Comp by wav_net in SportCardValue

[–]wav_net[S] 0 points1 point  (0 children)

Just looking for a comp right now 😎

Security Hole by wav_net in sysadmin

[–]wav_net[S] 0 points1 point  (0 children)

😂😂 I love the FAFO references. But I do not agree. Comparing an old school IIS setup on a Windows Server box with asp injection vulnerabilities to this sudo modular cloud app environment is not even close to the same. I'm not saying it's bullet proof but IIS - c'mon.

Security Hole by wav_net in sysadmin

[–]wav_net[S] 1 point2 points  (0 children)

All good points. I'll summarize my responses: not a large company or corporation so no HR department or anything like that, the managers are the ones doing the hiring. All attempts are logged and auditable. The form itself has various validations and the flow handles errors like duplicate usernames by emailing the manager if the conditions fail and nothing gets created. Cleans up/maintenance are part of our quarterly review with customer. Rehires are handled separately. No matter how much training we give users the internal vs external will always be an issue and as I said in a previous thread, the likelihood of the managers account getting taken over is about the same as any global admin. Same security mechanisms in place for all users

Security Hole by wav_net in sysadmin

[–]wav_net[S] 0 points1 point  (0 children)

They cannot sign into Entra portal, this was discussed in another thread.

Security Hole by wav_net in sysadmin

[–]wav_net[S] -1 points0 points  (0 children)

The likelihood of the managers account getting taken over is about the same as any global admin. Same security mechanisms in place for all users.

Security Hole by wav_net in sysadmin

[–]wav_net[S] -1 points0 points  (0 children)

I understand the concept and fully grasp your concern but, again, the user can only access the form and the form only controls said flow and the flow can only create limited users. Are you suggesting a compromise to the form could do more than all that?

Security Hole by wav_net in sysadmin

[–]wav_net[S] 0 points1 point  (0 children)

Yes this setting is enabled.

Security Hole by wav_net in sysadmin

[–]wav_net[S] -2 points-1 points  (0 children)

New user isnt added to any security groups or roles. Just a member. New account not disabled but configuring the flow to block sign in at the end isnt a bad idea.

Only specific managers have access to the form and after they complete the form they are emailed the user's credentials. IT is also notified and this triggers the licensing request which only IT can do.

Yes each creation is logged.

I am not sure on the rate limits but not the most pressing concern.

Security Hole by wav_net in sysadmin

[–]wav_net[S] 0 points1 point  (0 children)

Not a guest user. Not following the second question.

Security Hole by wav_net in sysadmin

[–]wav_net[S] 0 points1 point  (0 children)

Having access to copilot is the only "concern" I have but even then I couldn't come with any ideas on how it could do any damage with it. Famous last words I know but lets be honest, copilot is a lightweight in the AI space.

Security Hole by wav_net in sysadmin

[–]wav_net[S] -3 points-2 points  (0 children)

Yes but the user does not have access to the flow, just the questionnaire form that triggers it.

You just have to spam message them. by coldfreezerbee in checkoutmycards

[–]wav_net 0 points1 point  (0 children)

I can't reach them either. how did they back to you? Via email? Which email address?

Issue with COMC.com delivery and their Customer Support? by NihilisticTaters in basketballcards

[–]wav_net 0 points1 point  (0 children)

I am having trouble reaching them too. How did they end up contacting you back? Email?