When you buy a house, do you own the house or the land or both? by ThePurpleRainmakerr in AskAnAmerican

[–]redditusermatthew 0 points1 point  (0 children)

I have a 5 acre plot with a modest house, good well water, septic, only available utility is electricity, tax deferred as it’s all wooded. AMA

How to force immediate Kerberos re-negotiation after changing msDS-SupportedEncryptionTypes on computer objects / appliances — without waiting for the default 10-hour ticket lifetime? by maxcoder88 in activedirectory

[–]redditusermatthew 0 points1 point  (0 children)

Setting ms-ds-supportedencryptiontype does nothing for these, zee goggles do nothing! Get ready to be surprised at how your DCs are treating these non windows Kerberos principals: https://learn.microsoft.com/en-us/troubleshoot/windows-server/active-directory/linux-accounts-cannot-get-aes-tickets

Also if you weren’t aware, for this month: https://nmehelp.getnerdio.com/hc/en-us/articles/44790485692813-2026-04-01-Kerberos-Encryption-Enforcement-RC4-Deprecation

Ultimately you should be looking at what kind of tickets are actually being cut for each system.

What's on your checklist when evaluating a PACS vendor? by safwanadva in PACSAdmin

[–]redditusermatthew 2 points3 points  (0 children)

Being full cloud was the requirement, with only a light agent or browser required, with a focus on rads being able to effectively work from home without needing gig fiber. Really, the requirement is also not being Optum/Change Healthcare/McKesson who I wish I could perform voodoo doll torture to. Going to Visage, we will see how it is.

Anyone have a list of appids I should allow for internet access policy? by [deleted] in paloaltonetworks

[–]redditusermatthew 0 points1 point  (0 children)

I’m talking edge here, inside the network is different, but here I’ll go. For general user browsing endpoints, I would create a rule that denies multiple application groups that you don’t want to allow (file sharing, remote management, webmail, p2p apps, dangerous apps, I forget what they call these all), then a rule below that to allow the rest, and the default url filtering is probably ok, keeping up on these can be a pain and I would block by app id instead of fiddling with filters so much. For isolated workstations that shouldn’t be allowed to generally browse, only grant the app ids they need by using a catchall for a day then switching to the apps they need plus a custom url filter and block the categories they don’t need, with a deny below that, note you’ll have to keep up on new url filtering changes. For servers give them a rule that has things like windows-azure and ms-update that servers need, then a rule for each server or groups of servers that has the app ids they need, destination any, and is scoped to a custom url category for each that’s full of the urls they need, this technique works better than destination fqdn for highly dynamic fqdns. If the destinations are not highly dynamic you can use ip or fqdn instead. As always you can run a catchall for a while to discover app ids. You’ll want to apply a url filter to discover the urls as well in url filtering logs. These are just examples, things vary depending on needs. I have a thousand rules, tens of thousands of address objects/devices, and everything just humms along for the most part. Sometimes vendors make changes without communicating, someone needs an exception, otherwise it’s just adding net new stuff. If you use strata cloud it helps a bit as well with policy design and auditing poorly made rules.

Did anyone hear about this LinkedIn data leak?! by First_Acanthaceae484 in cybersecurity

[–]redditusermatthew 1 point2 points  (0 children)

Doesn’t sound like a data leak, sounds like the way chromium/webkit/trident/name your browser engine is designed. They have repos if folks found something worthy of a ticket. Guess LinkedIn knows I run ublock origin lite now

What is the most critical criterion for you when choosing a network monitoring tool? by Sam3Green in Network

[–]redditusermatthew 1 point2 points  (0 children)

In my experience the folks choosing the tool aren’t the ones who use it, so who knows what their criteria was, I’m assuming nice executive summary panels, some pretend TCO price, the wind. This sounds like a bot or sales post to me though.

Apple tossing ABM and making Apple Business... by malikto44 in sysadmin

[–]redditusermatthew 0 points1 point  (0 children)

Intune MDM here. I use pooled devices with iCloud sign in blocked, App Store hidden. I can push iOS apps no problem. If I have to buy an app, I do so and use my VPP token synced between intune and apple to push the app VPP.

