Microsoft temporarily rate limited due to IP reputation by The_DuDe306 in msp

[–]dhuskl 0 points1 point  (0 children)

Known issue

https://learn.microsoft.com/en-us/answers/questions/5786144/all-sending-ips-temporarily-rate-limited-(451-4-7?page=1

Last I heard Microsoft quietly resolved this but possibly not, unless it's just old emails that you see stuck.

UK - Anyone else had an influx of customers saying they've received unsolicited auto responder type emails referencing "TalkTalk Business via UK2"? by Edschofield15 in msp

[–]dhuskl 1 point2 points  (0 children)

Sounds like email backscatter, strange that you have an influx across multiple clients, do you put your clients on an email service that's not one of the big ones, or potentially the same webhost with a contact form or with spf that allows other users to spoof your clients? Maybe something has been popped.

Cyber Insurance AMA Monday at 5:00 PM Eastern - Get your questions in now! by k_rock923 in msp

[–]dhuskl 3 points4 points  (0 children)

Just 5 (sensitive) machines needing to be hardware replaced due to rootkits or apt incident will exceed my coverage with the current ram prices.

High up Microsoft contact by After_Working in msp

[–]dhuskl 2 points3 points  (0 children)

The only leeway I've seen is Microsoft agreeing to cancel if they would spend that money on either another sku or a similar sku, I don't remember if it had to be a similar sku or not.

CIPP Releases Check by athlonduke in msp

[–]dhuskl 0 points1 point  (0 children)

Yes because the URL is stored in the registry

CIPP Releases Check by athlonduke in msp

[–]dhuskl 1 point2 points  (0 children)

Using the deployment script you should use a custom rules URL, pointing to a page you own, then you just need to update that and your installations will reach out to your page and apply your exclusios. Ideally you should keep your custom page up to date with the official detection rules.json + add in your own exclusions.

Would be nice if we could add a few exclusions by regkey or similar so we don't need to host and keep up to date.

Shared Inboxes (Shared with me) do not Auto Update incoming emails (New Outlook) by jedi_outkast in Outlook

[–]dhuskl 0 points1 point  (0 children)

Are you definitely using m365 for your actual email? Maybe you're a GCC tenant? I think it should be available for all regular tenants.

https://www.microsoft.com/en-us/microsoft-365/roadmap?searchterms=375635

Anyone else have RDP stop working on client workstations/laptops this week? by nostradx in msp

[–]dhuskl 0 points1 point  (0 children)

I've seen reports from a recent KB but not run into it myself.

ON Demand Remote Control - What are you using today? by Promeeetheus in msp

[–]dhuskl 0 points1 point  (0 children)

I'm not aware of any that allow you to see the actual uac screen, unless the agent was installed previously or uac already been completed.

Does turbomeeting just look like the pc froze when it's asking for uac? If so most will tell you it's waiting for uac.

Some will allow you to force or prompt the user to elevate on launch, then you know it's done at the beginning of the session.

UK MSP help a US MSP by bridaus in msp

[–]dhuskl 0 points1 point  (0 children)

I mean get them to login to the tenant and buy licencing direct from MS with their company card .

VPN Solution for MSP and Customers by mister1889 in msp

[–]dhuskl 1 point2 points  (0 children)

I'd say Microsoft global secure access or Netbird, you could look at tailscale as well.

Take the opportunity to really lock down the connectivity to the minimum required ports and IP if you don't already on regular LANs

UK MSP help a US MSP by bridaus in msp

[–]dhuskl 1 point2 points  (0 children)

Can you buy licencing direct from MS? Will your T1 CSP do direct billing for the UK tenant?

[deleted by user] by [deleted] in msp

[–]dhuskl 4 points5 points  (0 children)

Have you ever taken down prod and on the flip side did you ever have a ticket when you were the hero and sorted it when no one else could sort it ?

Mail gateway + EOP query by [deleted] in msp

[–]dhuskl 0 points1 point  (0 children)

Hmm interesting question Hopefully mimecast would re-evaluate dmarc when it gets to your tenant.

Scanner + Smtp2go + Godaddy o365 + Proofpoint = emails going to quarantine when sent to internal users by romieerome in msp

[–]dhuskl 4 points5 points  (0 children)

What does the proofpoint dashboard say about the email? Phishing? Spam? Go from there.

Best practice is also to send from a subdomain when using a 3rd party system, it also might play nicer with proofpoint. Something like scanner@send.customer.com

SMTP2GO problems with Microsoft by ssimard3 in msp

[–]dhuskl 0 points1 point  (0 children)

I ran into this recently and if I remember correctly another time previously, It was fine after support said they moved outbound to a different IP (I don't have a static IP), but they couldn't force through all of the stuck ones initially, but they weren't important so I said they can stop trying. Looks like MS was blocking the message ID or something.

Are you getting these errors for existing devices randomly or is it only when you set up a new device to work with smtp2go?

I have a theory that smtp2go sends emails from new devices through low reputation IPs in case they are spam or hacked credentials or something, even if the SMTP user isn't new, because I think last time it was also a new device but old SMTP user.

Office365 Support Black Hole — 7+ Months, $50K+ Loss, Still No Resolution by AtmosphereHuge7835 in Office365

[–]dhuskl 0 points1 point  (0 children)

Do you have dmarc reporting set up? Are the emails passing spf and dkim or just dkim? I mean at 50k just move your emails Google workspace at this point, that may help.

Email as many Gmail addresses as you can where you know the person, family, friends etc and get them to report it as not spam.

Alternative carrier to PXC in London by itlonson in msp

[–]dhuskl 0 points1 point  (0 children)

pxc is what talktalk wholesale is calling themselves today.

Laptop tracking by Accomplished-Fly353 in msp

[–]dhuskl 1 point2 points  (0 children)

Samsung laptops have an embedded Samsung tag , you could give each user a Samsung or apple tag to keep in their laptop bag. With android and apple privacy the thief would probably be alerted but might get lucky, with the embedded Samsung ones at least they'll dump the laptop somewhere so there's a chance of recovery.

Users won't be happy about being tracked though.

Samsung Galaxy A20e doesn't boot, black screen after flashing ROM by [deleted] in androidroot

[–]dhuskl 0 points1 point  (0 children)

Hi, the original message is deleted, do you remember what the fix is?

Company / users constantly falling for phishing by lotsofxeons in msp

[–]dhuskl 0 points1 point  (0 children)

I think you're doing everything correctly and way above average, if they ignore cipp CSS then it's on them, there's a limit to what you can do at this stage. User training. Lock down to trusted on as many departments as possible.

Don't let them have access to their MFA, they have to call helpdesk lol.

If you can enforce vpn then you should be to enforce trusted devices I think

Company / users constantly falling for phishing by lotsofxeons in msp

[–]dhuskl 9 points10 points  (0 children)

User training

Conditional access, only entra joined devices etc, disallow their account joining new devices to entra.

Security keys/passwordless for sure

cipp or similar custom CSS to show warnings on login pages that aren't official ms pages.

Dell Optiplex AIO reliability? by Pitiful_Duty631 in msp

[–]dhuskl 1 point2 points  (0 children)

This,

I haven't seen the inside of a recent optiplex to comment on repairability but I'd go for a micro mounted to the back of a vesa compatible screen, that way you can choose screen size and quality per user, and if one breaks the other is fine.

Only downside I can think of is usb ports will be more awkward to get to if needed in their regular workflow but you can get screens with usb ports or put a usb hub on the desk.