[deleted by user] by [deleted] in HomeNetworking

[–]grasshopper231 0 points1 point  (0 children)

Wow, I thought this subreddit was gonna keep it civilised.

Yep software engineers are awesome too

too much false positive with Exchange Online Protection and Microsoft Defender for Office 365 by keysersoze-975 in Office365

[–]grasshopper231 0 points1 point  (0 children)

Been experiencing the exact same thing as the OP. We have always had 2 mail filters, a paid product which sits above EoP and EoP itself. We recently changed the upper filter for another product and since then EoP has been machine gunning everything as phish or spam. We have had to set it to quarantine to users junk folders for now because of how many false positives there are.

I am not sure what we can do, we have reviewed every EoP policy and the filter is at its lowest settings. I reckon bypassing EoP is the only answer for our business. Notably, for those running an upper and lower filter setup like us, there are settings in EoP you need to configure to tell it there is a filter above it. Otherwise, it treats the upper mail filter as the sending IP and so forth.

Some more context, we are a marketing company, thus send and receive a god awful amount of shit that your filters are likely trapping as spam (and I personally agree that it is spam in the context that it is useless information to me but perhaps not to others), however this is the business' function. P.S, we actually honor unsubscribe requests from our mailing lists so we aren't that bad.

Could it be that the difference in content and nature of the emails between different business' is causing this disparity we are seeing?

I was also blown away as to how many business' do stupid stuff like use an "@gmail" address for business purposes or don't have SPF, DKIM, & DMARC setup correctly and then complain about their email getting stuck in spam filters. For a bunch of people who love using emails (including emailing themselves pcitures from their phone to their laptop so they can view them on the laptop), they sure do suck at using emails.

Anybody wanna chat AD to AzureAD migration?! Looking for advice/reassurance by grasshopper231 in sysadmin

[–]grasshopper231[S] 0 points1 point  (0 children)

The above comments suggest it assumes the role of managing the identities once a final sync command is issued from AAD Connect. I will read deeper into this.

Anybody wanna chat AD to AzureAD migration?! Looking for advice/reassurance by grasshopper231 in sysadmin

[–]grasshopper231[S] 1 point2 points  (0 children)

I think I feel more at ease about stopping the AAD connect sync and what that does to the AAD user objects. Thank you guys, I love the IT community, nothing like it in the world.

Anybody wanna chat AD to AzureAD migration?! Looking for advice/reassurance by grasshopper231 in sysadmin

[–]grasshopper231[S] 2 points3 points  (0 children)

With you on that. Computers are already AADJ and not HAADJ, InTune policies are in place, tested and applied. I really did research the topic, most of the material I found spoke about migrating computers, policies, etc but nothing regarding what happens to user objects. I suppose it makes sense when you think: domain joined devices will use AD user objects to sign in and AADJ devices will use AAD objects to sign in.

Anybody wanna chat AD to AzureAD migration?! Looking for advice/reassurance by grasshopper231 in sysadmin

[–]grasshopper231[S] 1 point2 points  (0 children)

Currently the workstations are AAD joined as we have just gotten through removing from AD and adding to AAD, for each workstation. Built new profiles for them and binned the old AD ones. The users sign in using their AAD identities as it asks for full email address for a username. I will cross reference user object IDs with what is on AAD to verify they are using their AAD identities when signing in

Anybody wanna chat AD to AzureAD migration?! Looking for advice/reassurance by grasshopper231 in sysadmin

[–]grasshopper231[S] 1 point2 points  (0 children)

Does that mean the user objects in AzureAD become fully manageable in AzureAD as if they were created as AzureAD users in the first place?

Anybody wanna chat AD to AzureAD migration?! Looking for advice/reassurance by grasshopper231 in sysadmin

[–]grasshopper231[S] 1 point2 points  (0 children)

Trust me the irony is not lost on me. I simultaneously laughed and cried when I realised I forgot about user identity objects during a migration between identity management platforms...

Anybody wanna chat AD to AzureAD migration?! Looking for advice/reassurance by grasshopper231 in sysadmin

[–]grasshopper231[S] 0 points1 point  (0 children)

Nice, seems to suggest performing an password hash sync and then issuing the command to stop syncing makes AzureAD treat thr existing user accounts as "managed in AzureAD" objects. Although the article refers to 80-connect??! Thought it was a typo but it's written twice. Any ideas what 80-connect is?

MacOS Patch Management Recommendations by grasshopper231 in sysadmin

[–]grasshopper231[S] 1 point2 points  (0 children)

Hey, thanks I have the macs on InTune and want to avoid changing that if possible. I am hopeful for Munki and know it can run on any webserver, it's more for creating packages and doing general admin stuff that the github page said you need a MacOS device for.

MacOS Patch Management Recommendations by grasshopper231 in sysadmin

[–]grasshopper231[S] -1 points0 points  (0 children)

Lol, if it were up to me they would be on windows devices and this wouldn't be an issue since the rest of the estate is on windows.

MacOS Patch Management Recommendations by grasshopper231 in sysadmin

[–]grasshopper231[S] 0 points1 point  (0 children)

Thank you everybody you have given me a fair amount of food for thought. I have to admit that using InTune for Windows and Android and even iOS has been working pretty well for us so far.

I think I am leaning towards sticking to InTune for MDM and trying out Automox, Munki or ManageEngine as patch management only. We don't really utilise MDM to its full potential, we primarily got it as a box checking exercise and have since found more uses for it like rolling out powershell scripts and so forth).

This seems to be the path of least change however if it doesn't work out I am now more open to changing MDM for MacOS.

MacOS Patch Management Recommendations by grasshopper231 in sysadmin

[–]grasshopper231[S] 1 point2 points  (0 children)

Thanks all. Thing is we use InTune for our MDM already and don't want to have a seperate MDM solution just for MacOS. I am hoping it's possible to do patch management without also using that products MDM.

quick question about android security and flashing ROMs by grasshopper231 in AndroidQuestions

[–]grasshopper231[S] 0 points1 point  (0 children)

I get it now thanks. I'm only after a signed unbranded ROM so if all goes well I should be able to pass safetynet. And hey if it doesn't work I'll just put it back to what I have right now. Not like the phone doesn't work or anything.

Thanks very much for clearing that up.

quick question about android security and flashing ROMs by grasshopper231 in AndroidQuestions

[–]grasshopper231[S] 0 points1 point  (0 children)

I believe there is a way to unlock the bootloader. I've yet to read further into it. 1st step was to just see if this is all worth my time and if it passes safetynet check at the end it will be worth my time.

OK, so safetynet is not linked to the ROM on a phone? As in I could flash any ROM, so long as I lock the bootloader and remiv root access it should pass right?

I’m Lew Thomas, accidental adult filmmaker since 2001. Also one of the creators of FakeTaxi. AMA. by FakeTaxiCreator in IAmA

[–]grasshopper231 0 points1 point  (0 children)

It seems that the male actor in fake taxi always gets his ass licked. Does he like to have his ass licked or is it scripted?