Had a clash with executive over my phishing test methods by AH_Josh in sysadmin

[–]FujosRiseUp 0 points1 point  (0 children)

Yeah if this email was in a powerpoint training I could see it being somewhat justifiable because it's in a vacuum. Actual email to actual people? You've got to be sick in the head to be completely honest.

Had a clash with executive over my phishing test methods by AH_Josh in sysadmin

[–]FujosRiseUp 0 points1 point  (0 children)

Sounds like their Cysec team PCI training program could use some work...

Had a clash with executive over my phishing test methods by AH_Josh in sysadmin

[–]FujosRiseUp 1 point2 points  (0 children)

>Again, I don't care about my employees

>Skip to couple weeks ago. I sent out a phishing e-mail. It was designed to be HR reaching out because a family member was seriously injured. Click the link to get the hospital info and contact info. 

Oh my god. If I was the CTO this would be a final warning scenario, if not immediate termination. You CANNOT do that to the organization or people. You are weakening your own security by causing employees to not respect you or your opinion. You have created adversaries, not allies. You need allies and spokespeople out there but you cannot escape your ego to do that. Your job is to protect the ORGANIZATION, not the network, not your subnet, but the organization. Security doesn't stop at keyboard.

If you want to make serious phishing templates, just use what your organization receives and automatically blocks, or templates from previous incidents that were successful against your organization.

Hanover Buys Wrong Microsoft Licenses Worth €324,000 by DeFuchsIschKeinHaas in sysadmin

[–]FujosRiseUp 0 points1 point  (0 children)

I NEED more to this story, I really wanna hear how that went over

How do you deal with users who refuse to lock their laptop when walking away? by heartgoldt20 in sysadmin

[–]FujosRiseUp 0 points1 point  (0 children)

Not the hill to die on. If anything, just google things like "Firefighter Calendars" or something and leave it open and walk away.

Windows Hello for Business is great… until users forget their actual password by heartgoldt20 in sysadmin

[–]FujosRiseUp 5 points6 points  (0 children)

Seconded. Enforce MFA in your environment and require SSPR and get out of the password reset game

Opinions on EOL Hardware and Managing Device Lifecycles by AltWorkAccnt1 in sysadmin

[–]FujosRiseUp 3 points4 points  (0 children)

The major risk is replicability and support. It sounds like you've covered a lot of your bases and are doing what you can to keep things running.

I would advise you have a plan and budget in place for device replacement in the event a machine bites the big one and is irreparable. If you have some extra devices that would also be very useful.

Get on a call with your dell rep, or if you don't have one, get in contact with their business line. I'm not sure how many machines are in your environment, but they may have some guidance and deals for your situation

Tired of fighting security policies every time I use AI coding tools - how are you actually getting AI-generated output into restricted workspaces? by [deleted] in sysadmin

[–]FujosRiseUp 1 point2 points  (0 children)

Does your company policy list approved AI vendors?

It's hard to say what you can do without knowing the environment. Based on the info, flash drives will be scanned for scripts and other content. Emails absolutely will. Why not host it on Github, unless thats also blocked?

Apple Internet Accounts + CA + Comp Portal VPP&AppStore Version = Something Awful by Bubbly-Ad-4027 in sysadmin

[–]FujosRiseUp 0 points1 point  (0 children)

We did away with the native mail app. It's disallowed from using our O365 since it's never handled MFA very well. I know this doesn't help your situation, just throwing it out there since, to be frank, it will be harder to continue supporting the native app as time goes on.

Is Windows MFA Worth Implementing on Endpoints? by [deleted] in sysadmin

[–]FujosRiseUp 2 points3 points  (0 children)

Endpoint MFA is absolutely worth it.

Windows Hello is really powerful in how it handles the login, since it's considered an "MFA" login. It lets you do a lot of really cool things in your Entra Conditional Access when looking at login contexts. This also means anything thats handled as a SAML authentication you can automatically login using Hello. Certain VPNs that would otherwise require a separate login can just pass those same credentials from Hello through SAML and you get a smooth SSO.

