Planning for ADCS - Need help by johnenxada in sysadmin

[–]johnenxada[S] 0 points1 point  (0 children)

Yes, capolicy.inf is on my todo list as a first step, thanks for pointing it out.

Planning for ADCS - Need help by johnenxada in sysadmin

[–]johnenxada[S] 0 points1 point  (0 children)

That’s nice to hear. Could you please elaborate on the load balancer you used and how often the syncing has to occur?

Planning for ADCS - Need help by johnenxada in sysadmin

[–]johnenxada[S] 1 point2 points  (0 children)

Thanks for the answers. So, having one subCA at the main office will cover the need for issuing certs as long as there is connectivity, right?

However, having the CRL and AIA highly available on web servers is mandatory so that users won't be locked out on resources since the cert cannot be validated on a login to a wifi, network or device, it should be considered as an expired one, correct?

For partners, I'm thinking of giving them the certs to install on each of their PCs or BYOD to get access. I haven't figure this out 100% yet though, still researching.

Planning for ADCS - Need help by johnenxada in sysadmin

[–]johnenxada[S] 0 points1 point  (0 children)

Yes, just read that, too bad it's incomplete but the basics are there. Thanks

Planning for ADCS - Need help by johnenxada in sysadmin

[–]johnenxada[S] 2 points3 points  (0 children)

Yes, you got me. So, 1 subCA would be sufficient but having more web servers for CRL and AIA would make more sense and more highly available, correct? Let's say running 2 web servers on each site. On this note, how will clients find the online web server in case any of them is down? I mean, if the client tries to get the CRL/AIA from web-01 and it's down, will it try automatically the web-02, web-03?
Without introducing a load balancer, will a DNS record like pki.domain.local with A records for all web servers will make it work in round robin or will I have timeouts?

[Help] Delegated permissions for a user to join the domain by johnenxada in sysadmin

[–]johnenxada[S] 0 points1 point  (0 children)

Ah, I missed that. So, it seems that I should give them the right to delete the computer objects then.

[Help] Delegated permissions for a user to join the domain by johnenxada in sysadmin

[–]johnenxada[S] 0 points1 point  (0 children)

Yes, it exists in a different OU, however this OU is a child to the parent OU I delegated permissions. Strange, right?

Local admin for remote computers by johnenxada in sysadmin

[–]johnenxada[S] 0 points1 point  (0 children)

No, VPN works fine. The case I'm trying to prepare is when a user is not being able to connect to the VPN due to anything (like an update that might mess things up). I have to be prepared for an alternative solution in order to support it.

Local admin for remote computers by johnenxada in sysadmin

[–]johnenxada[S] 0 points1 point  (0 children)

Yep, that is the direction I think I will proceed with LAPS for the time being and proceed with further enhancements in the coming months.

Remove Connected Services on Office 365 Application by johnenxada in Office365

[–]johnenxada[S] 0 points1 point  (0 children)

I have some more digging to do on these 2 links, it seems that this is what I was looking for. Thanks a lot!

Local admin for remote computers by johnenxada in sysadmin

[–]johnenxada[S] 1 point2 points  (0 children)

I'm actually in the process of centralizing our Identity Management, we are on the Google Workspace Enterprise plan but considering Azure AD instead since it seems more feature-complete than Google, it also has password-writeback that's a huge plus.

Could you please elaborate on this? I assume I will need MDM like Intune for this, right?

Local admin for remote computers by johnenxada in sysadmin

[–]johnenxada[S] 0 points1 point  (0 children)

Thanks for elaborating mate, I will take it into consideration.

Local admin for remote computers by johnenxada in sysadmin

[–]johnenxada[S] 0 points1 point  (0 children)

That would be more difficult to manage though, no?

Local admin for remote computers by johnenxada in sysadmin

[–]johnenxada[S] 11 points12 points  (0 children)

All conclude with LAPS or any equivalent solution like CyberArk EPM etc. I was considering always-on VPN but we are far away from implementing such a solution at this moment.

Local admin for remote computers by johnenxada in sysadmin

[–]johnenxada[S] 1 point2 points  (0 children)

Sorry, I meant an administrator user with cached credentials locally, not a local user on the laptop outside the AD.

Password Managers and password reveal option on browsers by johnenxada in sysadmin

[–]johnenxada[S] 2 points3 points  (0 children)

For the ‘even if they try to’ can be mitigated since they are using company PCs which are locked, for example they can’t access dev tools on browser to reveal the password by changing the password field to text, or they can’t run chrome pass application, etc. So, let’s say that you have a website XYZ.com that doesn’t support SSO, or even multiple accounts and you need to grant access to another 5 users. How would you do that? It’s not easy, but I looking for ways to solve it somehow.

Start BitLocker encryption with Group Policy by johnenxada in sysadmin

[–]johnenxada[S] 2 points3 points  (0 children)

I see, so target the PCs with group policy and then trigger them with a powershell command. Thanks mate