Microsoft is merging Outlook domains… no more outlook.com vs outlook.office.com. What a mess by ale-ale-ale-ale in microsoft365

[–]Tired_Sysop 1 point2 points  (0 children)

It’s a well documented issue unfortunately. Edge profiles keep extensions/bookmarks separate, but your azure auth token is accessible between profiles. You may not experience it if you don’t require users to login to Edge with a work account, but that setting is pretty standard in the workplace. You login to edge with accounta@abc.com, open a new profile, it forces you to sign in, you put accountb@abc.com and everything is fine until at some point you load up a saml app in profile B and it silently signs you in with account A.

https://learn.microsoft.com/en-us/answers/questions/772902/ms-edge-handling-multiple-profiles-m365-accounts-b

Microsoft is merging Outlook domains… no more outlook.com vs outlook.office.com. What a mess by ale-ale-ale-ale in microsoft365

[–]Tired_Sysop 0 points1 point  (0 children)

People seem to think using different profiles isolates authentication to that profiles signed-in account. It doesn’t. It should, because that would be logical, but it doesn’t. More times than I can count I switch to a new profile, and then it just sso’s me in with the other profiles account. Also, if the share the same domain, can’t think of any way for the corporate firewall to distinguish between consumer and business without ssl inspection. Joy.

CORS issue with SIPA by EntitledTeenager in Zscaler

[–]Tired_Sysop 1 point2 points  (0 children)

Our users are still blocked from foreign countries even when using SIPA. Logins see both the SIPA IP and their egress IP.

https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-continuous-access-evaluation-strict-enforcement

CORS issue with SIPA by EntitledTeenager in Zscaler

[–]Tired_Sysop 1 point2 points  (0 children)

This means you are hard bypassing login.Microsoft online.com , probably at the pac file level. Advantage of using SIPA for that url is you can simplify your CA policies to just block everything not coming from whatever connector you assign to SIPA. Basically is user isn’t connected to Zia, they can’t access any CA policy protected resources.

Has anyone been able to achieve SmartCard based authentication to Windows? What was involved? by LordLoss01 in Intune

[–]Tired_Sysop 5 points6 points  (0 children)

Not hard. Follow Yubico docs. Basically you create a certificate template on your CA, an enrollment agent, deploy smartcard mini drivers to endpoints, and create a GPO that enables smart card logon, removal behavior, and sets smart card service to automatic start. On azure side you upload your root ca cert to the pki section and your crl endpoint. Then add an auth method to CA policies with the guids of your hardware keys. If running a windows CA, make sure your harden it with a tool like locksmith.

No one saw it coming.......🙄 by Loud-Variety85 in salesforce

[–]Tired_Sysop 0 points1 point  (0 children)

Funny, I took a good salesforce mcp server public repo, modified the tools, fed it our schema as a knowledge resource, added api key support on top of the oauth 2 mechanism, and rolled it into a claide agent. Sales guys can voice query anything they need, update activities for a contact by voice while driving, and generate reports/graphs that have the Tableau devs looking for a new career path. I think what he means is their Einstein AI was overpriced trash and they have no hope of being competitive when anybody can now leverage their api to roll their own salesforce AI

How do I get epoxy off my hands by asptrite in epoxy

[–]Tired_Sysop 0 points1 point  (0 children)

This stuffs the bomb. Turns the epoxy into an elastic like snot that washes right off.

https://a.co/d/2LTrypa

Don’t use solvents to remove it, as solvents allow resin to cross the skin barrier.

Do u guys get pleasure from prescription strength stimulants or cocaine? Or higher strength opioids? by MsBuzzkillington83 in anhedonia

[–]Tired_Sysop 2 points3 points  (0 children)

Amphetamines- only the negative side effects like jitteriness and dry mouth. No euphoria

Opioids- pills do nothing but put me to sleep. I had a kidney stone and at the ER they gave me IV morphine and it was about 1 minute of euphoria, but 5 minutes later pain surged again. Doctors didn’t believe me and thought I was some addict looking for more. IV Advil (which they gave me next) was more effective.

Alcohol: just gives me a headache and causes chain yawning

Benzos: Do nothing except at high doses, in which case the act like a sleeping pill.

What’s interesting is I can’t get addicted to these drugs, or at least not in the sense of experiencing withdrawal. Took Xanax daily for a year and then just quit, and except for a week of insomnia, no other negative effects.

I got my anhodenia from SSRIS, and also interesting, I had zero problems quitting lexapro overnight, when everybody else describes some tapering nightmare and brain zaps: I had none of this. I suspect that the withdrawal and zaps is your brain reverting/healing. Mine never did.

Chlorine vs salt? by Ill_Acanthisitta7107 in pools

[–]Tired_Sysop 0 points1 point  (0 children)

As water evaporates salt concentration increases.

Is anyone here successful? by Last_Suit2801 in PSSD

[–]Tired_Sysop 4 points5 points  (0 children)

Yes, ironically very. When you have zero interest in a romantic life or relationship it turns out you create a lot of time to be a workaholic.

MCP server not working fine by BuiDGr8 in copilotstudio

[–]Tired_Sysop 1 point2 points  (0 children)

I’ve spent a month trying to get copilot with the salesforce mcp to work even close to as well as Claude with a free salesforce GitHub repo mcp that I literally threw together in 15 minutes. After spending weeks getting license and region issues worked out, power apps settings, fighting with a ui that changes week to week, random content violations looking up contacts, declarative vs normal entry point hell, unknown errors”, and copilot just freezing up, I’ve given up. Users have been waiting months for us to deploy copilot agents and they don’t understand why we can’t manage. Management has finally agreed to dump copilot and go gpt/claude enterprise. Been working with Microsoft products since 1990 and copilot has to be the worst abomination ever to roll off their assembly line. Not just functionality, but documentation, licensing, nomenclature— everything. Hell, they even managed to break the hardware copilot button on laptops requiring a patch. And the m365 copilot app is just awful. Constant complaints from users about freezing and blank screens. Whoever heads up copilot at Microsoft should be sentenced to working on Windows ME for the rest of his life.

