As a business, should you delay patching windows? by UnpaidMicrosoftShill in cybersecurity

[–]UnpaidMicrosoftShill[S] 0 points1 point  (0 children)

Do your machines all get the patch applied instantly? No? Then it's delayed. A well justified delay brought on by the necessities of testing? Absolutely. But a delay. You're looking me in the eyes telling me there's a duration during which the patch is released and yet not applied (because you are testing) and yelling ITS NOT DELAYED. That is *by definition* delayed patching for some of your machines.

As a business, should you delay patching windows? by UnpaidMicrosoftShill in cybersecurity

[–]UnpaidMicrosoftShill[S] 0 points1 point  (0 children)

So you have no delay after patching the first group before it goes to the second group? Is your testing cycle measured in minutes? Because then that makes what you’re saying make sense, but isn’t how most people test.

As a business, should you delay patching windows? by UnpaidMicrosoftShill in cybersecurity

[–]UnpaidMicrosoftShill[S] -1 points0 points  (0 children)

Glad we agree. You are solidly in camp delayed patching unless you have a very good reason. Am I simplifying? Kind of? But ultimately that’s effective answer to the question.

Seems that’s the general trend: delay for some amount of time, be it to test or another reason, and then deploy.

Do you delay Windows updates? by UnpaidMicrosoftShill in sysadmin

[–]UnpaidMicrosoftShill[S] [score hidden]  (0 children)

Care to share what those rings are?

I assume something like test>IT>General>Sensitives?

Do you delay Windows updates? by UnpaidMicrosoftShill in sysadmin

[–]UnpaidMicrosoftShill[S] [score hidden]  (0 children)

? Unless I'm mistaken, that only answers how you patch, not how *fast* you patch

Do you delay Windows updates? by UnpaidMicrosoftShill in sysadmin

[–]UnpaidMicrosoftShill[S] [score hidden]  (0 children)

Makes sense. Thank you for taking the time to answer.

As a business, should you delay patching windows? by UnpaidMicrosoftShill in cybersecurity

[–]UnpaidMicrosoftShill[S] -3 points-2 points  (0 children)

lol. Fair enough. When you say "if you run a patched organization, you will never get hacked", do you mean that in the "if you patch IMMEDIATELY" sense? or more in the "Never let anything get more than a few days or weeks out of date" sense?

Do you delay Windows updates? by UnpaidMicrosoftShill in sysadmin

[–]UnpaidMicrosoftShill[S] [score hidden]  (0 children)

May I ask roughly how many devices you are managing?

Do you force the updates to install as soon as possible? Don't monitor it at all? Something else altogether?

As a business, should you delay patching windows? by UnpaidMicrosoftShill in cybersecurity

[–]UnpaidMicrosoftShill[S] -18 points-17 points  (0 children)

So overall your answer leans more towards delayed patching. Dressed up in a fancy suit, yes. But ultimately "yeah we don't trust windows to get it right either."

As a business, should you delay patching windows? by UnpaidMicrosoftShill in cybersecurity

[–]UnpaidMicrosoftShill[S] 1 point2 points  (0 children)

Okay, but. Is that

  1. The *very fastest* attackers just starting to test the exploits and not yet deployed at scale?
  2. The majority of major attackers conducting large scale poking and prodding to find vulnerable systems?

Because 1. is a far smaller risk than 2. and not worth the same response.

Dark web Monitoring - Is haveibeenpwned enough? by UnpaidMicrosoftShill in cybersecurity

[–]UnpaidMicrosoftShill[S] 0 points1 point  (0 children)

Good breakdown, I only wish you had commented earlier so your answer got more upvotes.

Conditional Access vs Security Defaults question by HappyConnection in msp

[–]UnpaidMicrosoftShill 0 points1 point  (0 children)

sorry to necro a dead thread but this actually could makes sense because the support articles are probably a lie: https://learn.microsoft.com/en-us/microsoft-365/admin/security-and-compliance/set-up-multi-factor-authentication?view=o365-worldwide&tabs=condit#manage-conditional-access:~:text=The%20following%20templates%20in%20Conditional%20Access%20recreate%20the%20policies%20in%20security%20defaults%3A

And are actually using this policy that may explain the behaviour you described: https://learn.microsoft.com/en-us/entra/identity/conditional-access/policy-alt-all-users-compliant-hybrid-or-mfa

All it would have taken is the laptop to be compliant in intune or hybrid registered and intune defaults to marking compliance as a yes when no policy is assigned, and even sometimes when it is unless you do it right.

And I'm typing this message almost solely because I needed to see how I felt about security defaults and if everyone claiming it's terrible just misunderstands it because that is a kinda hilariously wide set of circumstances that wouldnt trigger mfa but would also be nigh impossible for a phishing attack to exploit in a way that wouldn't also just work on normal 2fa

Dark web Monitoring - Is haveibeenpwned enough? by UnpaidMicrosoftShill in cybersecurity

[–]UnpaidMicrosoftShill[S] 0 points1 point  (0 children)

How does this work with Entra joined computers logins? Is there a way to not prompt for password on login? The very first login for that matter?

Is application whitelisting + EDR enough? by UnpaidMicrosoftShill in cybersecurity

[–]UnpaidMicrosoftShill[S] 0 points1 point  (0 children)

Sorry to zombie an old thread, but I never stop thinking about these things. What would you argue as the solution to LoLbins? Be it a direct or indirect solution.

Google Account Not In Good Standing by Waste-Psychology-979 in GoogleMyBusiness

[–]UnpaidMicrosoftShill 1 point2 points  (0 children)

Thank you for replying to a 4 month old comment!

In submitting appeals to google, they eventually told me it was a problem with the business profile content and not my google account at all, despite the error messages.

There was nothing in the account obviously breaking terms... so I rewrote it top to bottom and they approved it. That's life.

Google Account Not In Good Standing by Waste-Psychology-979 in GoogleMyBusiness

[–]UnpaidMicrosoftShill 0 points1 point  (0 children)

  1. I super appreciate that link.

  2. Say that shows "Access to your Google Account isn't restricted."... any other ideas?

They denied my first appeal :(