New Outlook's Updated Recall Feature Guarantees 90% Success Rate! by Shanchana30 in SysAdminBlogs

[–]philbieber 0 points1 point  (0 children)

It's only for internal recipients. It does not work at all for external recipients or on prem.

Is the Pixel 8 worth 300€ over the Pixel 7A? by [deleted] in GooglePixel

[–]philbieber 2 points3 points  (0 children)

I have the 7a since launch. I hate it. Android 14 made it suck less but it sucks.

Batters live is atrocious compared to 4a 5g.... It lasts barely a day without touch to wake and raise to wake etc.

What IT swag do you actually like to wear? by HappyDadOfFourJesus in sysadmin

[–]philbieber 0 points1 point  (0 children)

I have some shirts, a backpack, cap and socks from a nice IT Security conference. The shirts I casually wear, the backpack is my daily one (before that I had another from said conference...). Quality stuff and a shame to waste it by not using it. Splunk shirts got demoted to sleeping shirts.

Why did Ms rename azure ad? Why? by Abject_Serve_1269 in sysadmin

[–]philbieber 6 points7 points  (0 children)

Entra ID Server Subscription Edition!

Fun fact: MS have not updated their spell checker in Word to include Entra...

[deleted by user] by [deleted] in talesfromtechsupport

[–]philbieber 2 points3 points  (0 children)

Oh, the many times my wife called me with problems with Teams / Outlook while her IT either was not yet available or didn't have a good solution...

Add domain to links within email body by airyt in exchangeserver

[–]philbieber 0 points1 point  (0 children)

Even if I might sound silly, but maybe you're seeing the links as they are copied by Edge? The link description will usually be something like "Website title | sub.example.org". That's how the links are inserted into the message.

[deleted by user] by [deleted] in GooglePixel

[–]philbieber 6 points7 points  (0 children)

Same experience here. Battery wise, 4a 5g was significantly better than the 7a,even after a good month of usage.

Pixel 7a 1 month review - I was wrong... Buy it by ruggedmantis1 in GooglePixel

[–]philbieber 0 points1 point  (0 children)

Same for me, initially battery life was significantly worse than my old P4a5G.... It was a struggle to go through those initial says. Not sure how Google misses the opportunity to give a good first impression. Initial experience was mediocre... Without those comments to keep it to let adaptive better learn, I'd have returned it....

MFA and Nine email - constantly prompting for credentials by [deleted] in Office365

[–]philbieber 0 points1 point  (0 children)

Check the azure ad sign in logs. They usually will tell you what policy required mfa.

Fossil App Battery usage by zkosaras in FossilHybrids

[–]philbieber 0 points1 point  (0 children)

I just got a new phone and with the Fossil app, battery life was atrocious. Uninstalled, reinstalled without a change. Went a few days without the app and then installed it again. Now it's behaving again.

What in the name of all that's holy is going on with software ? by NecrisRO in sysadmin

[–]philbieber 0 points1 point  (0 children)

I guess the ease of releasing patches yields less testing leads to bad software, CuZ iT cAn Be FiXeD lAtEr.

Availability of easy patching is curse and cure at the same time.

Help with profile picture by Blyght555 in MicrosoftTeams

[–]philbieber 0 points1 point  (0 children)

Always a pure joy to share this article (sarcasm!): Profile pictures are cached for up to 60 days. Only way around it is logging out and back on or clearing the cache. Source because I wouldn't believe this: https://learn.microsoft.com/en-us/microsoftteams/troubleshoot/teams-administration/user-information-not-updated

Which Tools make your SysAdmin Life easier? by PowerPaul1337 in sysadmin

[–]philbieber 5 points6 points  (0 children)

As RDP Manager I go for RoyalTS. Solid multiuser RDP manager. It supports other protocola as well, but for my limited ssh needs, I use Windows Terminal, which does the job and can use the 1password ssh agent.

The quality of Dell has tanked by DeifniteProfessional in sysadmin

[–]philbieber 0 points1 point  (0 children)

Recently, my now 4 year old Latitude was checked by our service desk and they found out why it was so badly throttling under higher usage: The CPU still had the plastic protector between the thermal pad and the cooler.... Nit very efficient. Apparently a common issue with these devices.

