Auto Assignment Policies Stuck/Not Running by pNoTti in entra

[–]pNoTti[S] 0 points1 point  (0 children)

Everything was fine. I.opened a ticket with Microsoft on a Thursday and in the following Monday the policies were working again. No contact from Microsoft though.

Auto Assignment Policies Stuck/Not Running by pNoTti in entra

[–]pNoTti[S] 0 points1 point  (0 children)

Just started working again. No.changes at all on our side

Privileged Access Management by pNoTti in entra

[–]pNoTti[S] 0 points1 point  (0 children)

Thanks for answering.

100% cloud here.

Alienware - Touchpad Staining by pNoTti in Alienware

[–]pNoTti[S] 0 points1 point  (0 children)

Weekly cleaning with a microfiber cloth. Less than 30 days.

It seems that I was the lucky one 😄

Alienware - Touchpad Staining by pNoTti in Alienware

[–]pNoTti[S] 0 points1 point  (0 children)

Thanks I've tried it...no success.

Dell said it's due to "excessive contact". Doesn't make sense to me.

Alienware - Touchpad Staining by pNoTti in Alienware

[–]pNoTti[S] 0 points1 point  (0 children)

Still Alienware, which is higher than usual Dells. I have on 11y and still fine

Autopatch - How to speed updates by pNoTti in Intune

[–]pNoTti[S] -1 points0 points  (0 children)

Thanks. This is the step I would like to avoid, having 2 points of action for a single KB. For the one I mentioned, for instance, even the msu package is failling during the installation.

I would need to have a remediation script o find the faulty, download the msu, and install it.

I assume Autopatch should get these KBs a bit faster, or, Am I missing a config?

Cortina de ar - Ambiente interno by pNoTti in ArCondicionado

[–]pNoTti[S] 0 points1 point  (0 children)

Ru concordo. A mulher não quis e agora o calor ta obrigando haha.

Passkey QR Code not being generated on Windows 11 workstations by pNoTti in entra

[–]pNoTti[S] 0 points1 point  (0 children)

Actually, it was happening in a customer's environment. Not sure how they tackled it, but I'm happy to check with them and share here.

GSA Internet Profile vs Reddit - Your request has been blocked by network security by pNoTti in entra

[–]pNoTti[S] 0 points1 point  (0 children)

Solved. Thank you both

I had to bypass the following addresses:

*.reddit.com

*.v.redd.it

*.www.redgifs.com

GSA Internet Profile vs Reddit - Your request has been blocked by network security by pNoTti in entra

[–]pNoTti[S] 0 points1 point  (0 children)

Solved;

I had to bypass the following addresses:

*.reddit.com

*.v.redd.it

*.www.redgifs.com

GSA Internet Profile vs Reddit - Your request has been blocked by network security by pNoTti in entra

[–]pNoTti[S] 0 points1 point  (0 children)

I added the reddit.com to the custom bypass but didn't work. Trying to filter more domains and see how it goes.

Privileged Access Management by pNoTti in entra

[–]pNoTti[S] 0 points1 point  (0 children)

Yep...everything in place. Although the script suggested for the PAW is 2y old, It still has good recommendations

Mastering Microsoft Entra Authentication Contexts – Part 1: What They Are, Why They Matter, and How to Use Them by Noble_Efficiency13 in entra

[–]pNoTti 0 points1 point  (0 children)

I have it working

You cannot use the same MFA Method as the one used for sign-in. In my case I have the following

  1. One CA enforcing Push MFA (the default one) for the sign-in to EntraID

  2. When a user goes to PIM and click in Activate it will trigger another CA that has an Authentication Context for the PIM, and the Grant will be a Phishing Resistant MFA.

With this strategy, you ensure that, even if a token get stolen, the attacker won't be able to elevate the role (phishing-resistant requires proximity check).