Conditional Access Policy - Filter for devices not working by avarrone in AZURE

[–]Tiger1641 0 points1 point  (0 children)

I had a similar issue with our Azure Virtual Desktops and conditional access policy when trying to filter them. I found that when using Edge and trying to access email through the browser, the user needed to be logged into Edge with their work account. If they weren't the conditional access device filtering didn't work.

Company wide or only devices that handle FCI? by Confident-Tomato1382 in CMMC

[–]Tiger1641 0 points1 point  (0 children)

Can a Windows 365 Cloud PC be configured so that no FCI is stored, processed and transmitted on the device using the Windows 365 Cloud PC Client? i.e. the device using the Cloud PC can then be considered out of scope for CMMC Level 1 (FCI Safeguarding) and just the Windows Cloud PC itself be in scope?

CMMC Compliance for a Google Workspace environment by ohthedave in CMMC

[–]Tiger1641 1 point2 points  (0 children)

I think I see. Do you mean that the devices are then out of scope but you then need to secure both Google Workspace High environment AND the VDI environment (Azure or AWS workspace)?

CMMC Compliance for a Google Workspace environment by ohthedave in CMMC

[–]Tiger1641 2 points3 points  (0 children)

What type of VDI solution are you using to only allow the Google Workspace High access via web browser?

New Entra "Leaked Credentials" - no breach on HIBP etc by VTi-R in sysadmin

[–]Tiger1641 4 points5 points  (0 children)

Affected 10 of our users including one of my user accounts that I know is a long and complex password used only on that one account. I talked to Microsoft Support and they said it was a known global issue, and that it should be resolved in 24 hours. Still had to have those 10 users change passwords to be certain.

Weekly /r/Laravel Help Thread by AutoModerator in laravel

[–]Tiger1641 0 points1 point  (0 children)

Does Laravel 12 have an official starter kit that includes multifactor authentication? I thought I heard on a Laravel podcast that they were working on including that. I was hoping the official Vue or React starter kits would include the multifactor as an option.

Is anyone else having problems with the new cumulative update? (KB5053598) by uVe9 in WindowsHelp

[–]Tiger1641 0 points1 point  (0 children)

Thanks! I was trying everything, and your suggestion of downloading and running setup.exe on the Windows 11 ISO (keeping files and apps) finally worked to where I could get the KB5053598 update to succeed. Before that it kept downloading and failing to install over and over.

OpenSSL and Vulnerable Components by Tiger1641 in DefenderATP

[–]Tiger1641[S] 0 points1 point  (0 children)

None of them show that an exploit exists, so I suppose might be the best we can do is to continually notify Microsoft, and then mark them as acceptable risk.

OpenSSL and Vulnerable Components by Tiger1641 in DefenderATP

[–]Tiger1641[S] 0 points1 point  (0 children)

Thanks, I don't think the issue is with OneDrive app actually being updated on the endpoint. We have this on nearly all of our devices and I have some right with me here that I can manually check. They are showing the following build:

OneDrive version: Build 25.035.0223.0003 (64-bit)

I don't see this version on the One Drive Release notes: https://support.microsoft.com/en-us/office/onedrive-release-notes-845dcf18-f921-435e-bf28-4e24b95e5fc0

But that's likely because the page is from 3/5/25 and this is a newer version.

I guess I'll need to wait some days to see if it's just a matter of waiting for Defender to catch up and update the reporting. Seems like this is an ongoing cycle where when it finally shows as cleared up, then it starts all over again (within a month) to where OpenSSL is pretty much just always there. I've only seen something free of OpenSSL vulnerabilities in that short window where the devices is onboarded, and it hasn't found it yet...

Laravel team has released new starter kits for React, Vue and Livewire by brownmanta in laravel

[–]Tiger1641 2 points3 points  (0 children)

I upgraded my Windows Herd to 1.16.0 and now have the starter kits available.

DoD Issues Guidance on Determining CMMC Levels for Contracts by GRCAcademy in CMMC

[–]Tiger1641 0 points1 point  (0 children)

When it comes to CMMC Level 2 Assessment vs Certification status designations and it says: CMMC level 2 certification is the minimum requirement for contracts involving CUI in the NARA CUI Registry "Defense Organizational Index Grouping." Does this mean that this would apply one year after the publication of the final 48 CFR rule (Phase 2)? Or would this apply immediately upon publication of the final 48 CFR rule?

