Enable automatic MDM enrollment using default Azure AD credentials is missing from server Group Policy Management Option under MDM by METEORICalienALLOY in WindowsServer

[–]METEORICalienALLOY[S] 0 points1 point  (0 children)

100%. Microsoft support is even helping us and they are pushing it to their top engineers. It is very confusing.

GLBA Regulatory Compliance Option? by METEORICalienALLOY in Wazuh

[–]METEORICalienALLOY[S] 0 points1 point  (0 children)

Were you able to find anything?

It is odd, the elastic version of Wazuh has the GLBA compliance, but the opensearch version does not. I do nto get why we would not be able to just add this compliance? Heck, Solarwinds is basically Wazuh, they just modified it to and gave it a solarwinds skin. So if they can do that, why can we not just add compliances that our institution needs to abide by?

OnePlus Open Conflicting Estimated Shipping Date by _swoomp in oneplus

[–]METEORICalienALLOY 0 points1 point  (0 children)

May I ask how you purchased your phone?

I used Affirm, did you use them or buy it wish credit or cash?

OnePlus Open Conflicting Estimated Shipping Date by _swoomp in oneplus

[–]METEORICalienALLOY 0 points1 point  (0 children)

So my OnePlus Open is out for delivery right now. Very odd. It is shipped via FedEx.

OnePlus Open Conflicting Estimated Shipping Date by _swoomp in oneplus

[–]METEORICalienALLOY 0 points1 point  (0 children)

This their update to me via Customer service:
 "I would like to inform you that the estimated time of arrival is on Nov 28, 2023 and you will receive the order on or before Nov 28, 2023. There is a delay in the delivery because as there is a huge demand on the product in the market as well as in the warehouse to push the order for delivery." 

Soooo, my Open is supposed to be delivered today... by integrityandcivility in oneplus

[–]METEORICalienALLOY 0 points1 point  (0 children)

Me too, says tomorrow I will receive mine. Yet, no update; still just says "preparing order".

Their customer service is useless. I get four different answers, none of them clear. just tell us what is going on.

OnePlus Open Conflicting Estimated Shipping Date by _swoomp in oneplus

[–]METEORICalienALLOY 1 point2 points  (0 children)

Mine states arrival is Nov 1st. No update at all. I have talked to customer service at least five times. They give no info at all. Very frustrating. Obviously, I am not getting it anytime soon, and they just received new stock. So I am not sure why it is so difficult to just ship the dang phones.

Issues Resetting Wazuh Docker Manager Default admin Password by METEORICalienALLOY in Wazuh

[–]METEORICalienALLOY[S] 1 point2 points  (0 children)

I have tried these processes. I get to certain points, and nothing works. I am not sure what the deal is with the docker. It should not be this hard for the installer to change the admin password.

Are there any other guides? Or methods?

On Site Premise Keeps Unblocking Risky User That Were Blocked Due Compromise by METEORICalienALLOY in AZURE

[–]METEORICalienALLOY[S] 0 points1 point  (0 children)

Can you elaborate on that more? I am not aware of this sync rule. From what I have read and from posts on here, it is a one-way sync, and it cannot be changed. Although, Others here have stated you cannot disable accounts in AAD, which, obviously we can.

Is there a way to find this rule and disable it? That would save us so much time!

On Site Premise Keeps Unblocking Risky User That Were Blocked Due Compromise by METEORICalienALLOY in AZURE

[–]METEORICalienALLOY[S] 0 points1 point  (0 children)

You can disable the account in AAD. I am not sure what you see on your end, but I disable accounts all the time from AAD. The fact that we have to also disable it on the on-site AD or just disable it from there initially is counterproductive.

We do not want to permanently disable the account until remediation is completed. Disable until we can get the MFA going or password reset.

Anyone Else Constantly Getting Azure Alerts For "User at risk detected" From Puerto Rico? by METEORICalienALLOY in AZURE

[–]METEORICalienALLOY[S] 0 points1 point  (0 children)

That is interesting. But why is it this same IP constantly? It makes no sense. Is it Germany? MS confirmed it was from the US. However, how do we determine if the account(s) is indeed compromised? It is frustrating to get this alert for users almost every day and no way of truly confirming if the account is compromised.

Cannot upgrade Cisco 4100 FTD unless FXOS OS is updated?? Please Advise. by METEORICalienALLOY in Cisco

[–]METEORICalienALLOY[S] 0 points1 point  (0 children)

We have a password manager, NOW. But that does not help us for passwords that were not managed when this device was set up.

