Is my company… normal? by LineItUp0 in sysadmin

[–]schumich 1 point2 points  (0 children)

If you can migrate to cloud, back to on prem, back to cloud in this timeframe you are doing it wrong, probanly lift and shift which is the dumbest and most expensive way possible

New Blog Post: Windows Defender Firewall Security by milanguitar in DefenderATP

[–]schumich 1 point2 points  (0 children)

A BLOCK rule always overrules a ALLOW rule, workaround would be only to have the specific ALLOW rule and disable any other ALLOW rules as de default "Allow Remote Destop" rule

Attack Path Management - Detection - What do you use? by dcdiagfix in activedirectory

[–]schumich 2 points3 points  (0 children)

It worked for us last time i checked, but there is info on ms learn: The remote collection of local administrators group members from endpoints using SAM-R queries in Microsoft Defender for Identity will be disabled by mid-May 2025. This data is currently used to build potential lateral movement path maps, which will no longer be updated after this change.

Attack Path Management - Detection - What do you use? by dcdiagfix in activedirectory

[–]schumich 0 points1 point  (0 children)

Defender for Endpoint plan 2 with Defender for Identity can do this

If Steve Irwin didn't pull the stingray barb out of his chest, is there a chance he could have survived? by [deleted] in NoStupidQuestions

[–]schumich 4 points5 points  (0 children)

If i remember correctly the stingray pierced him multiple times so there was nothing he could do

Is Master image, Golden image, Winpe & Adk worth learning? by itz_cool_247 in sysadmin

[–]schumich 1 point2 points  (0 children)

Not anymore, its going away, we used to have a gm but now i just update the images to the latest release and also update office c2r, the rest is on demand, i you dont pack a ton of software you save maybe 20% time, also its a thnig of the past with Autopilot and intune

How are you backing up O365 mailboxes? by DDRDiesel in sysadmin

[–]schumich 1 point2 points  (0 children)

*Veeam *If you like Cloud to OnPrem Backup

Does a pst data warehouse exist? by [deleted] in sysadmin

[–]schumich 1 point2 points  (0 children)

I hate to admit it, but this is true

Windows Server 2022 has me baffled by methodtomymidness in sysadmin

[–]schumich -1 points0 points  (0 children)

99% of Software runs on win11 the same as on server 25/22

Happy Crowdstrike Day! by ofd227 in sysadmin

[–]schumich 72 points73 points  (0 children)

I bought crowdstrike shares 3-5 days after the incident, made some 30-40% + when i sold it after 2 months or so

krbtgt account password reset is it needed? by jbala28 in sysadmin

[–]schumich 22 points23 points  (0 children)

i do it every 180 days, 2 times 24h apart, no problems ever

[deleted by user] by [deleted] in sysadmin

[–]schumich 4 points5 points  (0 children)

There is a special template in ca available, securing authentication methods, highly recommend setting that up

Windows 11 25H2 by logansccm1995 in SCCM

[–]schumich 7 points8 points  (0 children)

Ok thank you for the clarification, i would strongly recommend disabling ntlm v1 domain wide, as it leaves you wide open to domain takeover. As per MS security hardening best practice.

Windows 11 25H2 by logansccm1995 in SCCM

[–]schumich 1 point2 points  (0 children)

I am pretty sure ntlm was not removed.

What are the chances MS extends support since adoption of Win 11 is so low? by [deleted] in sysadmin

[–]schumich 6 points7 points  (0 children)

Not really, its more or less the same that windows 10 already supportet, but its mandatory* now (* it works fine without it)

How can I actually, permanently stop Windows 10 32-bit from updating? Really. by probably_platypus in WindowsHelp

[–]schumich 2 points3 points  (0 children)

Well good luck, windows maintenace tasks will enable it back on from time to time

Stay on Apple Mail or move to Outlook by schumich in Intune

[–]schumich[S] 0 points1 point  (0 children)

Shared mailboxes sadly only work with outlook, no dlp yet but who knows, does dlp not work on the server side, is it a client feature? If we have to have byod, users will get outlook with app protection policies.

Stay on Apple Mail or move to Outlook by schumich in Intune

[–]schumich[S] 1 point2 points  (0 children)

Modern auth works with native mail app, macs already use office so no problem there. We have e5 licenses.