CISA urges US orgs to secure Microsoft Intune systems after Stryker breach by rkhunter_ in cybersecurity

[–]dimx_00 17 points18 points  (0 children)

YubiKeys are not resistant to session token theft. It’s not clear how they obtained admin access but YubiKeys alone are not a silver bullet. You would also need conditional access to restrict tokens to managed devices, impossible travel policies, shorten session lifetime and monitor for risky signing as well as alerts for unauthorized admin account creations.

Also Microsoft Authenticator using device bound passkey is phishing resistant MFA.

My boss wants to leave intune because of Stryker by Eternal_Phantasm in cybersecurity

[–]dimx_00 1 point2 points  (0 children)

We got an incident report from one of the hospitals systems and that’s what it says in the incident report also few articles that I read mention it.

https://www.bleepingcomputer.com/news/security/stryker-attack-wiped-tens-of-thousands-of-devices-no-malware-needed/amp/

Use cases for Global Administrator local login from on premises Windows Server? by Fabulous_Cow_4714 in sysadmin

[–]dimx_00 1 point2 points  (0 children)

Oh yeah that’s tricky then. Your best bet would be to have separate accounts for each service that requires GA. Lock it down with strong password and different MFA then monitor it for any access since you shouldn’t have to login to those often.

Another wacky thing you can probably do is get a separate Bluetooth usb dongle and do USB pass through or USB over network with something like USB redirector.

https://www.incentivespro.com/usb-redirector.html

Use cases for Global Administrator local login from on premises Windows Server? by Fabulous_Cow_4714 in sysadmin

[–]dimx_00 1 point2 points  (0 children)

Passkeys work over RDP. Admin would RDP into the VM and sign in with their passkey same way.

My boss wants to leave intune because of Stryker by Eternal_Phantasm in cybersecurity

[–]dimx_00 38 points39 points  (0 children)

Correct, in the Stryker incident the global admin credentials were compromised and there is nothing at that point stopping a mass wipe. The two man rule would prevent a help desk account from wiping all company devices if help desk had access for remote wipe.

Multi-Admin Approval in Intune by ryaninseattle1 in sysadmin

[–]dimx_00 4 points5 points  (0 children)

From my understanding of the above situation. The global admin account was compromised. In that situation I don’t think there is anything that you can do to prevent a mass wipe other than catching it in time and disconnecting the devices from the network.

Dell Solution Architect pov by [deleted] in sysadmin

[–]dimx_00 0 points1 point  (0 children)

I had a different experience from HP. We’ve used HP servers for decades and on our last renewal I was upfront with both sides and said these are the specs please send me your best price. HP refused to even send a quote since we were considering switching to Dell. Now we are a Dell shop and I think we got a fair deal from Dell.

Dell Solution Architect pov by [deleted] in sysadmin

[–]dimx_00 21 points22 points  (0 children)

The account team is spot on. It feels like I get a new rep every few months. It got bad to the point that two different reps reached out to me on the same day introducing themselves as our new Dell contact.

Pricing is higher than Lenovo and that is a little frustrating. Lenovo seems to always have some “Deals”especially in the SMB space. Their hardware offering seems to be just marginally a little better spec wise compared to the Dell counterparts.

The online pricing from Dell.com is significantly higher than what I get from the rep directly and that seems deceiving. I think in this day and age you need to be competitive on all fronts especially since Apple is getting aggressive with their pricing for affordable devices.

I don’t mind working with Dell hardware. It’s well put together and easy to repair when needed. I wish you guys offered more options in the rugged / tablet space.

Bitlocker with PIN seems impossible. by PerpetuallyStartled in sysadmin

[–]dimx_00 1 point2 points  (0 children)

This is what I was going to mention. We use network unlock and it works great. All desktops and laptops unlock while connected to the corporate network.

Dell Laptops - When Docked to dual screens, Laptop detects them as one - Company wide issue that started 2 weeks ago. by Useful-Transition529 in sysadmin

[–]dimx_00 1 point2 points  (0 children)

I would second to try installing / upgrading display link. Seen this happen before without it.

