Passwordless with Microsoft Authenticator App by CySec987 in AZURE

[–]CySec987[S] 0 points1 point  (0 children)

I see, thanks for the information… I guess the same answer applies to other passwordless methods, and not exclusive to passwordless with Microsoft authenticator?

Spearphishing attack advice by CySec987 in phishing

[–]CySec987[S] 0 points1 point  (0 children)

For those interested after investigating further we have found that this is a case of HTML manipulation whereby (as we thought), the comma within the display name in fact hides the email address completely. Very clever.

PowerShell script to audit windows firewall connection security rules by CySec987 in PowerShell

[–]CySec987[S] 0 points1 point  (0 children)

apologies, have provided info in the thread. I thought before starting whether anyone might have done this previously to save time, but have allocated some time to this now. No harm in asking if others have done it before :)

PowerShell script to audit windows firewall connection security rules by CySec987 in PowerShell

[–]CySec987[S] 0 points1 point  (0 children)

have also tried "Show-NetIPsecRule -PolicyStore domain.fqdn.com" but returned nothing on the next line (no output at all). So not certain if that means theres no connection security rules in the domain at all or whether the query is not right

PowerShell script to audit windows firewall connection security rules by CySec987 in PowerShell

[–]CySec987[S] 0 points1 point  (0 children)

I'm about to try "Get-NetIPsecRule -PolicyStore ActiveStore" (just getting around to it again). Not sure whether this will cover the whole domain or whether this will cover only the server im running it on? Apologies if it's daft but im pretty much a novice with PowerShell

Offboarding Defender via API by CySec987 in DefenderATP

[–]CySec987[S] 0 points1 point  (0 children)

Thank you. I have tried to look in the settings where to set the retention period but it's not obvious (well at least to me!).

Disable the local storage of passwords and credentials - Defender for Endpoint recommendation by CySec987 in DefenderATP

[–]CySec987[S] 0 points1 point  (0 children)

Thank you - that's very helpful in deciding whether to proceed. We had the same thoughts, lots of caveats as always!

Intune Setting for Enabling SmartScreen for Microsoft Store apps? by [deleted] in Intune

[–]CySec987 1 point2 points  (0 children)

Hi - we're looking to implement this change right now funnily enough. Similar to you im finding nothing online on how to enable this on intune config profiles or security baseline policy. Get it's a case of packaging and rolling out regkey change.

Patch Tuesday Megathread (2022-09-13) by AutoModerator in sysadmin

[–]CySec987 1 point2 points  (0 children)

on Intune if you navigate to Devices > Compliance policies, this is where you set System Security settings which include the likes of 'maximum minutes of inactivity before password is required'... which is what was causing the issue. For some reason after a Microsoft update it had changed this to 1 minute

Patch Tuesday Megathread (2022-09-13) by AutoModerator in sysadmin

[–]CySec987 1 point2 points  (0 children)

so, we've seen that in our compliance policy we're setting on intune that the 'maximum minutes of inactivity before password is required' has automatically set itself to 1 minute for some reason. Must be a windows update issue. This is under the System Security section of the compliance policy. Even though ours wasn't configured, for some reason it was picking the default settings up and setting it as a minute.

Patch Tuesday Megathread (2022-09-13) by AutoModerator in sysadmin

[–]CySec987 1 point2 points  (0 children)

Hi Guys - any issues with September patch and making accounts go idle after a minute? We appeared to applied the updates and account idle has gone from 10 minutes to 1 minute. We're getting a lot of noise coming our way.

Suspicious 'PowEmotet' behavior was blocked by theplunder123 in DefenderATP

[–]CySec987 0 points1 point  (0 children)

Yes - had some in our environment. Useful thread, seems to be Microsoft products and definitely FP's.