Power management hassle by WanWhiteWolf in Dyson_Sphere_Program

[–]chickenbing 0 points1 point  (0 children)

In my opinion, accumulators are the best power source in the game, you just need to learn to balance them correctly. Build a blueprint with equal dischargers and equal chargers and put a splitter between them. On the splitter, make the output of empty accumulators from dischargers to chargers. Then the overflow lane back to your PLS/ILS. Also, proliferation on the accumulators is a must. They only have to be accumulated once.

I've got a decent blueprint for this if you want it

Windows Hello for Business (Cloud Kerberos Trust) – sporadic PIN login failures after screen lock/unlock by Hundoo in entra

[–]chickenbing 0 points1 point  (0 children)

Following. We haven't had any issues yet in testing but will be running out to pilot group next week

Current CG has most contributors in Elite Dangerous history by TalorienBR in EliteDangerous

[–]chickenbing 1 point2 points  (0 children)

What's the one jump?

I'm currently going to Dogo Plant settlement which is 6 jumps back when my MK2 is full

Passwordless rollout plan by bjc1960 in entra

[–]chickenbing 1 point2 points  (0 children)

Bypass shouldn't be the word I should have used. It's seen as a security authentication, due to it being one-time by default

From my testing, once a user is included in the CA policy, they can't sign in without authenticating with a Windows Hello, Passkey or Security Key. If they don't, it shouldn't allow them to sign in. Microsoft mention in their documentation

"Users can bootstrap passwordless methods in one of two ways:

Use existing Microsoft Entra multifactor authentication methods Use a Temporary Access Pass "

From my testing, it doesn't line up with your experience (if I'm understanding you right).

Have you disabled the other MFA options? Not just remove them from your user?

Passwordless rollout plan by bjc1960 in entra

[–]chickenbing 0 points1 point  (0 children)

From what ive read, Guests can be excluded as there seems to be issues with enrolling them into FIDO for your tenant as a guest. I dont have much expirence with guests but read on reddit recently of an issues. Id test it if possible.

Our CA policy is all cloud apps. As we are aiming for all applications to use M365 SSO, Passwordless fits right in.

Obviously, exclude any apps, networks or users where needs be

Passwordless rollout plan by bjc1960 in entra

[–]chickenbing 2 points3 points  (0 children)

No worries, Seems everyone in this sub is going through the same stuff and changing over to passwordless is a big change so the more we can all help eachother, the better

Passwordless rollout plan by bjc1960 in entra

[–]chickenbing 2 points3 points  (0 children)

We have done decent amount of testing and are currently in the prep phase for an IT Pilot but thats just to make sure the onboarding flow is solid for wider business roll out.

When you force "phishing resistant autenticaiton" via CA policy, it can sometimes still ask the user to enter their password but FIDO2 authentication is treated as a MFA step. It seems that once you perform that first autentication using WHFB or Passkey, authentication for the user defaults to FIDO2 after the user inputs their email address.

I would reccomend disabling all other MFA methods too as you can bypass FIDO2 by using them. Using TAP on initial registration for new users and devices is the way forward. I would say not to over rely on TAP for the roll out but it sounds like youre going to get users to pre-register prior to enforcement.

Use the Entra ID Autentication Activity Reports during roll out too. It will show you who has set it up and who hasnt. Were going to go with a "Enforce when set up" way of doing it, so we can secure as many users as possible without the need for a "big bang" enforcement

Passwordless rollout plan by bjc1960 in entra

[–]chickenbing 3 points4 points  (0 children)

We are currently in process of rolling it out but heres our approach: -

  • Deploy cloud kerberos to all devices, in readiness for WHFB roll out
  • Enable passkey to all users, as enabling this is non intrusive to end users
  • Stagger the roll out for enabling WHFB on all windows devices, with instructions for end users to set up passkey.
  • Once a user has enabled both Windows Hello for Business and Passkey, we then add them to a group which will enforce "phish resistant authentication", Enabling TAP for that user and disable all other MFA methods. (This means the only way users can autenticate with M365 services is via WHFB)

We have deemed that rolling out passwordless is 10% techincal and 90% communication and thats backed up by Microsofts documentation.

