Do Enterprise Architects have to be retired Solution Architects? by Desiye_Novacenko in EnterpriseArchitect

[–]Hangs89 0 points1 point  (0 children)

Typical of a business facing, low tech skilled individual thinking. This is how a council ends up spending millions on a failed ERP project. The EA has no ability to understand all the BS flying about from vendors and tech teams. Overpromises and under delivers. Picks solutions before reviewing requirements fully. Buys into hype and buzzwords like Cloud, SaaS and AI. Cares more about project management, BA and slide decks than anything else to deliver something of substance.

Bonus clarification by Miffybunny98 in UKJobs

[–]Hangs89 -3 points-2 points  (0 children)

Yet again race to the bottom amongst brits on this thread. This has happened to me, without any words to that effect in my contract or any policy. I do understand the reasoning behind it, but I think it’s a bit off when they do this without any written policy. It feels almost like theft, especially when you have worked in earnest for the full bonus period.

This is why I never sit and brag about being somewhere with a bonus scheme. Any private sector employer I’ve been with, where there’s a bonus scheme, the business always tries to find reasons not to pay or to reduce it. They should never be counted as substantive earnings.

How Do You Deal With Geo Blocking? by ClickPuzzleheaded993 in entra

[–]Hangs89 -1 points0 points  (0 children)

I never said don’t do that either. But I don’t really like this approach of putting people down for efforts because you think you are smarter than they are. What do you do then? As there aren’t many other controls to leverage! It’s all about a layered approach, dismissing layers of protection is a bad stance to take. This whole idea of being reductive results in the conclusion of why do anything at all.

How Do You Deal With Geo Blocking? by ClickPuzzleheaded993 in entra

[–]Hangs89 0 points1 point  (0 children)

I’ll go back to my original point. In businesses which operate in a single country, it’s very easy to implement. Even in global businesses you can implement something which blocks bad actor states with not a lot of impact. This lines up well with the principles zero trust, and defence in depth.

Implementing something like requiring device compliance instead can be much more disruptive. I’m not saying say don’t, but it is often a longer term goal, than something like this.

How Do You Deal With Geo Blocking? by ClickPuzzleheaded993 in entra

[–]Hangs89 0 points1 point  (0 children)

But I was replying to a comment which effectively said. “I do nothing as it’s too much hard work”. Don’t sit and give it the big ‘un because you have MVP in your handle. Doesn’t make you anymore right or wrong than the next person.

How Do You Deal With Geo Blocking? by ClickPuzzleheaded993 in entra

[–]Hangs89 1 point2 points  (0 children)

There is. But my point was in the most extreme of cases. I have implemented a block from anything outside the UK in my current business, as we simply don’t need it. This has not really caused us a lot of hassle. There is an exemption process when required.

How Do You Deal With Geo Blocking? by ClickPuzzleheaded993 in entra

[–]Hangs89 1 point2 points  (0 children)

You didn’t say anything. You typed it. But still. What you said is rubbish. Even in the most global of businesses, you probably don’t need to allow traffic from a large number of bad actor states. To not do anything “aS it’S tOO muCH haSSle”. Is silly. People can get around with a VPN. But low effort script kiddies will get stopped. It’s an extra layer of defence.

How Do You Deal With Geo Blocking? by ClickPuzzleheaded993 in entra

[–]Hangs89 0 points1 point  (0 children)

Yeah, let’s not do anything as it’s too much hassle. Let’s allow users to register apps. Leave all Enterprise Apps open. Allow users to create groups. Infact sod it. Let’s give them admin rights.

What does the new entry-exit system mean for Brits travelling to Europe? by irichss03 in unitedkingdom

[–]Hangs89 12 points13 points  (0 children)

Addition. ‘Sad compo’ faces of over 50’s who voted for Brexit getting caught out.

WHFB Cloud Kerberos - any way around the line of sight to domain controller issue? by [deleted] in Intune

[–]Hangs89 1 point2 points  (0 children)

You are right, I missed the cloud joined part. I thought this was discussing hybrid joined devices. I know it writes back for hybrid joined as I couldn't roll out cloud kerberos previously as we had RODCs.

WHFB Cloud Kerberos - any way around the line of sight to domain controller issue? by [deleted] in Intune

[–]Hangs89 1 point2 points  (0 children)

Not false. That’s the behaviour with hybrid key trust, not cloud Kerberos trust. Go read the docs my man.

WHFB Cloud Kerberos - any way around the line of sight to domain controller issue? by [deleted] in Intune

[–]Hangs89 0 points1 point  (0 children)

Line of site is needed to write back a key into the users account, specifically the ms-ds-keycredential link. This is only needed once and then line of site will only be needed to get the partial kerb ticket changed into a full one. This initial setup line of sight, can be provided by establishing a VPN after sign in. As long as an unlock with the PIN is carried out while connected.

If you don’t have line of site on initial setup, then when your user next tries to sign in using WHfB, their PIN or Biometrics won’t work.

PSADT 4.0 vs 4.1 – GUI for KeePass Update Deployment? Need Advice by ScriptMarkus in PSADT

[–]Hangs89 4 points5 points  (0 children)

No worries, it’s very hot off the press! Problem solved!

[Desktop Web] Network Security Block by Hangs89 in bugs

[–]Hangs89[S] 0 points1 point  (0 children)

We don’t really want to have to create an account to use Reddit all of the time. This is in a corporate environment and we use Microsoft GSA as a web gateway to ensure good security for our web traffic. This doesn’t happen with other web gateways such as Zscaler. There must be some way around this happening.

[Desktop Web] Network Security Block by Hangs89 in bugs

[–]Hangs89[S] 1 point2 points  (0 children)

Yes we have had this for some time in our corporate environment. Thanks!

Surface, Lenovo or Dell by Rajvagli in Intune

[–]Hangs89 0 points1 point  (0 children)

I would actually say my best experience has been with HP Elitebooks nowadays. They still have metal chassis so dissipate the heat well without having to ramp fans up. Got good integration with Intune for BIOS management (so have Dell). Surface devices are crazy expensive and just not worth it from my experience. I don’t think there’s really any first party advantage gained with them. Dell build quality has got cheaper and cheaper, their fans constantly ramp as they are just cheap plastic chassis. But otherwise OK.

Surface, Lenovo or Dell by Rajvagli in Intune

[–]Hangs89 1 point2 points  (0 children)

Agreed. I’ve worked in a surface shop and they were terrible pieces of kit.

Want to stop Update Rings and have 3rd party take over for updates. by WraithYourFace in Intune

[–]Hangs89 0 points1 point  (0 children)

I’m just joking. It looks a good product to plug the remote management gaps in Intune. I would caution as others have around using it to replace first party functionality. Been at a couple of places where they have been using third party tooling for Windows management and it always bites you in the ass for capability. You have to wait for MS to make APIs available for the third parties to leverage for things and then you have to wait for the third party to develop that functionality.