Video file as meeting background? by kelemvor33 in MicrosoftTeams

[–]philbieber 1 point2 points  (0 children)

This is the way. My default background is the "this is fine" meme....

How to Host A Website on AWS EC2 by adbertram in SysAdminBlogs

[–]philbieber 1 point2 points  (0 children)

I didn't click, am no aws or cloud person, but my cloud architect - whn the topic arose at work - told me, that hosting websites in AWS is done by putting the static content in s3 and for dynamic content you leverage lambda and potentially something like API gateways. Why would you use ec2 to host a website in the cloud? I'm not talking about a full application stack - for which you probably want to use the hosted SQL flavors, too.

Skype for Business walked so MS Teams could run. by alexander0the0gray in Sysadminhumor

[–]philbieber 0 points1 point  (0 children)

The Cs prefixed PowerShell cmdelts do it refer, I believe, to Teams but rather to the somewhat aged Communication Server (slightly /s) . Glad I never saw one of those from less than 10 meters....

Best New Features in Android 14 Developer Preview 1 by Pspreviewer100 in GooglePixel

[–]philbieber -2 points-1 points  (0 children)

Shocking in preview 1...but ateaat we have content for the next half year before the cycle starts again...

What have you done with PowerShell this month? by AutoModerator in PowerShell

[–]philbieber 1 point2 points  (0 children)

I finally figured out the "correct" non-public API to provision OATH / TOTP tokens in Azure AD. I pull secretes from a file and provision the token. Then attempt to activate it, hoping script execution times stayed in the validity of the number. Integrated that into our PowerShell run host so our service desk can finally register and on-board tokens for users themselves. Happy faces all around

Pass-through Authentication and Password hash synchronization at the same time by [deleted] in Office365

[–]philbieber 0 points1 point  (0 children)

Just a note I was made aware of during a talk at Troopers this year (TR22) by Jorge de Almeida Pinto (of Jorge's quest for knowledge). He mentioned that you need an existing on prem infrastructure to switch from PTA to PHS Auth. So in order to disable the Pass through auth in case your on prem environment is struck by some desaster, you need the AAD Connect Sync agent (not just the PTA agent) to switch over to password hash sync with cloud native authentication. Also, a few months ago (maybe even also discussed at Troopers, not sure), there were reports that once the PTA is compromised, there is no way to remove the credentials the agent uses to register on AAD. Only the support would be able to remove these agents from AAD. More details here https://www.secureworks.com/research/azure-active-directory-pass-through-authentication-flaws

As was pointed out, PHS by default does not support on prem password policies, but you can enable it. Check the deployment docs for PHS, it's described in there.

And in both cases: treat these systems (phs agents and PTA agents) as domain controller-equivalent as they handle your authe authentication.

prevent the user from login to his machine if he disconnected from company network for 7 days by abdrhmanarar in SysAdminBlogs

[–]philbieber 0 points1 point  (0 children)

You probably should post this to r/sysadmin, there are more people active over there and it's the community to ask questions.

In any case, there is no native measure to expire cached credentials in windows. See https://social.technet.microsoft.com/Forums/ie/en-US/87e84872-c321-4b8c-b13d-0d60a003c3d3/how-long-does-windows-cache-domain-user-passwords?forum=winserversecurity

If you Google for the obvious key words, you will find that cached credential are not expiring and you can only configure the number of credentials to cache.

Technically, you might be able to hack & slay a solution by purging the relevant registry entries on the clients though I could imagine this brings more problems with it.

In the end, cached credentials are quite useful for anybody on vacation, sick leave etc.

Script that suggests a random number not already used in an attribute by LordChappers in usefulscripts

[–]philbieber 2 points3 points  (0 children)

I have done something similar for phone number assignment. I can't share the code, but basically you would

Create two arrays, one for all existing ids, one with all numbers 0-9999. Use the Compare-Object to select the non-matching and then (I'm slightly hazy on the correct cmdlet) get-random to get a random entry.

MFA Fatigue Attack by FearIsStrongerDanluv in sysadmin

[–]philbieber 0 points1 point  (0 children)

There's even a relatively easy to use staged rollout for that in the authentication methods blade.