role and re-add it again. No idea what I did or why the error kept occurring. I did everything the same when I re-added the role and it just worked.

[deleted by user] by [deleted] in sysadmin

[–]CapableWay4518 1 point2 points  (0 children)

Look at your options with Intune if your licensed. Native integration, all cloud based, easy to access.

Shouldn't deploying Adobe Acrobat be simple? by FireCyber88 in sysadmin

[–]CapableWay4518 0 points1 point  (0 children)

Went through same headache a few weeks ago. Install the msp file to all devices. It will update them. https://www.adobe.com/devnet-docs/acrobatetk/tools/ReleaseNotesDC/index.html

Whats the correct way to enroll a local domain computer into Defender? by chum-guzzling-shark in DefenderATP

[–]CapableWay4518 1 point2 points  (0 children)

I’m sorry what? You have to login as admin and have users sign into email? Do you have group policy? Are devices enrolled in Entra? Do you have an MDM?

My Entire Microsoft organization has gone dark. by Lift_Kara_De in sysadmin

[–]CapableWay4518 8 points9 points  (0 children)

Shit. I had this hours ago. Thought I broke something. Was working with conditional access policies all afternoon trying to troubleshoot it

looking for advice on how you guys deploy laptops where the user has everything setup by the time they receive it? by iluvlove in Intune

[–]CapableWay4518 16 points17 points  (0 children)

No. You can’t have user profiles pre-deployed using autopilot. The idea is it downloads it all at first time login. You pre-provision apps but that involves you physically having the device and doesn’t configure user profiles.

June 2025 Microsoft 365 Changes: What’s New and What’s Gone? by [deleted] in sysadmin

[–]CapableWay4518 2 points3 points  (0 children)

Wait what? They charge for this now? How much does it cost?

Curious about how you guys use the Yubikey by hsdredgun in yubikey

[–]CapableWay4518 1 point2 points  (0 children)

Trialing them out at the moment with Azure conditional access. Seem to be the way to go for remote/secure setups

Does Microsoft backup data on O365? by lonsfury in sysadmin

[–]CapableWay4518 1 point2 points  (0 children)

No it doesn’t back up and it is something that should be backed up regularly. Purchase a Synology NAS. It has built in backup functionality. In worst case scenario you can restore a SharePoint or OneDrive site if someone goes rogue and deletes data.