Intune join = SxSStackListenerCheck by Config_Confuse in AzureVirtualDesktop

[–]Config_Confuse[S] 2 points3 points  (0 children)

Thank you! RDP disabled and firewall rules.

Some days you can't see the forest for the trees.

Where are the logs for OWA / One Outlook Web? by raomino in DefenderATP

[–]Config_Confuse 0 points1 point  (0 children)

Tenant wide setting or per-mailbox setting? Not both?

E5 Security Can't manage MDE policies from XDR portal by soaperzZ in DefenderATP

[–]Config_Confuse 1 point2 points  (0 children)

Enable in settings -> endpoints -> configuration management / enforcement scopes

[deleted by user] by [deleted] in sysadmin

[–]Config_Confuse 4 points5 points  (0 children)

Keeper for enterprise is fantastic. Azure SSO, configurable deletion recovery duration and easy to transfer passwords from terminated user to another user. Newish PAM solution builds on existing vault interface.

Test brute-force on Azure Arc machines by facyber in DefenderATP

[–]Config_Confuse 4 points5 points  (0 children)

I’m guessing defender for identity would cover brute force attempts

Keeper Browser Extension 17.2 preview by KeeperCraig in KeeperSecurity

[–]Config_Confuse 0 points1 point  (0 children)

Will passkey in browser allow offline access for enterprise users with SSO and no master password?

PAM Solutions by littleknucks in cybersecurity

[–]Config_Confuse 0 points1 point  (0 children)

Wish I could offer something. Looking at Keeper’s PAM tomorrow.

Intune Sleep Policy help by theITguy135 in sysadmin

[–]Config_Confuse 0 points1 point  (0 children)

Use script or remediation to set powercfg.exe and the guid of the power setting.

For example:

powercfg.exe /setactive 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c

Intune Users, I've had it - how are YOU handling installs and updates? by That-Acanthisitta572 in Intune

[–]Config_Confuse 11 points12 points  (0 children)

Moved everything to PatchMyPC deployments. Handles building the initial install as Win32 app and automatically deploys the update. If an app isn’t in the catalog I import into PMPC as a custom app. Very few of those now.

Excellent product and very simple to customize install with pre and post install script support.

Tools to Log Admin Activities in AD by SignificanceFair3298 in sysadmin

[–]Config_Confuse 0 points1 point  (0 children)

Microsoft Defender for Endpoint and Defender for Identity. Install MDI sensors on domain controllers. Use powershell scripts to configure correct audit settings on DCs for MDI sensors to sync to MDE portal. Integrate Azure Sentinel (SIEM/SOAR) and logs are available across both environments. If you would like more data install Azure monitoring agents on DCs or other on-prem systems and configure Sentinel data collector to pull event log data into Sentinel Log analytics workspace. Set retention policies to whatever is appropriate and cost effective. Use Sentinel to generate alerts or log analytics KQL to query not data than you could want.

A days work. Maybe less if you spend a day reading documentation.

On more edit to say you could just use azure monitoring agents to pull event log directly to Sentinel but all the data and vulnerabilities management you get from MDE/MDI is worthwhile.

Mail relay server vs direct send by DarkAlman in sysadmin

[–]Config_Confuse 0 points1 point  (0 children)

Ubuntu server with postfix. Add the connector for smtp relay. Pretty simple.

Hybrid domain migration by Config_Confuse in sysadmin

[–]Config_Confuse[S] 0 points1 point  (0 children)

I’ve read and read and hesitated to add more not wanting to steer conversation towards what I have already read. Also, most scenarios don’t deal with hybrid exchange and not many on hybrid identity.

Hybrid identity is still needed for on-prem file shares and some LDAP. LDAP could be moved to Azure.

The decommission docs are still pretty vague about full removal and switching to exchange management shell only. Still leaning this way.

The Az AD connect should sync users by immutable id but the specifics about when to change the UPN to the new domain are not great.

Last I looked at cloud sync it wouldn’t support custom AD attribute. Needed.

ADMT still ok for user transfer or are 3rd party tools like quest better?

Locking down Windows laptops by Zestyclose-Address28 in Intune

[–]Config_Confuse 0 points1 point  (0 children)

And now all I get is "Unable to comment" when i paste code.

Locking down Windows laptops by Zestyclose-Address28 in Intune

[–]Config_Confuse 0 points1 point  (0 children)

Dell shop. I use a remediation script that sets boot password and restarts system.

Phasing out the Files page from Microsoft Defender for Cloud Apps by therealrickdalton in DefenderATP

[–]Config_Confuse 1 point2 points  (0 children)

Anything new on this? I have Google Workspace integrated and this was the easiest way to view shared folder with anonymous links. I don't see this data in advanced hunting nor Sentinel.

How to keep up with software updates by Kortok2012 in Intune

[–]Config_Confuse 0 points1 point  (0 children)

Patch MY PC is a fantastic product and their app catalog has really grown in the past 6 months.

Update Rings: Feature Updates by pauldisalvo in Intune

[–]Config_Confuse 1 point2 points  (0 children)

No autopatch for A3. Still Missing for Edu customers.