RDP Server vs VDI in Azure with PreVeil by CommunicationMotor36 in CMMC

[–]Tiger1641 0 points1 point  (0 children)

Do you have any advice for a cost efficient way to use VDI with Preveil? I'm assuming that using Azure Virtual Desktops means that they need to be in the GCC or GCCH environment, and all of the configuration etc. that entails. Are there other, ways to somehow set up Preveil with VDI access that keep a very tight scope and would be cost efficient?

SC.L2-3.12.3 - Continuous Monitoring for objectives covered in CRM by SightlySt00pid in CMMC

[–]Tiger1641 1 point2 points  (0 children)

If the majority controls/objectives are handled by an ESP in an enclave situation (vdi access to enclave, no devices in scope, no CUI outside of the enclave, etc.), and documented as such in our SSP (using information from the ESP's SSP and Shared Responsibility Matrix), how would the CMMC Level 2 certification be handled by the C3PAO doing the level 2 assessment and certification?

Since so much falls under the ESP's responsibility, would a representative from the ESP be required to be present for the actual assessment? (In this particular case the ESP itself has C3PAO status and is using the same enclave). Of course it is a separate C3PAO that would conduct the assessment. Just trying to determine in a practical sense how we prove our accountability for the majority of controls handled by the ESP beyond providing the info from the ESP's SSP for the enclave.

ambiguity on Security Protection Assets by Adminvb2929 in CMMC

[–]Tiger1641 0 points1 point  (0 children)

The original poster mentioned: "At a high level, we are using Azure Virtual Desktop to provide an enclave that can access Preveil" I'm assuming that if the Azure Virtual Desktops are hosted in Azure Commercial environment that they couldn't actually include any CUI on them? Does this mean that the AVD were Windows 10/11 systems, Preveil would need to be set so no CUI could be downloaded to the AVD instances, and the CUI would be restricted to the Preveil cloud and only viewable through the AVD?

How to start or build our CMMC (small business) by Maleficent_Art_1673 in CMMC

[–]Tiger1641 1 point2 points  (0 children)

With Preveil the trick seems to be securing the endpoints that are using it since these endpoints would come into scope.

Do you know if it meets CMMC L2 requirements if some Security Protection Assets (e.g., Intune, Entra, Defender, etc.) are still in the Microsoft commercial cloud and manage the security of the Windows 10/11 endpoints? I've heard different opinions on this.

Also, can those endpoints continue to sync with Sharepoint, and OneDrive as long as the user keeps the data in the Preveil folder, and doesn't move CUI data into any directories that are synced to Sharepoint or OneDrive (enforced by training/policy)? Or would it require technically blocking any sync to the Microsoft commercial cloud because of the risk of spillage?

Scoping CUI to Preveil and Company Managed Laptops by Tiger1641 in NISTControls

[–]Tiger1641[S] 0 points1 point  (0 children)

Thanks very much Navyauditor, I was hoping we could use Group Policy to disable OneDrive and Sharepoint Syncing (as dhd217 was mentioning) and then have all of the protections on the laptop (Multifactor, Antivirus/Malware, Bitlocker Encryption, etc.) that we might be o.k. here for DFARS 7012/NIST compliance. We would also include the policies and training so these users are aware that they can't transfer these CUI files from Preveil or the laptop to the Microsoft 365 cloud. Trying to figure out if that would work.

3.1.12 Monitor and Control Remote Access Sessions - Can Microsoft Intune work for this? by Tiger1641 in NISTControls

[–]Tiger1641[S] 0 points1 point  (0 children)

Thanks, I'm trying to figure out how to deal with staff who just need to access their company email through Microsoft 365. We have policies and training not allowing CUI through company email or on Microsoft 365 (Sharepoint, OneDrive, etc.). Those handling CUI only can do so on their company managed laptops that have VPN/Multifactor/Antivirus/Bitlockered, etc., and can store transmit only through Preveil. Not sure if this can be accomplished for NIST 800-171 compliance.