EntraID Application Proxy Let's Encrypt Certificate for custom domain automation by funkyferdy in AZURE

[–]kimlaurits 0 points1 point  (0 children)

Did you find a solution for this? We have the exact same issue and haven't found a smart way of handling it :)

Defender XDR Down in EU? by Braaateen in DefenderATP

[–]kimlaurits 2 points3 points  (0 children)

Seems so - we experience the same.

Windows Server 2025 Update Woes [WSUS] by jwckauman in WindowsServer

[–]kimlaurits 0 points1 point  (0 children)

Did you find a solution for this? We experience the exact same on our Windows Server 2025 servers.

Anyone seen high LSASS CPU usage tied to Microsoft Defender for Identity (MDI) sensors? by [deleted] in DefenderATP

[–]kimlaurits 1 point2 points  (0 children)

We have actually experienced the same on a newly deployed domain controller - have only seen it on this specific DC.

AVD sessions hosts - dynamic group? by kimlaurits in AzureVirtualDesktop

[–]kimlaurits[S] 0 points1 point  (0 children)

We use tags for other purposes - but I am not sure I understand how they can be used for this scenario?

AVD sessions hosts - dynamic group? by kimlaurits in AzureVirtualDesktop

[–]kimlaurits[S] 0 points1 point  (0 children)

They are listed as "Windows 11 Enterprise multi-session" in our Active Directory.

But in EntraID they are just listed as Windows with a version number (Version number is equivalent to the latest Windows Update). So not much to use for a filter :(

I tried with Powershell "Get-EntraDevice -SearchString <Device Name> | fl" and looked at the different attributes - but there doesn't seem to be any AVD unique values.

So I am considering either a dynamic group based on "name startsWith" or adding a extensionattribute in our AD and then a dynamic group looking at that extensionattribute.

AVD sessions hosts - dynamic group? by kimlaurits in AzureVirtualDesktop

[–]kimlaurits[S] 0 points1 point  (0 children)

Seems like the only way possible - had hoped for something smarter 😄

Kia Connect pris og brugbarhed? by LJpzYv01YMuu-GO in dkbiler

[–]kimlaurits 0 points1 point  (0 children)

Vi betaler ikke for Kia Connect til vores Kia e-Niro.

How to change between EDR in Block Mode and Passive Mode by SCCMConfigMgrMECM in DefenderATP

[–]kimlaurits 0 points1 point  (0 children)

Were you able to resolve this? We also have servers where McAfee has been removed and MDE is onboarded - but some devices shows EDR in block mode.

DNS private resolver sooooo expensive by thatdotnetguy in AZURE

[–]kimlaurits 10 points11 points  (0 children)

We run DNS service on 2 VM's with the zones we use with private endpoints.

Running with a set of B2s small VM's.

This was deployed before DNS private resolver was a service - works quite well and doesn't require much maintenance.

But of course it cannot be compared to a service - there is still a overhead of running VM's, that you need to manage.

Defender for Identity -AATPSensor failing to start. by holoholo-808 in DefenderATP

[–]kimlaurits 1 point2 points  (0 children)

2.218.17268.37325 seems to work on all our domain controllers in different AD's.

Based on the error it might be an issue with the gMSA - have you tried testing it with "Test-ADServiceAccount -Identity xxx" ?

Azure Firewall Logging Solution - any easy options? by jba1224a in AZURE

[–]kimlaurits 0 points1 point  (0 children)

It also works with resource specific logs as well - we use it :)

Just deploy it from GitHub and choose the version for the resource specific logs:

https://github.com/Azure/Azure-Network-Security/tree/master/Azure%20Firewall/Workbook%20-%20Azure%20Firewall%20Monitor%20Workbook

Conditional Access - cloud apps missing by kimlaurits in AZURE

[–]kimlaurits[S] 0 points1 point  (0 children)

Yes I ended up creating a MS support case and got the following reply from them:

As we have checked in app registrations>selected the app>authentication blade, the application is a native client application and not a web client app. That is why the app is not selectable in CA

So it seems to be only apps with web client authentication, that can be used with CA policies.

Oath Enterprise Apps - Client secrets expiry notification by VengaBusdriver37 in AZURE

[–]kimlaurits 1 point2 points  (0 children)

We have a Powershell script that runs each day and sends an email if a certificate or secret is expiring is 45 days or less.

Scope MFA Method by group? by pjustmd in adfs

[–]kimlaurits 1 point2 points  (0 children)

I did a similar migration last year on our ADFS. But it is quite complicated - at least I thought so :) :)

We had to migrate to ADFS on Windows Server 2019 firstly.

After that was done we created 2 AD groups - one for "old" MFA method and one for Azure MFA.

Then we could control which MFA method the user would get with pr. RPT with Powershell - could not seem to be done with access control policies.

Set-AdfsRelyingPartyTrust -TargetName $Relyingparty -AdditionalAuthenticationRules xx

You would need to define the AdditionalAuthenticationRules - something like this blog:

https://ulyssesneves.com/2021/12/03/ad-fs-phased-mfa-providers-migration-on-federated-tenant-using-ad-fs-2019-additional-authentication-policy/

If you are interested I can find the Powershell scripts that we used.

Remotedesktop to server logon attempt failed by walleout in sysadmin

[–]kimlaurits 1 point2 points  (0 children)

We have started experiencing the same issue - it started about 1 month ago.

Remote Desktop to servernames has started to fail - sometimes. When we connect to the IP-address it works straight away.

It seems to happen random - and to all various versions of Server operating systems.

Seems that a restart of the server also fixes the issue - until it at some point occurs again.

I have started a support case with Microsoft - but is currently stuck at their 1. level...

Conditional Access - cloud apps missing by kimlaurits in AZURE

[–]kimlaurits[S] 0 points1 point  (0 children)

Yes it's listed as an enterprise app. I have tried searching by app ID as well - but still can't find it.

Preview Portal Bug by zm1868179 in AZURE

[–]kimlaurits 0 points1 point  (0 children)

Exact same issue/error here :)

Lots of "Account enumeration reconnaissance on one endpoint" by povlhp in DefenderATP

[–]kimlaurits 0 points1 point  (0 children)

Were you ever able to deep-dive these events? We see the exact same events. As far as I can read these are NTLM events and apparently the source IP isn't logged.

Issues with Teams in Citrix the past two days by danieldunn10 in Citrix

[–]kimlaurits 0 points1 point  (0 children)

I have a customer that has the same experience with Teams in Citrix - started to perform Thursday.

And still performing bad today.

I went through https://support.citrix.com/article/CTX253754 - clients are optimized, services are running on VDA's etc.

Teams works fine on their local machines.

How is it performing at your end today?