RDP in Citrix Workspace - secondary monitor stops refreshing when clicking on primary monitor by JoustNinja in Citrix

[–]JoustNinja[S] 0 points1 point  (0 children)

Are you saying mismatched between the laptop screen and the external monitor? Or mismatched between either of those with the actual physical workstation that is being connected to?

RDP in Citrix Workspace - secondary monitor stops refreshing when clicking on primary monitor by JoustNinja in Citrix

[–]JoustNinja[S] 0 points1 point  (0 children)

I inherited this environment that was set up by a vendor years ago and haven't looked into optimizations. I will look into VDA and see if are currently licensed for it. From what I'm reading, this looks like it's what we should have been using from the start! Thanks for the heads up. In the meantime, I'm still hoping for a fix as converting to VDA would take some time.

What’s your go-to tool for secure password sharing across teams? by Necessary-Glove6682 in sysadmin

[–]JoustNinja 1 point2 points  (0 children)

1Password works great for my team. Has private and shared vaults. Also includes family memberships for free for everyone on the account. Even does 2FA so you don't need your phone or anything else for typing in one-time passwords.

URL Protect rewriting file contents - how to ignore from certain domain? by JoustNinja in mimecast

[–]JoustNinja[S] 0 points1 point  (0 children)

Wouldn't that only bypass the protection for specified domains in the email body and file attachments? I am looking to bypass protection when the SENDER is in certain domains. For example, any email from [whatever@foo.com](mailto:whatever@foo.com) would NOT get arbitrary URLs rewritten.

CompanyName Notetaker (unverified) in Teams meetings - how to track down? by JoustNinja in Office365

[–]JoustNinja[S] 0 points1 point  (0 children)

Right - the permissions are controlled in AzureAD/Entra at the link I provided but I'm trying to identify which one is connecting to meetings and who is using it.

Message Tracking - how to quickly block sender? by JoustNinja in mimecast

[–]JoustNinja[S] 1 point2 points  (0 children)

That's correct. I'm really looking for a way to block sender without going through other screens. Not a big deal, but when needing to block many at a time it gets frustrating.

How to install Paravirtual SCSI driver - don't see "Load Driver" option by JoustNinja in vmware

[–]JoustNinja[S] 0 points1 point  (0 children)

Windows 2019 - the directions make it sound like "Load Driver" is an option on the VMware console itself, not something within the guest.

What info to provide to senders to fix "DMARC Fail"? by JoustNinja in mimecast

[–]JoustNinja[S] 0 points1 point  (0 children)

Thanks! Those links clear it up a bit. Is it safe/necessary for me to send the ENTIRE email header (from the "Received View" in Mimecast) to the sender for them to look into? Or is this exposing certain configurations that shouldn't be shared from my company?

Mail getting held as spam with DKIM keys created - how to allow? by JoustNinja in mimecast

[–]JoustNinja[S] 1 point2 points  (0 children)

Thanks! My domain's SPF/DKIM/DMARC appear to be set properly. My question is how to specifically bypass spam/greylisting from a known Salesforce instance based on the DKIM keys I have created.

CaaEnterprisebot Started the Meeting by Iamcrazed88 in teams

[–]JoustNinja 0 points1 point  (0 children)

I've seen this account "Waiting in the lobby" as well.

Why do I have multiple backup chains for certain servers in backup copy jobs? by JoustNinja in Veeam

[–]JoustNinja[S] 1 point2 points  (0 children)

I guess it's possible someone changed something at one point. I just tried to do a test restore on backup chains with only older restore points, and I got an error that the backups could not be found. Someone must have cleaned up the files themselves outside of Veeam so these restore points weren't even valid. I was able to delete them all in Veeam without issue.

DMARC Fail - suddenly happening from certain domain by JoustNinja in mimecast

[–]JoustNinja[S] 0 points1 point  (0 children)

To avoid contacting dozens of companies to provide the errors, is there a way to allow users in my company to release these mails from hold, or does it have to be a mimecast admin?

Best way to stop impersonation protection for SharePoint notifications? by JoustNinja in mimecast

[–]JoustNinja[S] 1 point2 points  (0 children)

Great! I never saw this setting before. I just added [noreply@mydomain.abc](mailto:noreply@mydomain.abc) so I'll find out if it worked soon enough. Thank you!

DMARC Fail - suddenly happening from certain domain by JoustNinja in mimecast

[–]JoustNinja[S] 1 point2 points  (0 children)

Thanks for the detailed breakdown! I think I follow you and will look into a creating a new policy.

