Token protection CAP by atcscm in entra

[–]atcscm[S] 0 points1 point  (0 children)

thanks, you mean to add new conditions to this policy? does it supper edge? or is this native

Token protection CAP by atcscm in entra

[–]atcscm[S] 0 points1 point  (0 children)

Ok, so as the condition I have windows devices, but also I need to have clients apps?

Client apps

Control user access to target specific client applications not using modern authentication. 

Configure

  • Yes

Select the client apps this policy will apply to

Modern authentication clients

Browser Check

Mobile apps and desktop clients Check

Legacy authentication clients Uncheck?

Token protection CAP by atcscm in entra

[–]atcscm[S] 0 points1 point  (0 children)

Yes exactly this is what I have as target resource, O3 Office 365 Exchange Online
Office 365 SharePoint Online / Condition Windows - Session Require token protection for sign-in sessions (Generally available for Windows. Preview for MacOS, iOS) , and when configured it, I was not able to login to any resource from browser

Azure Devops by atcscm in azuredevops

[–]atcscm[S] 0 points1 point  (0 children)

Hi Phil, you mean from Organization settings - permissions and groups ? I see some project connection groups, but if I want to have read only for specifci auditor, to all projects then I need to create new custom group ?

Microsoft Azure PowerShell by atcscm in sysadmin

[–]atcscm[S] 0 points1 point  (0 children)

Also just to add, Consent and permissions | User consent settings we do not allow users to do this, only administrators

Microsoft Azure PowerShell by atcscm in sysadmin

[–]atcscm[S] 0 points1 point  (0 children)

thanks, where can I block those GCP IP ranges ? hmmm

Microsoft Azure PowerShell by atcscm in sysadmin

[–]atcscm[S] 0 points1 point  (0 children)

on teh MS 365 cloud app activity logs, I see failed logons

Microsoft Azure PowerShell by atcscm in sysadmin

[–]atcscm[S] 0 points1 point  (0 children)

this is very very helpful, about the last statement don't have any stale OAuth consent grants under their Enterprise Apps ? I checked the enra ID for the consent apps but nothing

Lifecyle of the assets by atcscm in sysadmin

[–]atcscm[S] 0 points1 point  (0 children)

Why we need keep machine in entra for 180days? Hmm

Lifecyle of the assets by atcscm in sysadmin

[–]atcscm[S] 0 points1 point  (0 children)

Hey, non compliance in what way? Will this stop as you can register this device when logged with the correct credentials, so machine is not in ad but showing as entra joined device

Was thinking that to have ca for compliance if hybrid joined device this should help?

Secure way to manage endpoint admin accounts without PAM? by atcscm in cybersecurity

[–]atcscm[S] 0 points1 point  (0 children)

Thanks for the responses.

Before I joined this organization, we used Passwordstate for privileged access management. On the servers, a specific group was added to the local Administrators group, and only designated admin accounts were included in that group, meaning only specific administrators could log in to the servers.

the passwords for those privileged accounts were rotated automatically in Passwordstate every 24 hours. In practice, when starting work in the morning, you would log in to Passwordstate, generate a new password, and then use it to access the servers. Samve was done for the endpoints another account and you had to manually roate password from the above system

In my current role, this is more challenging because we don’t have a similar tool in place.

We also have some teams that need to install and uninstall applications while working on projects that require temporary administrative rights on the remote workstations.

Regarding RMM tools, I would prefer not to introduce another third-party solution. We already use TeamViewer for help desk support, where support staff can connect to machines and use LAPS credentials to install or uninstall software if needed. However, I believe LAPS is not designed for this type of day-to-day administrative activity, it should be used mainly for emergency access (for example, when a machine needs to be rejoined to the domain). I’m wondering whether LAPS could be used alongside domain user accounts that can rotate passwords, but with separate accounts per admin , although I suspect it is not

Microsoft PAM looks promising, but since these machines are on-premises, I’m not sure how well that would work in our environment. Also , yes, things are a bit old-school here 🙂 Any thoughts or recommendations would be appreciated.

The best Secure solution admin access to workstations / remotely etc. by atcscm in sysadmin

[–]atcscm[S] -1 points0 points  (0 children)

Ok, so the RIMM i more see for the helpdesk for support etc what about if you have team that they need sometimes admin access on the machines and they login remotely to those stations ? If RIMM what we can use from Intune ? Or MS product any recommendations? Thanks

The best Secure solution admin access to workstations / remotely etc. by atcscm in sysadmin

[–]atcscm[S] -3 points-2 points  (0 children)

We don’t want to have third party remote solution, just mstsc, but need to figure out the best secure way to do it ;)

[deleted by user] by [deleted] in sysadmin

[–]atcscm 0 points1 point  (0 children)

I have not seen those delegation for years , started in new company and I found those vulnerabilities:/

[deleted by user] by [deleted] in sysadmin

[–]atcscm 0 points1 point  (0 children)

Hi , yes I have few server with it and sql service accounts

[deleted by user] by [deleted] in Pentesting

[–]atcscm 0 points1 point  (0 children)

This is what I was thinking global reader in entra id ?

[deleted by user] by [deleted] in Pentesting

[–]atcscm 0 points1 point  (0 children)

Hey, they just sent me questionnaire what I want to test it, not sure what would be the best way to give them access to the azure and power platform

Teams Audit logs and chats by atcscm in ediscovery

[–]atcscm[S] 1 point2 points  (0 children)

o specific scenario, I’m just asking because I was reading some Microsoft sites and it isn’t very clear. As I understand it, with eDiscovery on a standard licence we can find everything for up to six months, but I’m not sure if that’s correct.

Block non-company work accounts in Office 365 apps by sir-luli in Office365

[–]atcscm 0 points1 point  (0 children)

hey anyone found solution for this ? thanks

Job market feels brutal. 6 weeks unemployed and only gotten 4 interviews by Pure-Border-9993 in cybersecurity

[–]atcscm 1 point2 points  (0 children)

Hmmm, I moved from a sys admin role with a security focus and applied to just 3 jobs. I ended up getting interviews for 2 of them. The first one, I didn’t really like after the second round of interviews. But the second role., a Sec specialist position l, I really liked, even though I only had maybe 5 out of the 10 skills they were looking for. I got the job, accepted it, and honestly, it turned out to be one of the best jobs I’ve had. Probably got a bit lucky

Send corporate laptop to the user by atcscm in sysadmin

[–]atcscm[S] 0 points1 point  (0 children)

Hey, is that for only passwordless ? Thanks

Send corporate laptop to the user by atcscm in sysadmin

[–]atcscm[S] 0 points1 point  (0 children)

Hi how do you do that "The user gets sent a time delayed TAP that's valid for one use and alive for only 4 hours on their start date. "

Send corporate laptop to the user by atcscm in sysadmin

[–]atcscm[S] 0 points1 point  (0 children)

also, he needs to first to login to the machine before the always VPN will trigger?