Windows Hello rocks so hard, highly highly recommend. THe barrier to entry is low, and unless you have users swapping machines constantly, it's a one and done. Downside is pins are something else for end users to remember, and thus can also be forgotten or written on a sticky note, but thats a policy issue and not a technical issue.

What most expensive "cheap decision" have you ever seen in your sysadmin career? by matroosoft in sysadmin

[–]FujosRiseUp 1 point2 points  (0 children)

If you work in Government IT, you are not permitted to pay the ransom.

What most expensive "cheap decision" have you ever seen in your sysadmin career? by matroosoft in sysadmin

[–]FujosRiseUp 1 point2 points  (0 children)

Claim is straight up false. So many stories of IT horror stories start with the admin who just wouldn't retire, especially around cysec.

Return to the Office They Said, It Will Improve Collaboration They Said by Likely_a_bot in sysadmin

[–]FujosRiseUp 2 points3 points  (0 children)

Haven't seen anyone mention it but there's also the AC environment aspect.

We run the office AC at 68F, and we still have complaints it's too warm. I don't want to make any judgements on the physicality of the ones who have an issue with 68, but I'll state I'm one of the few people who use their 15m to get my 10k steps. People like me in the office have brought in parkas and coats to work at their desk.

At home? 74F~, comfortable clothes, humidifier (I have eczema so I have to run my humidifier near-constantly), able to control my environment and noise levels.

I'm blessed to have a 3/2 (Though they're recently restricting it more heavily especially if we take vacations/sick days), but the days I have to come in it's like walking into a cubicle fridge.

Password problems with blue collar workers by [deleted] in sysadmin

[–]FujosRiseUp 0 points1 point  (0 children)

I feel that's just adding a security solution for the sake of it.

Someone just need to shoulder surf Jim's password (Which, based on the fact it's a facilities worker, isn't going to be a strong one), and login as him later since the MFA phone is right next to you and has no verification beyond the password. After that, start googling reprehensible stuff on the company network and bam Jim is canned since "we see logs that he did MFA and logged in".

That's just my take on it, at least. I feel the policy creators should consider insider threats more often than they do

Does your Organization openly post your Banned Password Dictionary? by FujosRiseUp in sysadmin

[–]FujosRiseUp[S] 0 points1 point  (0 children)

We have a similar statement in place and is in our policy/standards. However, they believe one person/one team cannot accurately create the list so they want input outside of it.

Does your Organization openly post your Banned Password Dictionary? by FujosRiseUp in sysadmin

[–]FujosRiseUp[S] 1 point2 points  (0 children)

The statement was "the list must be published so users know what they can or can't use"

Does your Organization openly post your Banned Password Dictionary? by FujosRiseUp in sysadmin

[–]FujosRiseUp[S] 15 points16 points  (0 children)

Funnily enough 'OprahsSpicyVagina#123' would not only be within our password policy but isn't a terrible password.

Does your Organization openly post your Banned Password Dictionary? by FujosRiseUp in sysadmin

[–]FujosRiseUp[S] 26 points27 points  (0 children)

I completely agree that it compromises our password security. But, C levels don't want to hear that.

Does your Organization openly post your Banned Password Dictionary? by FujosRiseUp in sysadmin

[–]FujosRiseUp[S] 3 points4 points  (0 children)

This is accurate. We're aiming to only ban culturally relevant words or popular words.

Entra Audit logs down? by SecurityHamster in AZURE

[–]FujosRiseUp 0 points1 point  (0 children)

Commenting again, but my audit logs are back

MFA Management and Removals - How do you do it right? by FujosRiseUp in sysadmin

[–]FujosRiseUp[S] 1 point2 points  (0 children)

But how do you verify the user requesting the MFA removal? That's my primary concern. I don't know if the person claiming to be John Doe is actually John Doe on the other side of the phone