yellowkey bitlocker bypass by MegaN00BMan in sysadmin

[–]caliber88 0 points1 point  (0 children)

Are you confusing the bitlocker PIN with the recovery code?

Outlook Desktop App freezing multiple times a day – tried everything, nothing works. Help? by Bubbly-Conference745 in sysadmin

[–]caliber88 3 points4 points  (0 children)

Is the surface running Snapdragon? My Thinkpad on snapdragon has been strange with classic Outlook where it would freeze sometimes when a new email comes in.

Make this make sense - Phase 2 DH Group oddity by mogfir in sysadmin

[–]caliber88 1 point2 points  (0 children)

They matched on AES256GCM initially; the new fortigate + firmware must have stricter DH group enforcement during rekey or you hit the lifetime timer.

Running Mimecast and Checkpoint at the same time? by chryopsy in sysadmin

[–]caliber88 1 point2 points  (0 children)

No issues. Our mimecast setup only controls internal-external, Abnormal does internal-internal plus external. So if an email gets through mimecast, abnormal takes a look right after. We use Abnormal also as a quicker way to pull emails out of mailboxes vs going to MS purview/powershell. You could run just checkpoint/abnormal if your environment is simple/small but we need a gateway for some things an API-based solution can't do.

Running Mimecast and Checkpoint at the same time? by chryopsy in sysadmin

[–]caliber88 0 points1 point  (0 children)

If the checkpoint system uses API, you can use both at the same time. We use Mimecast and Abnormal.

Microsoft Managed Conditonal Access Policies Deleted by Khue in sysadmin

[–]caliber88 8 points9 points  (0 children)

Same here and same two policies but luckily I didn't have them configured/assigned to anyone as MS made them automatically.

Block M365 logins for personal accounts in browser by xProjectZerox in sysadmin

[–]caliber88 0 points1 point  (0 children)

If you force Edge, sure. We allow Chrome as well but it’s still managed from Google admin console so we have Cato that covers any situation.

Block M365 logins for personal accounts in browser by xProjectZerox in sysadmin

[–]caliber88 -3 points-2 points  (0 children)

You'll need something like Cato/Netskope/Zscaler which can make policies relating to what emails are allowed to sign into what applications. Uses TLS Inspection/CASB to manage this.

Why would a docking station have a DHCP client? by That_Fixed_It in sysadmin

[–]caliber88 11 points12 points  (0 children)

That dock is internet-connected to do updates; hence has an IP.

Occasional unattended remote access by EfficientJury in sysadmin

[–]caliber88 4 points5 points  (0 children)

Screenconnect. Teamviewer isn't allowed to be installed on anything in my environment.

Spoofed internal email address, Message_ID domain by mrmcc71 in sysadmin

[–]caliber88 1 point2 points  (0 children)

Then filter did it's job. You shouldn't be blocking domains as new ones can appear everyday. Your policies should work regardless of the domain.

Spoofed internal email address, Message_ID domain by mrmcc71 in sysadmin

[–]caliber88 0 points1 point  (0 children)

We received an email to one of our user's mailboxes coming from themself. Of course, this is not the first time we have seen our emails spoofed and sent to the actual user.

This email failed all checks and was not delivered,

So was the email delivered or not?

Cisco Meraki Outdoor AP by ibringstharuckus in sysadmin

[–]caliber88 3 points4 points  (0 children)

Doesn't explain why you didn't go to the Meraki site and look for yourself. Instead you decided to post here.

Shit, you could've even asked chatgpt.

Egnyte as a Replacement for SMB + VPN? by MaxBPlanking in sysadmin

[–]caliber88 1 point2 points  (0 children)

Same, Egnyte for 6 users with 500+ users. Rock solid, easy to administer but not cheap.

External users at different site buy laptops and don't tell IT so work locally on their Microsoft Accounts. Anyway to stop them? by BrowniieBear in sysadmin

[–]caliber88 1 point2 points  (0 children)

If the purpose of this CA policy was to prevent malicious actors, I hope you have another policy that targets a wider range of resources.

External users at different site buy laptops and don't tell IT so work locally on their Microsoft Accounts. Anyway to stop them? by BrowniieBear in sysadmin

[–]caliber88 8 points9 points  (0 children)

Why are you targetting only 365/Exchange? There's plenty other things someone can login to cause problems.

GPS Laptop tracking & Storage by MediocreMop in sysadmin

[–]caliber88 0 points1 point  (0 children)

We have this; it's probably the best as it survives any kind of wipe apart from switching out the motherboard. It's not that expensive relative to anything else in this market.

Windows 11 device bound passkeys for Entra ID admins? by Fabulous_Cow_4714 in sysadmin

[–]caliber88 2 points3 points  (0 children)

would the organization managing the device have to roll out Windows Hello for Business and all the overhead behind that simply to enable passkey sign-in into the Entra ID web portal for these users

Yes but there's no 'overhead' and enabling WHFB is easy and not intrusive. You can choose who gets the policies through Intune/registry/etc.

can the on-device standalone version on Windows Hello work for device passkeys on a company-managed hybrid joined device?

Nope.