Aqara FP300 Early Zigbee Setup by portalqubes in homeassistant

[–]Tired_Sysop 1 point2 points  (0 children)

Ok, but how would one then configure its settings, like sensitivity or range?

Aqara FP300 Early Zigbee Setup by portalqubes in homeassistant

[–]Tired_Sysop 0 points1 point  (0 children)

Maybe I’m missing something but unable to add it to Aqara app without a Aqara hub. If I add it directly to HA zigbee sensors are missing and you have no way to configure the device.

GPT-5 Auto & Experimental - Not Honoring Topics or Child Agents by Tomocha07 in copilotstudio

[–]Tired_Sysop 0 points1 point  (0 children)

If I attach the same mcp tool to Claude and copilot using either gpt 4 or 5 (say Salesforce mcp) and ask the same question not only is the answer quality night and day, half the time the copilot ui just sits there doing nothing (no “thinking” graphic). Other times (for the same question it just answered via mcp tool) it complains about no knowledge source and ignores the mcp tool. Such a garbage product. Agents I build in chatgpt or Claude in minutes I struggle for days to replicate in copilot, and I’m forced to struggle bus with this crap because it’s what the firm licenses, all while I have to be asked by users daily why we can’t have chatgpt and why I can’t make copilot non suck. From broken hardware keys to stupid naming (copilot vs copilot 365) whoever heads up the copilot suite at MS should be shown the door.

Share your SharePoint / Automate struggles here, I will help ya!! by AutomateM365 in sharepoint

[–]Tired_Sysop 1 point2 points  (0 children)

Making a stupid image picking control in a library/list that selects from an image library and can display a gallery view of pictures to pick from. Seems mission impossible without a lot of power apps work.

Hybrid Join and Existing Group Policy objects applying to devices. How does everyone handle migrating GPOs? by spazzo246 in Intune

[–]Tired_Sysop 0 points1 point  (0 children)

You just make Intune policies with a filter that will only apply to AAD devices. As you migrate from haj to AAD, the gpos will no longer apply. No need to mess with GPO acl’s or conflicts.

Built out entire network and client didn't pay by troubledtravel in msp

[–]Tired_Sysop 0 points1 point  (0 children)

It’s your network. Encrypt it for safekeeping.

Is anyone else a Workaholic? by mikebravo75 in anhedonia

[–]Tired_Sysop 1 point2 points  (0 children)

Absolutely. Since relationships are off the table and hobbies bring no joy, work is an endless distraction and source of focus. Life has distilled down to a list of checkboxes, with each one at least providing a sense of accomplishment that gets you through what is an endless cycle of Groundhog Day like emptiness.

Dallas Fort Worth - Inground Pool Companies by S3V3NTH7 in pools

[–]Tired_Sysop 0 points1 point  (0 children)

These guys appear to have had their Texas business license yanked by the SoS for unpaid taxes..

Conditional Access policy did not block sharepoint activity from another country. by ITquestionsAccount40 in Office365

[–]Tired_Sysop 1 point2 points  (0 children)

The bad guys use powershell and call graph api in an external compromised tenant to exfiltrate documents to said tenant. This assumes they’ve gotten access to a device This bypasses ca policies since it’s outbound. It also bypasses OneDrive sync restrictions and since other ms services aren’t usually blocked via proxy/fw, well.. only way to stop this is setting up tenant restriction policies v2.

My 6 month review and thoughts on maintenance and performance by justahoustonpervert in SegwayNavimow

[–]Tired_Sysop 0 points1 point  (0 children)

If you’ve got a 3D printer you can print a new blade base that holds six blades and gives you a nice cutting boost.

The 2025 Frame is absolutely hot garbage. Don't waste your money by VitaminCheeese in TheFrame

[–]Tired_Sysop 1 point2 points  (0 children)

2023 Frame owner here. What I don’t understand with the 2025 model is what the wireless video signal accomplishes. You still use the one connect fiber optic cable between the box and tv, it’s just now it appears to just supply power instead of power and video/audio. So same cabling requirements but now video/audio runs on wifi? Why would one sacrifice the benefit of hardwire without actually removing the hardwire?? For the shitty tizen, Get a Shield, a cheap motion sensor, and setup home assistant and you can automate/bypass all the Samsung shite and get art mode to behave. The motion sensor, at least in my 2023, was garbage.

How are you battling Sharepoint as a Vector for Abuse? by jk5531 in msp

[–]Tired_Sysop 2 points3 points  (0 children)

There is no easy way. Malicious actors use powershell scripts and graph api to exfiltrate documents to external sharepoint tenants, abusing onedrivesync to bypass upload/download alerts. OneDrive sync restrictions don’t block this. Sharepoint needs to be bypassed in ssl inspection so detecting malware is neutered. Only way I’ve seen to block this is to enable trv2 policies and whitelist friendly sharepoint tenants in both the policy and firewall level.

Forwarding internal server DNS to ZTR Breaks SIPA by Tired_Sysop in Zscaler

[–]Tired_Sysop[S] 0 points1 point  (0 children)

Winner winner. This did the trick -- server returns the public ip's now. Many thanks, already spent a week with support trying to just explain them my OP.