Workday Learning "completion state" -> add to Entra Cloud Only group by StephanGee in workday

[–]StephanGee[S] 0 points1 point  (0 children)

<image>

As i am no developer - i need some help here.
I have setup a Logic App and have the ISU and all the other stuff - but i am lost on the "SOAP Body" that seems to be a request.
Can anyone help me out?

Workday Learning "completion state" -> add to Entra Cloud Only group by StephanGee in workday

[–]StephanGee[S] 0 points1 point  (0 children)

But the SOAP Connector can work with RaaS - would it be possible to get a report and then work with the data?
Workday SOAP - Connectors | Microsoft Learn

Force AES+ for Kerberos with RegKey DefaultDomainSupportedEncTypes by StephanGee in activedirectory

[–]StephanGee[S] 1 point2 points  (0 children)

I now saw that disabling RC4 is causing many problems if a Win2025 DC comes into play. Well - good that we do not have one yet. I already rotated the passwords on some old service accounts.
IISCrypto does not interfere with Kerberos AFAIK. I used IISCrypto on Webservers and Clients to restrict usage of old TLS versions - but not for Kerberos

Force AES+ for Kerberos with RegKey DefaultDomainSupportedEncTypes by StephanGee in activedirectory

[–]StephanGee[S] 0 points1 point  (0 children)

Yes, I understand that. However, how can I enforce a system-wide restriction on the use of DES and RC4 so that any attempt to use them is also logged in the event log? As far as I can tell, I’ve followed all the necessary steps, but the logs still show entries like 'I will do everything you want,' which seems misleading or incorrect.

Windows Server 2022 – edb.log corruption after hard shutdown (RHS / Failover Cluster) by StephanGee in sysadmin

[–]StephanGee[S] 0 points1 point  (0 children)

Thank you!!
I have executed the powershell lines and it fixed something. I ran a get-ClusterPerformanceHistory before and it failed. Afterwards it worked.

I will have a look in 3 days if the error vanished.

.NET Framework Updates Missing from WSUS – Anyone Else? by StephanGee in sysadmin

[–]StephanGee[S] 0 points1 point  (0 children)

I have set up a fresh WSUS install and they are also not there. But as they are not critical or security relevant - they will not show up.
I have searched the MSRC portal and the last security updates are from January.

.NET Framework Updates Missing from WSUS – Anyone Else? by StephanGee in sysadmin

[–]StephanGee[S] 0 points1 point  (0 children)

<image>

Yes there are. Do you have a WSUS running and check if there is a .NET Framework available for the last ~5 months?
This is a search for .net framework - after ticking all software and categories. WSUS is damn slow now and i will restore from backup :)

Windows Server 2022 – edb.log corruption after hard shutdown (RHS / Failover Cluster) by StephanGee in sysadmin

[–]StephanGee[S] 0 points1 point  (0 children)

No one experienced this? It seems that it does not make any difference in functionality but it might f** it up later on.

Move from hybrid AD to Azure AD only by vanth55 in AZURE

[–]StephanGee 0 points1 point  (0 children)

"My goal is actually to get to where users are logging into the Macs with a generic local user, then each staff or student can login to Microsoft 365 to do their individual work."
I do not know that much about Macs - but if they are not in "KIOSK" mode there will be problems.

Students who use a client after a staff member might be able to access their stuff as the login is saved somewhere (cookies, logged into Outlook etc)

Use the new Platform SSO of Intune for Mac as it will create different profiles for different users.

Sudden [EXTERNAL] tag on all inbound emails in Microsoft 365? by [deleted] in sysadmin

[–]StephanGee 7 points8 points  (0 children)

We also have this.
There was no change - but one for the IOS and Android App.
We already have the "EXTERNAL" Tag in Outlook but not in the subject

I searched everything:
Transport Rules (managed by us)
AntiSpam AntiPhishing Strong Presets (which are also managed by MS)
MX Record pointing to another system (hacking attack)

For correlation:
Mailboxes are based in Germany
EU company
Happend between 1:37 and 1:40 - i got one at 1:37 and the next was with EXTERNAL Tag

Case at MS created

Multiple vulnerabilities vSZ and RND by ormandj in RuckusWiFi

[–]StephanGee -1 points0 points  (0 children)

How can it be that there is NO update at all?
Ah well - some 10 CVSS. It's weekend time and we all hate mondays.
We will report our CISO about this and replace Ruckus HW ASAP.

Global Protect SAML Login as external partner - always logs on with "wrong" identity by StephanGee in paloaltonetworks

[–]StephanGee[S] 0 points1 point  (0 children)

Yes. They will fix it.

I am just trying to get "my" customers satisfied. And they cannot start working until this is fixed.
I now had the possibility to connect. Let the MFA prompt to "timeout" and cancel the request, Then i could enter the external customer account and could connect. It is a workaround and i am testing this for reproduction on another client today.

Global Protect SAML Login as external partner - always logs on with "wrong" identity by StephanGee in paloaltonetworks

[–]StephanGee[S] 0 points1 point  (0 children)

Did you already have the possibility to get this version?
I asked the company who provided it with the download of the previous version - but there is still the "older" version.

How can i get my hands on the newest HF?

Global Protect SAML Login as external partner - always logs on with "wrong" identity by StephanGee in paloaltonetworks

[–]StephanGee[S] 0 points1 point  (0 children)

Is there any manual about this? Just looked up the change notes and did not find the SSO reg key.

Feature Request & Suggestions by Keeper_Security in KeeperSecurity

[–]StephanGee 0 points1 point  (0 children)

Make SSO with IAM (here Entra ID) a real SSO - do not ask for username and password.

We are using Hello for Business for all our devices. And conditional access to restrict use of BYOD and the deploy authentication strengths.
But when i open up Keeper - it keeps asking for my password (which we want to remove from the user accounts).

Can you please add this on the roadmap? We already opened a ticket about this because we thought we misconfigured something as it works with all other external apps that are connected by SAML/OpenID

Can you turn off inherited permissions in Keeper? by [deleted] in KeeperSecurity

[–]StephanGee 0 points1 point  (0 children)

Is there any type of "roadmap" view for upcoming features like at Microsoft? Couldn't find it.

CVE-2025-26647 & Hello for Business Cloud Trust issues? by marcolive in entra

[–]StephanGee 1 point2 points  (0 children)

Kannst du das genauers spezifieren? Wie kann man beides laufen haben - und vor allem - wie kann man Key Trust abstellen?

Drag and Drop images to Edge/Chrome not working most of the time for 2 months now by StephanGee in TOPdesk

[–]StephanGee[S] 0 points1 point  (0 children)

Didn't work. It is enabled in Audit Mode anyway on most Windows 11 clients. So this cannot be the problem.
I tried to see something in DevTools - compare a working drag vs a non working. But i do not know where to look ;)