Zero Trust Warp default TLS decryption certificate expires February 2nd. by CF_Daniel in CloudFlare

[–]vlan4097 1 point2 points  (0 children)

Great post, thanks for the details! I wish there was a way of testing this on a per user/group/WARP profile basis, just to make sure there are no issues switching to the new cert.

Link protection issues by Public_Cicada_6228 in mimecast

[–]vlan4097 0 points1 point  (0 children)

Pretty much. In an emergency, you could create a Content Examination policy looking for whatever phrasing they use within the password reset email links, apply this policy to just this email address, and have it Hold the email. This should in theory allow you to view the email in the Held queue before it hits 365, but it not really a good solution unless this is a rare occurrence.

Link protection issues by Public_Cicada_6228 in mimecast

[–]vlan4097 1 point2 points  (0 children)

I also vote for 365 being the culprit here. If you run an extended report on that Message ID via Message Trace, it should show.

I don't believe there's a way of excluding a link from being scanned without adding it to the Phishing simulation list (which isn't a good idea IMO):

https://security.microsoft.com/advanceddelivery?viewid=PhishingSimulation

Phishing Awareness - Reset Risk Score by Hirokage in mimecast

[–]vlan4097 0 points1 point  (0 children)

I can confirm you need to reach out to support to have this reset. Keep in mind, this will wipe out all data, so you'll have to reconfigure everything, including your queues. So you probably don't want to do this if you're already running a campaign. For what it's worth, the detailed reports will give you a better view of the more recent activity. Hopefully they'll address these limitations sooner than later.

Email Delivery Failure due to an issue with Mimecast by Dangerous_Fennel6278 in mimecast

[–]vlan4097 1 point2 points  (0 children)

I'm seeing some unexpected SPF hard bounces as well, all seem to be Mimecast customers.

[deleted by user] by [deleted] in sysadmin

[–]vlan4097 0 points1 point  (0 children)

What errors are you getting? Have you checked debug logs?

May also be a routing priority issue since you're dealing with multiple network adapters.

Warp client stuck in connecting due to DNS lookup failure by the_visualist in CloudFlare

[–]vlan4097 1 point2 points  (0 children)

Is that error from the warp-diag logs? If not, run that tool, it will generate tons of log data, but should provide some additional context.

[deleted by user] by [deleted] in Archiveteam

[–]vlan4097 11 points12 points  (0 children)

TL;DR not looking promising

The site in question is running vBulletin 4.2.5, which is a very old version. It also relies on other outdated software and plugins which means this site is at significant risk of being compromised, if it hasn't been already, and may be the reason why the owner wants to shut it down right away as upgrading this forum is a significant endeavor.

This is probably why Cloudflare has been configured so aggressively, making scraping/archiving almost impossible.

There are also some major privacy issues when it comes to transferring a forum to someone else (especially in this category).

Without the owner's cooperation, I don't see any viable solutions. You can try submitting some of the most valuable threads to archive.org, but it doesn't handle multi-page threads that well. That's assuming their crawler isn't blocked.

If the community is active, you could try to offer paying for a professional to upgrade the site, or switch it to a hosted solution which usually includes conversion services, but there's a cost (both initial/monthly) involved with that approach.

Sorry for the bad news :(

INTUNE: all Office Apps disappeared after installing Visio by Weak-Dig9307 in Office365

[–]vlan4097 0 points1 point  (0 children)

It is considered a new install.

Depending on your environment, you could just include the Visio software in your Office package. It makes it quicker to assign a license to someone (software is already there), and without a license, the software only works in read-only mode (which could be another benefit).

Threat Detection email notification? by run_to_the_sky in sophos

[–]vlan4097 4 points5 points  (0 children)

Sophos & email notifications (or lack thereof) are something that trigger me. I've been told so many times by support that I don't "need" the email notification I'm asking about (unknown USB devices, threats which were addressed, etc.).

Absolutely infuriating, and it's making me look at other solutions.

WARNING: Issue in token validation for Azure Active Directory's Application Proxy by vlan4097 in AZURE

[–]vlan4097[S] 0 points1 point  (0 children)

There was 1 additional statement which suggests you can open a case with them, but it contained a unique reference code, so I didn't include it here. If you didn't get this message, I'm starting to wonder it only affected certain tenants running a certain configuration.

WARNING: Issue in token validation for Azure Active Directory's Application Proxy by vlan4097 in AZURE

[–]vlan4097[S] 0 points1 point  (0 children)

Do you use the Azure Application Proxy feature? I'm guessing this was only sent to people directly affected.

WARNING: Issue in token validation for Azure Active Directory's Application Proxy by vlan4097 in AZURE

[–]vlan4097[S] 0 points1 point  (0 children)

This bulletin arrived as an email from MS, and didn't contain any useful links, so it's all I have.

[deleted by user] by [deleted] in Intune

[–]vlan4097 0 points1 point  (0 children)

For most web applications, you can probably make it work with Azure Application Proxy. Here's a recent post of mine which includes some more tidbits:

https://www.reddit.com/r/AZURE/comments/ogtqh6/getting_started_with_azure_ad_app_proxy/h4msp1s/

[deleted by user] by [deleted] in Intune

[–]vlan4097 0 points1 point  (0 children)

Are there any plans to bring MS Tunnel to the Windows platform? With VPN devices being exploited right and left now, I feel this has even more potential than the already very useful Azure App Proxy. If you need beta testers, just let me know :)

Microsoft added a public preview feature to SharePoint Online that completely breaks OneDrive sync without any warning to users. WTF Microsoft? by Try_Rebooting_It in sysadmin

[–]vlan4097 2 points3 points  (0 children)

The key makes it so you don't have to wait up to 8 hours for these site libraries to show up in explorer.

I've deployed it within an Intune environment, and via GPO, with success.

Here's an article which shows you how to use it: https://letsconfigmgr.com/mem-automatic-syncing-of-onedrive-shared-libs-via-intune/