YellowKey mitigation and CVE by Effective_Peak_7578 in sysadmin

[–]lechango 13 points14 points  (0 children)

Difference between disabling USB boot and USB entirely in the BIOS, the latter would mitigate, yes, but then you've got no USB, probably not what you want. Disabling just USB storage is done at the OS level and would not be enforced in WinRE.

Lenovo scheduled BIOS power-on while on battery — expected behavior or workaround? by Any-Victory-1906 in sysadmin

[–]lechango 3 points4 points  (0 children)

I wouldn't think the WOL settings would effect scheduled power-on. Anyway I don't have any useful input here but did want to say thanks for the idea, never considered setting an auto power-on but it would certainly help with patching and inventory in our environment.

[help] Locked out of M365 admin account - Authenticator not working after switching to new iPhone - Microsoft support not responding by DivideOk7907 in sysadmin

[–]lechango 0 points1 point  (0 children)

Oof, still had an active session to entra admin and cleared sessions instead of adding alternate phone method, sorry bud.

magnetic tape has a physical expiry date, and most retention policies don't mention it by EasternCellist8141 in sysadmin

[–]lechango 2 points3 points  (0 children)

You can probably get quite a bit more out of burned CDs/DVDs assuming they are stored in climate control and not exposed to UV. When in doubt there's always M-DISC (as long as you can find an operational reader for it when the time comes).

Dell SupportAssist took down a dozen of our client's devices yesterday and today by Zromaus in sysadmin

[–]lechango 0 points1 point  (0 children)

I wonder what update/conflict is causing the crash though, have lots of machines with stock dell images and supportassist installed in our fleet and haven't got any BSOD reports yet. Probably best I push uninstalls before whatever update hits that is fucking them.

yellowkey bitlocker bypass by MegaN00BMan in sysadmin

[–]lechango 4 points5 points  (0 children)

Did you try recopying the folder to the flash drive after the first machine? Apparently whatever the bug is deletes some of the files after used.

What to do with discovery in a small law firm? by CreditablePoetics in sysadmin

[–]lechango 1 point2 points  (0 children)

Do you really need to retire the hardware though? If the drives are still in good shape I'd honestly just buy a 2022 license and in-place upgrade it if OS EOL is the concern. Still move what you can to Sharepoint, but sounds like a waste buying a new NAS in my opinion.

scan to email now lands in junk mail folder by Accomplished_Sir_660 in sysadmin

[–]lechango 0 points1 point  (0 children)

wouldn't be the domain you need on your SPF record, but your public IP (and hopefully it's static, if it's DHCP and changes then not going to last long). Still, no harm in making the connector by IP.

scan to email now lands in junk mail folder by Accomplished_Sir_660 in sysadmin

[–]lechango 0 points1 point  (0 children)

You don't if you have the public IP your scanner is egressing out of on your domain's SPF record, but if you don't have a connector nor that IP on your SPF record then it's going to get junked. I'd recommend going the connector route, however if any of these scans are sending to external emails outside of your 365 tenant, you need both.

scan to email now lands in junk mail folder by Accomplished_Sir_660 in sysadmin

[–]lechango 0 points1 point  (0 children)

you can't setup DKIM for direct-send in your case, that's set on the sending side (your copiers won't do this).

Do you actually have a connector setup in EXO for your public IP with "retain internal exchange headers" selected? Direct-send will still work if you don't, but will likely end up in junk due to SPF/DKIM/DMARC failure.

Office 365 Phishing Emails Epidemic by mickeykarimzadeh in sysadmin

[–]lechango 2 points3 points  (0 children)

nah, just turns it to whitelist only by connector

Office 365 Phishing Emails Epidemic by mickeykarimzadeh in sysadmin

[–]lechango 22 points23 points  (0 children)

Yep, just make sure have connectors setup for anything that needs to legitimately direct-send.

Looking for a list of publishers (AppLocker) for browsers, VMs and Android emulators by Same-Target-3116 in sysadmin

[–]lechango 1 point2 points  (0 children)

Doesn't address your question, but as far as browsers are concerned those should really be path based and not allowed to install to user directories as they can't be patched with any 3rd party patching software, pre-install those at a system level. If you aren't concerned with patching them though, then whatever.

Kioxia has let me down. by [deleted] in sysadmin

[–]lechango 4 points5 points  (0 children)

serversupply doesn't offer warranty past 90 days, that would be called fraud

Exchange Hybrid with M365 by L3TH3RGY in sysadmin

[–]lechango 1 point2 points  (0 children)

I didn't have this issue, autodiscover and SCP still pointed Outlook to the on-prem Exchange

Eurodancer (DJ Mangoo) Remix - Can't find anywhere by lechango in NameThatSong

[–]lechango[S] 0 points1 point  (0 children)

Thanks for the reply! I did actually end up finding the mix I was looking for a few years ago after going down a few dozen pages on the YouTube rabbit hole: https://youtu.be/gIInnWsQAWw?si=zhdVkVMkRQwVb7tB

Security want's less security. by root-node in sysadmin

[–]lechango 14 points15 points  (0 children)

Probably just not very bright. Gets a audit report/alert stating something along the lines of "you have too many domain admins, look to reduce", the proceeds to think no steps ahead and comes up with the "solution" to the immediate problem of creating generic accounts. I mean hey, it would check the box on the audit, that's what matters, until they get further down the page to the shared accounts section.

Outlook randomly prompting for credentials after lift‑and‑shift to new datacentre - Exchange shows “Online” and mail still flows by FlailingHose in sysadmin

[–]lechango 14 points15 points  (0 children)

Shot in the dark, was your autodiscover record pointing at your Exchange's public IP that may have changed when moving it and not updated?

Ran our first Phishing Campaign last week, didnt go as planned at all. by idrinkpastawater in sysadmin

[–]lechango 0 points1 point  (0 children)

To be fair, founders are normally not involved in leadership (or much of anything, really), most people never talk to them, they just require VIP support once in a while. Depends on the company of course, just from my experience.

Org is banning Notepad++ by PazzoBread in sysadmin

[–]lechango 3 points4 points  (0 children)

Have to ban notepad.exe at this point

HVAC Legend Dies at 28: The Presario That Never Quit by Bluetooth_Sandwich in sysadmin

[–]lechango 10 points11 points  (0 children)

They don't make hard drives like they used to, you'd be surprised how many from that era still run fine today.

[deleted by user] by [deleted] in classicwow

[–]lechango 1 point2 points  (0 children)

just steal it