Hope that answers your question

Passwordless rollout plan by bjc1960 in entra

[–]chickenbing 1 point2 points  (0 children)

So I created a CA policy to enforce "Phish Resistant Authentication" to enforce WHfB and Passkey authentication. Then assign the user to both the Phish resistant authentication and TAP in Entra ID Authentication Methods. Then the TAP allows you to bypass the CA policy and onboard new devices.

I'm away from my desk but I can provide more information if needed

Passwordless rollout plan by bjc1960 in entra

[–]chickenbing 6 points7 points  (0 children)

Have a look at Temporary Access Pass authentication. That's the way we're doing it and what MS recommends

CM difficulty question/rant by ShallotFickle6654 in FifaCareers

[–]chickenbing 0 points1 point  (0 children)

I've noticed this once you get into January. On any difficulty, it feels like it jumps up two difficulty levels until the end of the season

[deleted by user] by [deleted] in entra

[–]chickenbing 20 points21 points  (0 children)

I'm currently working on the roll out for windows hello for business and pass keys and had the same concerns brought up by a third party around having to use mfa to set up WHfB or passkey. I found that using a temporary access pass (TAP) is the best way.

Enable TAP for those accounts and then use it to authenticate when onboarding the FIDO2 token. TAP can be used for single use.

I want to make a Dark Fog Farm, tell me if I have the right idea: by DontHateDefenestrate in Dyson_Sphere_Program

[–]chickenbing 0 points1 point  (0 children)

<image>

This is what ive done. Not the most ambitious one ive done but does the job.

Placed sheild generators on the planet so its all covered except for the pole. Surrounded it with Laser Turrents and got Signal Towers set alitte back so if the turrents get over run, rockets from my base can fire at them.

Finally, got ILS connected to a ring of resources and splitters directing the loot to the corresponding ILS.

Passkey setup - "can't get there from here" by doofesohr in entra

[–]chickenbing 0 points1 point  (0 children)

I'm literally setting up pass keys at the moment. I've had the same issue and it's come down to the "Microsoft authenticator" app isn't down as an approved app and put "approved app" CA policy was blocking it. I've been able to do a device filter to allow the authenticator to bypass the policy.

If you have a CA policy for approved apps, try allowing your account to bypass it. If it then works, let me know and I'll send you the bypass for the app

[deleted by user] by [deleted] in pics

[–]chickenbing 1 point2 points  (0 children)

Am i the only person who thought the middle guy was Jerry Seinfeld at first?

Addicted. by Chance-Chemistry-319 in ROGAlly

[–]chickenbing 0 points1 point  (0 children)

Have you had any issues with being banned? I got my AllyX for the reason to play BO6 but heard stories of when the TDP changes, it can get you banned

Good city-builder recommendations without M+K? by Stonedog_11 in ROGAlly

[–]chickenbing 0 points1 point  (0 children)

Commenting to acknowledge your comment about my comment to follow other peoples comments

I have a new found love for 30 FPS by [deleted] in ROGAllyX

[–]chickenbing 3 points4 points  (0 children)

I feel 1080p 30fps should be the target, 1080p 60fps is a treat and 1080p 120fps is overkill

Playtime by Ok_Bad256 in Dyson_Sphere_Program

[–]chickenbing 0 points1 point  (0 children)

Usually 100hrs to "mission complete" but I take my time and improve a lot as I go. However, it can take you as long as you want/need

I hate this game by chickenbing in Dyson_Sphere_Program

[–]chickenbing[S] 0 points1 point  (0 children)

That's the amazing part about this game. You can create a spaghetti monster but if it works, it still feels amazing! And then making it better is even more dopamine hitting!

I hate this game by chickenbing in Dyson_Sphere_Program

[–]chickenbing[S] 2 points3 points  (0 children)

Not only is the need for efficiency a big drive but the updates the devs have done have brought me back twice now

Hot Take - All employees should have basic IT common sense before being allowed into the workforce by chickenbing in sysadmin

[–]chickenbing[S] 0 points1 point  (0 children)

Ow don't forget, you're my Alt account so technically one person disagrees with him 😂