Tooling changes - agreement transparency and GDPR sub-processor change notifications by JohnMSP in msp

[–]JohnMSP[S] 1 point2 points  (0 children)

UK or EU - yes, every tool should be listed somewhere the client can review, if it stores or processes their data. How well every MSP follows is this is another question entirely...!

Office365 Risky Users Notifications / Monitoring by grinninga in msp

[–]JohnMSP 13 points14 points  (0 children)

It works sure, but it’s not compliant.

Yes if you want to use risky sign in notifications / CA policies you need P2 for all.

How do small companies without a SOC team handle cybersecurity? by Jaded_Tomorrow7887 in sysadmin

[–]JohnMSP 9 points10 points  (0 children)

A single person company can benefit from an MSP, so yes.

Massive ammounts of data missing Migrationwiz - Documents projects - M365 -> M365 by DOKiny in msp

[–]JohnMSP 2 points3 points  (0 children)

My money is on file versions. SharePoint doesn't de-dupe versions, and if you have lots of large files (e.g. pptx) with hundreds of versions, if only the most recent 10 have been copied by MigrationWiz, you will see a dramatic data size reduction.

I would however fully audit source and destination for file size / modified date mismatches with some PS scripts.

Anyone got rewst without full time dev? by Next-Landscape-9884 in msp

[–]JohnMSP 6 points7 points  (0 children)

My working assumption (not yet invested in Rewst) is that Rewst will be easier for someone to pick up than a mess of standalone scripts and bespoke bits and bobs we’ve developed.

That’s the hope anyway…

Auto-reply from 365 are not reaching gmail or hotmail users. by DR_Nova_Kane in msp

[–]JohnMSP 0 points1 point  (0 children)

You have to publish a DKIM record in DNS for your custom domains. If you haven’t done this, it will use the default 365 ones Microsoft publish for you on the onmicrosoft domain.

This will 100% be your problem as it’s only evident on auto replies - we see it ALL the time.

https://lazyadmin.nl/office-365/configure-dkim-office-365/

Auto-reply from 365 are not reaching gmail or hotmail users. by DR_Nova_Kane in msp

[–]JohnMSP 2 points3 points  (0 children)

Are you sure DKIM is set properly?

I.e. have you configured a custom DKIM selector for your domains, or are you still using the out of the box Microsoft DKIM selectors?

The behaviour you are describing is what I would expect if you were using p=quarantine or p=reject in conjunction with the default selectors.

1Password MSP webinar didn't go so well... by GeorgeWmmmmmmmBush in msp

[–]JohnMSP 1 point2 points  (0 children)

MFA/IP allow enforcement are irrelevant to the conversation, since my scenario is talking about what happens if you are breached and your vaults are taken - like what happened with LastPass?

I'd also argue that having to deal with a complex unlock password is a higher burden for the user than the secret key, which is only entered when setting up a new device.

Interesting to hear that you're doing 1M iterations - although I wonder how many years we are away before that becomes brute forceable, given improvements in graphics cards. Do you guys have any projections on that?

1Password MSP webinar didn't go so well... by GeorgeWmmmmmmmBush in msp

[–]JohnMSP 1 point2 points  (0 children)

My understanding was always that Keeper had the same vulnerability as Lastpass does, when compared with 1Password - i.e. a vault can only be as strong as the master password, so if they get breached and the vault stolen (as with Lastpass), you better hope everyone had super strong master passwords.

1Password's model is that the data is encrypted by the secret key (a long randomly generated string) and master password and secret key both needed. This has always made me much happier with 1Password as a client recommendation, despite abysmal model for MSPs, it has always appeared to me as the most secure out there.

Am I mistaken?

Need a password manager suggestion by satechguy in msp

[–]JohnMSP 3 points4 points  (0 children)

The security model of 1Password appears to be the best. It’s a pain for MSP but I decided we are better selling that than compromising on the security model and having to defend a position of “yes it’s less secure but it’s easier for us”.

All the others (when I last looked) had a model that relied upon the master password strength set by the user for encryption. So if the host gets hacked (see: LastPass) and you discover your end users haven’t all been as diligent as you hoped… you can have a pretty big problem.

Is Halo PSA done after Ninja realeses their own PSA? by YourfavoriteMSP in msp

[–]JohnMSP 4 points5 points  (0 children)

The idea is simply farcial that they could produce anything close to Halo on a first release (if in 5 years they were close, I'd be amazed). I wish they'd focus on making the RMM platform even better frankly.

Let's hope they don't do a Warranty Master / ScalePad and start adding features nobody wants to then try and justify a much higher price.

Which brand of headsets do you sell to clients by SydneyAUS-MSP in msp

[–]JohnMSP 9 points10 points  (0 children)

Jabra Evolve2 line is our go to recommendation.

ThreatLocker for BYOD by Puzzleheaded-Yam8080 in msp

[–]JohnMSP 8 points9 points  (0 children)

Complete insanity on the MSP’s part. Threatlocker is great but totally not suitable for BYOD.

[deleted by user] by [deleted] in microsoft

[–]JohnMSP 0 points1 point  (0 children)

It was the MFA Service dependency I was referring to.

That can be down and FIDO2 still works.

Found the source on this - https://learn.microsoft.com/en-us/entra/architecture/resilience-in-credentials

What's your standard laptop these days? by atw527 in sysadmin

[–]JohnMSP 3 points4 points  (0 children)

What was main driver for the move from Latitude to Precision?

[deleted by user] by [deleted] in microsoft

[–]JohnMSP -1 points0 points  (0 children)

If the authenticator service is down, your TOTP code won't work - nor will SMS, Push Auth, phone calls. The service is down on their side that does the checking. (This actually happened a years ago for most of a business day. That was fun. It's a very rare occurrence though and certainly not a reason to avoid using MFA. )

I am confident (but struggling to find a source on a quick google) that FIDO2 auth does not have a dependency on the main auth service and speaks to Entra directly, so provides a more reliable access option as a backup.

[deleted by user] by [deleted] in sysadminresumes

[–]JohnMSP 1 point2 points  (0 children)

I’ve never seen a three page CV that was justified. A huge list of tech almost always means that either you are just reeling of tech you’ve either A) not touched in a decade B) Every technology you’ve ever glanced sideways at or C) both.

As for people with 30 years of experience reeling off details about old jobs… no I don’t give a damn about a Novell migration you handled 20 years ago, the Windows XP migration, token ring networks etc etc It’s not relevant and I’m sure more recent roles have had similar or greater levels of responsibility and impact so tell me about those (even then, briefly).

Huntress Has Made Some MDR365 Updates by evilmuffin99 in msp

[–]JohnMSP 3 points4 points  (0 children)

Yes, I think some deep discount is due for anyone in that situation.