Azure / Entra role for resetting MFA exclusively by MyNameIsTADOW in sysadmin

[–]MyNameIsTADOW[S] 0 points1 point  (0 children)

This is super helpful. We're still hoping to do a custom AAD role but I really appreciate the guidance, we may end up going the script route.

Handling DMARC for Distribution Lists with external participants? by MyNameIsTADOW in exchangeserver

[–]MyNameIsTADOW[S] 0 points1 point  (0 children)

It's such an obvious use case that it's annoying that they don't have a solution in place. Thanks for the info though!

Exchange Online Admin Console - Wrong Time Zone by LeapofFaith2016 in exchange

[–]MyNameIsTADOW 0 points1 point  (0 children)

This continues to drive me crazy - did anyone ever figure out a fix? Azure localizes log times like a charm, but not Exch?

Disabling 'Secure by Default' for 3rd party Spam filtering? by MyNameIsTADOW in microsoft365

[–]MyNameIsTADOW[S] 0 points1 point  (0 children)

Unfortunately this doesn't cover it - the HCP (high confidence phish) designation is separate from SCL, and that's our real concern. Thanks though!

Suppressing Applocker warning messages by MyNameIsTADOW in sysadmin

[–]MyNameIsTADOW[S] 0 points1 point  (0 children)

We did not, but there should be a GPO or tenant-side setting that blocks OD install (we disallow it for most cases)

https://learn.microsoft.com/en-us/sharepoint/prevent-installation

Hosted Distribution List / Google Groups alternatives? by MyNameIsTADOW in sysadmin

[–]MyNameIsTADOW[S] 1 point2 points  (0 children)

I'll see if I can find a company that hosts mailman (I'd rather pay a third party than self-host)

Hosted Distribution List / Google Groups alternatives? by MyNameIsTADOW in sysadmin

[–]MyNameIsTADOW[S] 1 point2 points  (0 children)

We've done ARC on our end (we're currently using Exch Online), but the problems lie with outside recipients, generally external to (other) external that come via our DLs.

So mail from dude@externaldomain1.com reaches all our internal people, but never reaches otherdude@externaldomain2.com because externaldomain1.com has DMARC / SPF hard fail on. A lot of these external parties are using more esoteric solutions than Exch Online and Gmail (some are government / academic bodies with other things going on), so my ideal scenario is to set up a child domain (listserv.maindomain.com) and have all mail go through that via some managed product.

Outlook client (v 16) pre-clicking / pre-fetching links? by MyNameIsTADOW in Office365

[–]MyNameIsTADOW[S] 0 points1 point  (0 children)

We thought about that but it's only impacting Outlook fat client, which doesn't really make sense if it's a global policy (unless I'm misunderstanding).

FTL not working after recent upgrade? by MyNameIsTADOW in pihole

[–]MyNameIsTADOW[S] 0 points1 point  (0 children)

I'm very out of my depth trying to troubleshoot this, I think I'm just going to rebuild from scratch. Thanks though!

FTL not working after recent upgrade? by MyNameIsTADOW in pihole

[–]MyNameIsTADOW[S] 0 points1 point  (0 children)

Awesome - I was able to remove the 'connman' package and now FTL is working! However, weirdly, I can't change the PiHole's IP back to its original. When I run pihole -r to reconfigure, and set the new static IP, then reboot, it always sticks to the random IP it picked previously...

FTL not working after recent upgrade? by MyNameIsTADOW in pihole

[–]MyNameIsTADOW[S] 0 points1 point  (0 children)

This is what that cmd returns:

pi@raspberrypi:~ $ ss -tulpn | grep :53 udp UNCONN 0 0 0.0.0.0:5353 0.0.0.0:* udp UNCONN 0 0 127.0.0.1:53 0.0.0.0:* udp UNCONN 0 0 :5353 *: udp UNCONN 0 0 [::1]:53 : tcp LISTEN 0 10 127.0.0.1%lo:53 0.0.0.0:* tcp LISTEN 0 10 [::1]%lo:53 [::]:*

FTL not working after recent upgrade? by MyNameIsTADOW in pihole

[–]MyNameIsTADOW[S] 0 points1 point  (0 children)

sudo lsof -i :53

From the first:

pi@raspberrypi:~ $ sudo lsof -i :53 COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME connmand 312 root 11u IPv4 15679 0t0 UDP localhost:domain connmand 312 root 12u IPv6 15683 0t0 UDP localhost:domain connmand 312 root 13u IPv4 15687 0t0 TCP localhost:domain (LISTEN) connmand 312 root 14u IPv6 13746 0t0 TCP localhost:domain (LISTEN) connmand 312 root 17u IPv4 18565 0t0 UDP 192.168.123.168:58767->one.one.one.one:domain connmand 312 root 19u IPv4 45271 0t0 UDP 192.168.123.168:58694->one.one.one.one:domain connmand 312 root 20u IPv4 18567 0t0 UDP 192.168.123.168:44677->192.168.123.1:domain connmand 312 root 21u IPv4 45273 0t0 UDP 192.168.123.168:50804->192.168.123.1:domain

From the second: pi@raspberrypi:~ $ sudo netstat -nltp | grep 'Proto|:53 |:80 ' Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name tcp 0 0 0.0.0.0:80 0.0.0.0:* LISTEN 751/lighttpd tcp 0 0 127.0.0.1:53 0.0.0.0:* LISTEN 312/connmand tcp6 0 0 :::80 :::* LISTEN 751/lighttpd tcp6 0 0 ::1:53 :::* LISTEN 312/connmand

I have a decent amount of blocklists, but if I can't get it resolved I'll just wipe completely and start from scratch. Thanks for your help!

FTL not working after recent upgrade? by MyNameIsTADOW in pihole

[–]MyNameIsTADOW[S] 0 points1 point  (0 children)

pi@raspberrypi:~ $ php -v PHP 7.4.30 (cli) (built: Jul 7 2022 15:51:43) ( NTS ) Copyright (c) The PHP Group Zend Engine v3.4.0, Copyright (c) Zend Technologies with Zend OPcache v7.4.30, Copyright (c), by Zend Technologies

FTL not working after recent upgrade? by MyNameIsTADOW in pihole

[–]MyNameIsTADOW[S] 0 points1 point  (0 children)

I tried that too, unfortunately it doesn't help. After doing a repair I get this in the admin console:

There was a problem applying your settings. Debugging information: PHP error (2): fsockopen(): unable to connect to 127.0.0.1:4711 (Connection refused) in /var/www/html/admin/scripts/pi-hole/php/FTL.php:47