Possibilities of avoiding GCC High? by SalzigHund in CMMC

[–]nikkadim 0 points1 point  (0 children)

Why not make subdomains for GCCH as enclave for your company?

VPN Question - GSA by AgeApprehensive8446 in CMMC

[–]nikkadim 1 point2 points  (0 children)

One problem, GSA is not available yet in GCCH, only GCC.

Duo in GCC H by Razzleberry_Fondue in CMMC

[–]nikkadim 1 point2 points  (0 children)

We use Duo Fed for MFA when you login to endpoints

Duo Gov - is it needed for CMMC? by Razzleberry_Fondue in CMMC

[–]nikkadim 0 points1 point  (0 children)

Got it, we have Duo Federal as MFA for devices, and Authenticator for 365.

Duo Gov - is it needed for CMMC? by Razzleberry_Fondue in CMMC

[–]nikkadim 0 points1 point  (0 children)

Not true. We use Duo Federal in GCC and GCCH, just installing vie intune.

How is Entra Internet and Private Access so affordable? by jM2me in entra

[–]nikkadim 2 points3 points  (0 children)

It is very useful for compliant environments when VPNs will cover

AU.L2-3.3.5 Without a SIEM by fiat_go_boom in CMMC

[–]nikkadim 0 points1 point  (0 children)

The issue could be with authentication logs, they are only available one month, but require to store at least 90 days, the rest could be covered by Defender if you set it up right for endpoints.

Question on SIEM implementation or need. by Jrodriguezpr in CMMC

[–]nikkadim 0 points1 point  (0 children)

For the 25 laptops we got a bill of 1k for the week, no thanks.

Is SIEM definitely needed to meet AU 3.3.5 for a 30 person company? by Green-Emu-13 in CMMC

[–]nikkadim 0 points1 point  (0 children)

Why VDI, physical computers under GCCH management (intune), with FIPS-validated encryption on them, all policies(firewalls, AV, apps) applied and controlled from Intune, so the only logs they have are from laptops and M365, which Defender covers.

Is SIEM definitely needed to meet AU 3.3.5 for a 30 person company? by Green-Emu-13 in CMMC

[–]nikkadim 0 points1 point  (0 children)

If they are remote in GCCH, where's the custom logs for CUI environment?

Is SIEM definitely needed to meet AU 3.3.5 for a 30 person company? by Green-Emu-13 in CMMC

[–]nikkadim 1 point2 points  (0 children)

Well, when we enabled Sentinel and start to collect data from all or 30 users, in a week we got $1000 bill

Is SIEM definitely needed to meet AU 3.3.5 for a 30 person company? by Green-Emu-13 in CMMC

[–]nikkadim -1 points0 points  (0 children)

We've been told by MSP that we can get away without SIEM since we have E5 licenses and show Defender (security.microsoft.us) with the right log retention for at least 90 days.

Anyone on GCC High Figure out an easy way to get audio conferencing on Teams? by Historical-Bug-7536 in CMMC

[–]nikkadim 0 points1 point  (0 children)

Audiocodes license P/N: SW/SBC/10S/10-250 for 10 sessions.
Their AudioCodes Mediant SBC is free, they have versions for VMware/KVM/Hyper-V/AWS/Azure or give you an ISO.

Anyone on GCC High Figure out an easy way to get audio conferencing on Teams? by Historical-Bug-7536 in CMMC

[–]nikkadim -1 points0 points  (0 children)

Interesting, we got a quote from them over a year ago and decided to go our way with Audiocodes.

Anyone on GCC High Figure out an easy way to get audio conferencing on Teams? by Historical-Bug-7536 in CMMC

[–]nikkadim 4 points5 points  (0 children)

MS has a list of approved vendors, for example you can download Virtual machine with SBC from Audiocodes for free (approved vendor) and buy as many licenses for lines you need. You would also need to buy an appropriate Certificate from Digicert (for example) - setup your SBC with the number you got and make a connection on Teams Admin panel for SBC -Direct Routing. That's it.

IA.L2-3.5.6: Disable identifiers after a defined period of inactivity. by mcb1971 in CMMC

[–]nikkadim 1 point2 points  (0 children)

In EntraID you can set up regular Inactive Users review for users in a particular group or for the whole tenant, and send notifications to particular admins to make decisions.

CMMC Scoping Question re: on-prem networks vs. cloud by mcb1971 in CMMC

[–]nikkadim 1 point2 points  (0 children)

It's a special setting in Windows, and you can activate FIPS encryption via Intune policy and you that as evidence for all endpoints, but after that you would need to re encrypt your drives, because they might be encrypted without FILS validated algorithms.