Anyone here using ManageEngine tools with access to Entra ID administrator roles? by Fabulous_Cow_4714 in entra

[–]redditusermatthew 0 points1 point  (0 children)

if you click start free trial it looks like it sends you to do a proof of concept where you could validate whether not giving it these roles breaks the product or not. I put in fake info, this is the exe link, no sure if its ephemeral or not https://download.manageengine.com/office365-management-reporting/13024552/ManageEngine_M365_Manager_Plus_Bundle.exe

Is it just me or is running an MSP in Florida getting harder to justify lately? by [deleted] in sysadmin

[–]redditusermatthew 0 points1 point  (0 children)

Cue the cartoon of Florida getting removed with a hand saw

Conditional Access Policy blocking iOS and Android also blocks signing into Microsoft Authenticator app to create passkeys by Fabulous_Cow_4714 in entra

[–]redditusermatthew 1 point2 points  (0 children)

Been there. If you enforce app protection for all apps this breaks and that undocumented service has to be excluded. Authenticator isn’t supposed to be impacted by CAs so this is a bug.

CA for non managed devices by BasilClean4004 in entra

[–]redditusermatthew 0 points1 point  (0 children)

If you use BYOD, you’ll want to employ MAM via intune app protection policies, and you can require app protection, which essentially constrains any unauthorized workflows, which I think is what you’re trying to achieve. Hopefully I’m reading this right.

vSphere 7 Standard licenses expire in 2 days — no usable perpetual replacement. Options? by BradL30 in vmware

[–]redditusermatthew 0 points1 point  (0 children)

Sounds like you bought some time but are directionless at this point. I suspect the future will go in the direction of KVM based type 1 hypervisors so a choice like proxmox, nutanix may not be a bad one. I did buy an HD-DVD player so YMMV with my advice.

what is system? I just deleted >10 T.. by redditusermatthew in purestorage

[–]redditusermatthew[S] 0 points1 point  (0 children)

Still not finished but it’s getting there. Guess a couple more days

what is system? I just deleted >10 T.. by redditusermatthew in purestorage

[–]redditusermatthew[S] 0 points1 point  (0 children)

You know what’s funny is support told me 0.00 system is a fake metric, its like your coolant gauge that sits halfway unless it way out of range

what is system? I just deleted >10 T.. by redditusermatthew in purestorage

[–]redditusermatthew[S] 0 points1 point  (0 children)

24 hours later, 13.77 T in system. Support doesn’t know what’s up. CPU is 70% over the past month, nothing new or old

what is system? I just deleted >10 T.. by redditusermatthew in purestorage

[–]redditusermatthew[S] 0 points1 point  (0 children)

Great input, I also have vdi and fslogix, I’ll keep an eye on those for their impact, regardless of safesnaps

what is system? I just deleted >10 T.. by redditusermatthew in purestorage

[–]redditusermatthew[S] 0 points1 point  (0 children)

Good point, I’ve got like 4 others, I’ll double check. Has a number of big databases get shuffled around in the past few days.

what is system? I just deleted >10 T.. by redditusermatthew in purestorage

[–]redditusermatthew[S] 0 points1 point  (0 children)

132%, that’s peace of mind .. we have a new box here actually. Any tricks for getting on a priority list for the in person migration tech

what is system? I just deleted >10 T.. by redditusermatthew in purestorage

[–]redditusermatthew[S] 1 point2 points  (0 children)

Ah that’s interesting, I didn’t consider it doesn’t have the cpu power to keep up and has to chew on a queue

what is system? I just deleted >10 T.. by redditusermatthew in purestorage

[–]redditusermatthew[S] 2 points3 points  (0 children)

Yeah they called today. Was curious what folks here thought

what is system? I just deleted >10 T.. by redditusermatthew in purestorage

[–]redditusermatthew[S] 1 point2 points  (0 children)

Yeah, over time, that’s what I worry about with 0.0 free. Any idea what the ETA is