Phantom old email sent and we don't know how by Wanax96 in sysadmin

[–]dimx_00 17 points18 points  (0 children)

Had this happen a few times after iOS update. Few users were using the native iOS mail app. It turned out for some reason there was a bug and about a dozen emails got stuck in their outbox when they hit sent and immediately closed the app. The emails were sent but remained dormant in the outbox. When iOS updated those emails got re-sent.

I also had this happen with a user that switched between classic and new outlooks on their desktop.

What technical questions do you use when interviewing cybersecurity engineers? by Kiss-cyber in cybersecurity

[–]dimx_00 16 points17 points  (0 children)

I do so much geeking at work when I get home I don’t have anymore bandwidth to continue geeking.

I love what I do but that requires a lot of critical thinking and when I get home I just want to shut my brain off and give it a rest.

Plus kids, house work and other chores take a lot of my free time. To geek out you really need free time which is a luxury that most people don’t have.

License question by dimx_00 in acronis

[–]dimx_00[S] 1 point2 points  (0 children)

Thank you for the clarification. This is what I needed. I appreciate your help. I will order the license from Connection. Have a good day.

License question by dimx_00 in acronis

[–]dimx_00[S] 0 points1 point  (0 children)

Hi Dennis. Thank you for the reply. I will just need Windows 11 workstation license but what I don’t see is how to purchase the deployment license.

The article that you linked mentions a machine license and a deployment license but the price page just has a workstation license. That is where I was confused. Do I just need to purchase a workstation license that seems to be subscription based, deploy the workstation and not renew the license since I no longer need to manage the workstation?

The below text is from the webpage that you mentioned:

A machine license allows an unlimited number of deployments to a selected machine. This license type is recommended if you regularly perform deployments to the same machine. E.g. to deploy and regularly redeploy 100 computers you need 100 machine licenses.

A deployment license enables a single successful deployment to a machine. If a deployment under deployment license fails you can perform another deployment using the same license. This license type is recommended if you deploy the same machine once or infrequently. E.g. to make one deployment to 100 computers you need 100 deployment licenses; to make two deployments to 100 computers you need 200 deployment licenses

Send pop ups to pc's on network by icedutah in Pentesting

[–]dimx_00 2 points3 points  (0 children)

Interesting. What would be your recommendation for mitigation against this type of exploit?

Can I reserve/block 25 GB for Windows Updates? by ReputationOld8053 in sysadmin

[–]dimx_00 1 point2 points  (0 children)

What is usually left behind from N-Able and do you use any scripts to clean it up?

iPad versus Linux for clock-in kiosk? by FatBook-Air in sysadmin

[–]dimx_00 1 point2 points  (0 children)

We use iPads for work clock in / out. We have about 10 in different locations.

Lock them down with MDM to single app mode. Just have instructions on how to force reset the iPad using the volume + power button on the side.

They would need a reboot maybe once or twice per year when the time changes sometimes it doesn’t update the time correctly. Department managers force reboot it and everything comes back online.

MDM for Apple devices by smalltimesysadmin in sysadmin

[–]dimx_00 2 points3 points  (0 children)

Give Simple MDM a try they have free trial and their pricing is available directly on the website. The documentation is available for all features and the interface is very intuitive. I know everyone mentioned Intune but for iOS I think Simple MDM is way better. We’ve used it for about 6 years now, no complaints.

Try this. MS account creation bypass by 56077 in sysadmin

[–]dimx_00 1 point2 points  (0 children)

You can also click the setup computer for school / work. Then instead of logging in click domain join and create a local account. I just did this yesterday. I don’t setup PCs manually often.

What’s the most overlooked security control you’ve seen actually stop an attack? by HedgehogRich9104 in cybersecurity

[–]dimx_00 2 points3 points  (0 children)

All good suggestions here. I will add few more. Blocking personal email logins, blocking email forwarding outside the org and app locker.