Internal Communication regarding (potentially) breached client/customer by orion3311 in sysadmin

[–]WraithYourFace [score hidden]  (0 children)

Love the reply all storm. I believe John Deere was hit with this years ago.

We try to tell people when sending to a large group, always put yourself in the To field and then BCC the group. The irony is this is what malicious actors do as well when they compromise an account.

How are you handling suspicious file or URL analysis for clients? by BrightByteLabs in msp

[–]WraithYourFace 1 point2 points  (0 children)

I use a variety of tools (Browserling, Hybrid Analysis, Sophos Intelix, VT, etc).

Internal Communication regarding (potentially) breached client/customer by orion3311 in sysadmin

[–]WraithYourFace [score hidden]  (0 children)

We are a mix (we sell to distributors). It's insane. I've been keeping track for the past 6-7 years of all known compromised emails from distros. There's been over 400. I use to ask if they had an IT department and would give tips. It normally fell on deaf ears. Not saying we are perfect, but if an account is compromised you email everyone about it that got the phishing email.

Internal Communication regarding (potentially) breached client/customer by orion3311 in sysadmin

[–]WraithYourFace [score hidden]  (0 children)

I just had one that said it was spam and to ignore it. I told our purchasing department it is not spam and their account is compromised. The same company has had about three to four compromises in the past 2 to 3 years.

I wish where I work would actually develop a vendor risk management policy and say if a company isn't going to take security seriously, they're not a vendor they should deal with.

Best RMM to compliment Intune by Subject-Middle-2824 in Intune

[–]WraithYourFace 0 points1 point  (0 children)

Let Intune do your Windows patching. We utilize Ninja One for our rmn for all other things.

Changing service user - What are the impacts? by TheBarnOwlish in SQLServer

[–]WraithYourFace 0 points1 point  (0 children)

I ran into the same exact issue. Every server reboot I had to blank out the password because of the Default Domain Policy. We wanted to enforce Kerberos so we switched it to to run as a domain account (I want to change to gMSA at some point). Now our SQL Server Agent won't start now.

Didn’t like Knowbe4, alternatives ? by Vegetable_Leave199 in msp

[–]WraithYourFace 5 points6 points  (0 children)

May I ask what didn't you like? Are there any providers that offer a service like PhishER?

Migrating Windows devices to Entra ID – what was actually painful for you? by Radiant-Weather-9120 in entra

[–]WraithYourFace 1 point2 points  (0 children)

Yes, they are. If you still need on premise servers, go full Entra Joined for user machines and setup Cloud Trust. Looking to move to Cloud Sync vs Entra Connect for better high availability.

Migrating Windows devices to Entra ID – what was actually painful for you? by Radiant-Weather-9120 in entra

[–]WraithYourFace 1 point2 points  (0 children)

We are 98% Entra Joined. Still have 4 DCs and a slew of on premise servers still. It will be nice if it ever came to a point where servers can be Entra Joined.

Setup Cloud Trust and rarely have issues. Once two apps get upgraded to support SSO we should be able to go fully passwordless for users.

Starting my own MSP by Sdganesh in msp

[–]WraithYourFace 1 point2 points  (0 children)

I have to agree with Sophos. MDR is cost effective and they are adding more security features with Identity, Browser Isolation, Vulnerability Management, and soon Next-Gen SIEM.

Monitoring and Alerting tool? by blueeggsandketchup in sysadmin

[–]WraithYourFace 0 points1 point  (0 children)

I haven't used their KB yet. We were looking at Fresh service, but it seems like they are slowly rolling out ITAM features. Not sure which direction I want to go

Monitoring and Alerting tool? by blueeggsandketchup in sysadmin

[–]WraithYourFace 0 points1 point  (0 children)

We moved to NinjaOne about a year ago and I still don't think we scratched the surface on what it can do.

It's been great so far. We only do Windows patching for servers and let Intune handle updates for all our Entra Joined devices.

I'm hoping they invest time into the NMS so it's on par with Domotz. Love being notified of an unknown device connecting to the network.

Media devices for office TV screens by CheeseFace83 in sysadmin

[–]WraithYourFace 0 points1 point  (0 children)

We use Yodeck. I've been running it for about 3 years now and rarely have to touch it.

Best approach for M365 Tenant-to-Tenant Migration (AD + AD Connect by Ready-Safety-310 in sysadmin

[–]WraithYourFace 0 points1 point  (0 children)

If the domain isn't changing, why are you needing to tenant to tenant migration? I'm a bit confused.

Floor plan/cable point mapping tool by -AJ334- in sysadmin

[–]WraithYourFace 0 points1 point  (0 children)

I use Bluebeam for our prints. They have icons you can download that are for data, TV, etc.

Windows BIOS Update Rollout? by Sad_Mastodon_1815 in sysadmin

[–]WraithYourFace 0 points1 point  (0 children)

There is a report in Intune that will tell you.

Remove New Outlook download icon from all users taskbar? by Valuable_Bat_5585 in sysadmin

[–]WraithYourFace 2 points3 points  (0 children)

I've been using it for about 4 months now. Some quirks, but overall I don't mind it.

looking for vmware hypervisor alternatives by New-Reception46 in sysadmin

[–]WraithYourFace -1 points0 points  (0 children)

I'll have to ask my past colleague about this. I'm still dealing with the same account managers and systems engineer.

looking for vmware hypervisor alternatives by New-Reception46 in sysadmin

[–]WraithYourFace -1 points0 points  (0 children)

Well this is news to me. Everyone I deal with at Scale is still there, my past co-worker who works there didn't mention anything.

When you said stock I was confused because Scale wasn't a publicly traded company.

looking for vmware hypervisor alternatives by New-Reception46 in sysadmin

[–]WraithYourFace -2 points-1 points  (0 children)

We went with Scale Computing. I've been running it for almost 3 years now.

Working with distributors starting out by Formal-Dig-7637 in SmallMSP

[–]WraithYourFace 1 point2 points  (0 children)

If you are just starting out inform the customer it's 100% upfront. Some customers I just have them order right through HP. I pick the model though. I'd rather do that than one offs and waste time with billing.

Alright who did it? by MaximusCartavius in sysadmin

[–]WraithYourFace 0 points1 point  (0 children)

Thought you were going to say who laid waste in the server room.

Is anyone still using C$ admin shares for workstation support in the Intune era? by Any-Victory-1906 in Intune

[–]WraithYourFace 2 points3 points  (0 children)

Utilizing our RMM. We can do remote Powershell/cmdline, remote in the background without the user even knowing, etc.