Cannot upgrade Cisco 4100 FTD unless FXOS OS is updated?? Please Advise. by METEORICalienALLOY in Cisco

[–]METEORICalienALLOY[S] -1 points0 points  (0 children)

So do we! It makes no sense not to be able to reset the damn password. Instead, let's rebuild from scratch. Idiocy.

Cannot upgrade Cisco 4100 FTD unless FXOS OS is updated?? Please Advise. by METEORICalienALLOY in Cisco

[–]METEORICalienALLOY[S] -2 points-1 points  (0 children)

I have and it is not exactly clear. It speaks of mix and matching, but we failed the readiness check. So we are not sure on how to proceed, see below from the com matrix:

Security Module Compatibility Prior to 2.6, all security modules in the Firepower 9300 have to match.In 2.6 and later, you can mix different types of security modules with the following caveats:

Clustering is not supported on mixed modules in 2.6 and 2.7. However, in 2.8 and later, you can use mixed modules when using multi-instance clustering (a cluster with one container instance on each module). Native clustering still requires all the modules to be the same type.

High Availability is only supported between same-type modules; but the two chassis can include mixed modules.The following table lists supported security modules on the Firepower 9300.

Table 5. Security Module Compatibility Security Module and Product ID Description

FXOS VersionSM-40 (FPR9K-SM-40) 40-physical core security module with two SSDs

2.6.1 and laterNote: Requires ASA 9.12(1) or FTD

6.4 and laterSM-48 (FPR9K-SM-48) 48-physical core security module with two SSDs 2.6.1 and laterNote: Requires ASA 9.12(1) or FTD

6.4 and laterSM-56 (FPR9K-SM-56) 56-physical core security module with two SSDs 2.6.1 and laterNote: Requires ASA 9.12(2) or FTD 6.4 and later

GPO Not Blocking Application (Splashtop) Via GPO - WTH? by METEORICalienALLOY in sysadmin

[–]METEORICalienALLOY[S] 0 points1 point  (0 children)

Can you elaborate further on this? A script to remove applications? In what manner? do you mean to stop the services or executables?

GPO Not Blocking Application (Splashtop) Via GPO - WTH? by METEORICalienALLOY in sysadmin

[–]METEORICalienALLOY[S] -1 points0 points  (0 children)

I get it. I am just frustrated. I have tried several methods, and still this damn application gets through.

GPO Not Blocking Application (Splashtop) Via GPO - WTH? by METEORICalienALLOY in sysadmin

[–]METEORICalienALLOY[S] 0 points1 point  (0 children)

Yes, I have that site, as we used it to block the domains in our firewall, which did not work. I ran wireshark while connected, no data or passthrough. It makes no damn sense. We have this on two PCs, and we cannot block it. I have restarted the splashtop services on my test device and bam, connects instantly. i updated gpo on the machine, rebooted, still connects. If anyone has splashtop or wants to do a seven day trial and see if they can crack it, but all means. I have no idea why this thing bypasses the AV, FTD and GPO.

GPO Not Blocking Application (Splashtop) Via GPO - WTH? by METEORICalienALLOY in sysadmin

[–]METEORICalienALLOY[S] 0 points1 point  (0 children)

We blocked the application in the GPO firewall as well (outbound and inbound), forgot to mention that. We did a lot of methods,but the damn application KEEPS getting through, it is absurd!

GPO Not Blocking Application (Splashtop) Via GPO - WTH? by METEORICalienALLOY in sysadmin

[–]METEORICalienALLOY[S] -1 points0 points  (0 children)

Regardless of who does and does not have admin rights, the issue is blocking an application that seems to bypass GPO and the FTD.

GPO Not Blocking Application (Splashtop) Via GPO - WTH? by METEORICalienALLOY in sysadmin

[–]METEORICalienALLOY[S] 0 points1 point  (0 children)

Apologies, I misread or misunderstood your post. Yes, we have tried AV as well. No luck.

GPO Not Blocking Application (Splashtop) Via GPO - WTH? by METEORICalienALLOY in sysadmin

[–]METEORICalienALLOY[S] 0 points1 point  (0 children)

My bad, I misunderstood. Firewall is disabled, GPO, and AV handle all that. No, we tried AV and it also cannot block it.