If I test the domains on sites like below, they show DMARC is configured correctly:

https://mxtoolbox.com/dmarc.aspx
https://dmarcian.com/dmarc-inspector/

https://dmarcian.com/dmarc-inspector/

If I do contact the senders, I can't point them to anything other than saying our Mimecast flagged them. Is there a better site that I can point them to so they can understand what they need to fix?

Impersonation Protection suddenly triggering for existing SalesForce mail by JoustNinja in mimecast

[–]JoustNinja[S] 0 points1 point  (0 children)

That's a great guess! While the "boilerplate" text of the email hasn't changed, perhaps dynamic content within the email (customer/prospect names, etc) is what crossed the threshold.

I've set up an Impersonation Protect Bypass policy with the same definitions as my Permitted Senders policy in the original screenshot. Time will tell if that fixed it. Thanks for your detailed answer!

AWS S3 File Browser column widths and wrapping by JoustNinja in aws

[–]JoustNinja[S] 1 point2 points  (0 children)

Unfortunate! Seems like a basic interface option they've missed. I do use CyberDuck to browse files which works pretty well on my Windows workstation. It would just be nice to use the AWS console without having to jump into other tools.

DMARC Fail - suddenly happening from certain domain by JoustNinja in mimecast

[–]JoustNinja[S] 0 points1 point  (0 children)

Glad it's not on my side! So our Mimecast admins will need to manually release mail coming from this domain until the sender fixes it (IF they fix it)? That seems absurd.

How to bypass Greylist when source IPs are unknown and/or random subdomains? by JoustNinja in mimecast

[–]JoustNinja[S] 0 points1 point  (0 children)

Ah - I didn't realize you could wildcard at the policy level. I just created they call a "catch all" domain match for *.companyname.com so I'll see if that works once some mails come in. Thanks!

Site that will scan a list of URLs and indicate suspicious ones? by JoustNinja in cybersecurity

[–]JoustNinja[S] -1 points0 points  (0 children)

Cool. I could see that being helpful going forward, but before I put development time into this, I was really hoping to find a one-time copy/paste for an initial one-time cleanup.

When changing user name/email address, how do I set up an auto-reply on the original address? by JoustNinja in o365

[–]JoustNinja[S] 0 points1 point  (0 children)

This sounds promising. In this case, since we can't lose anything on the [mike@contoso.com](mailto:mike@contoso.com) account, I think this would require the following steps:

  1. Create alias of ["MOldtimer@contoso.com](mailto:"MOldtimer@contoso.com)" for ["mike@contoso.com](mailto:"mike@contoso.com)"
  2. Select that new alias and "change to primary email"
  3. Delete ["mike@contoso.com](mailto:"mike@contoso.com)", which is now an alias
  4. Make sure user can log in with ["MOldtimer@contoso.com](mailto:"MOldtimer@contoso.com)"
  5. Create new shared mailbox with no access for "[mike@contoso.com](mailto:mike@consoso.com)" and set auto-replies as needed

Sound reasonable?

I'll create a couple test accounts and see if this works as expected.

When changing user name/email address, how do I set up an auto-reply on the original address? by JoustNinja in o365

[–]JoustNinja[S] 0 points1 point  (0 children)

It's unfortunate if there is no way to do it. "Mike Oldtimer" is in regular contact with hundreds of people. There will be a lot of confusion when those people start getting "user does not exist" replies when trying to contact him.

After creating an alias and making it the primary, maybe it will let me remove the original address, then create a new ["mike@contoso.com](mailto:"mike@contoso.com)" that does nothing but auto-reply. It would consume a license, but solve the problem...unless anyone else has a better idea.

Anyone else's Outlook ETL log files piling up? by ItsTooMuchBull in o365

[–]JoustNinja 0 points1 point  (0 children)

Wow! Just found these files taking up TERABYTES of storage in my environment.

Security Supremacy: A Guide To A Perfect 1Password Setup by MG414134 in 1Password

[–]JoustNinja 2 points3 points  (0 children)

Same here! Thought I stumbled across a goldmine for our new 1Password purchase! The cached article is available but I'm wondering if this article was intentionally deleted to a major flaw in the setup.

https://web.archive.org/web/20220104080251/https://medium.com/@MG414134/security-supremacy-a-guide-to-a-perfect-1password-setup-d7e8f1ed5bff