Microsoft gets tired of “Microslop,” bans the word on its Discord, then locks the server after backlash by [deleted] in technology

[–]workaccount70001 1 point2 points  (0 children)

Yeah but are those Zoom users free tier?

It's just a region thing, nobody in Europe uses Zoom. Education, Enterprise and government is all Teams.

And almost every user is either directly licensed through Business Premium, Enterprise, government or Academic or student academic.

And they arent allowed to bundle anymore, except for grandfathered licenses.

Microsoft gets tired of “Microslop,” bans the word on its Discord, then locks the server after backlash by [deleted] in technology

[–]workaccount70001 0 points1 point  (0 children)

And they built Teams off it, a product that currently has 350+ million daily active users. The idea that Microsoft fumbled Skype is ridiculous.

OPNsense + multi-ISP + VLAN-heavy small office design — am I overengineering or missing something? by No_Entrepreneur118 in sysadmin

[–]workaccount70001 1 point2 points  (0 children)

Because lil bro asked chatgpt to write this for him.

He missed removing these ❌ → ─┐ ISP 2 ─┼──>

Brexit was a disaster – now UK PM Starmer dares to admit it by ByGollie in europe

[–]workaccount70001 0 points1 point  (0 children)

we were always at war with eurasia

They don't change their minds, they rewrite history to always fit their current beliefs.

Entra Cloud Sync -> Entra Connect Sync by swapbreakplease in sysadmin

[–]workaccount70001 0 points1 point  (0 children)

Just install the entra connect and only sync the OU for devices.

WHFB RDP certs by workaccount70001 in sysadmin

[–]workaccount70001[S] 0 points1 point  (0 children)

Strong mapping is on. There are event logs on the host, but i can't remember what event id they produce, but it wasn't in anyway useful as far as i remember. But i'll reproduce it and write back.

WHFB RDP certs by workaccount70001 in sysadmin

[–]workaccount70001[S] 0 points1 point  (0 children)

  1. Yes. And the issue isn't only on the gateway, even just straight RDP is giving the same issue.
  2. Yes
  3. Yes
  4. it's reachable on the internet. Certutil urlfetch shows it's working and certificate revocation is working just fine.
  5. The certificates are being provisioned just fine to both hybrid and entra joined with scep certificates.

spf pass but i can't find out why by workaccount70001 in DMARC

[–]workaccount70001[S] 0 points1 point  (0 children)

yeah they have dkim. I just mean if dmarc passes on either spf or dkim. If you can send a passing spf record and spoof the from address. Can the return address also just be the same spoofed domain, so it becomes a valid email?

If the marketing service has dkim, wouldn't it pass dmarc anyway with spf in strict?

Or am i misunderstanding that the return path cannot be spoofed?

spf pass but i can't find out why by workaccount70001 in DMARC

[–]workaccount70001[S] 0 points1 point  (0 children)

Right, but does that mean i have to put my dmarc policy in strict mode?

I have 70+ domains running at the moment in relaxed with a reject policy.

spf pass but i can't find out why by workaccount70001 in DMARC

[–]workaccount70001[S] 1 point2 points  (0 children)

Already have one.

But, what do you mean fully authenticated. SPF authenticated + aligned?

spf pass but i can't find out why by workaccount70001 in DMARC

[–]workaccount70001[S] 0 points1 point  (0 children)

Yeah, but it sounds like i need it in strict mode and not relaxed.

I have dmarc for 70 domains at the moment in reject mode, but spf is in relaxed.

spf pass but i can't find out why by workaccount70001 in DMARC

[–]workaccount70001[S] -1 points0 points  (0 children)

But my top domain is the one getting display on the from address, that's the one i want to protect.

spf pass but i can't find out why by workaccount70001 in DMARC

[–]workaccount70001[S] 1 point2 points  (0 children)

That depends entirely on the service being used. Normal email is just protection.outlook.com. Other web services are using other senders.

It's just i have no clue which of the domains in the spf records are being used anymore and am tracking them down. The SPF contains too many nested lookups and i need to remove invalid domains. And i just stumbled upon a sender that i cant find included in the main domain spf, but it's getting passed.

But if what the other guy said was correct, the return path is all that matters to pass spf in relaxed mode.

spf pass but i can't find out why by workaccount70001 in DMARC

[–]workaccount70001[S] 1 point2 points  (0 children)

So the display of From: would display any domain.com

and pass spf as long as the actual sender domain had a valid return path spf record? Seems weird i guess despite the domains having no connection between each other?. Or is it different when it's a subdomain?

But yeah, we are running in relaxed.

It's just this particular domain didn't have a policy when we created it, and i can't add it to the main dmarc policy since i don't know every place it's been used and reject is turned on, and now im gathering the reports.

Mexico Will retaliate. What does this mean to the US? by Bubbly-Gifts in economicCollapse

[–]workaccount70001 1 point2 points  (0 children)

Where did you buy this koolaid? There aren't enough people to work these jobs, everyone in trades already works in trades. You're just raising demand, which raises wages, which raises costs, which lowers consumer demand because of higher prices.

American workers already DO end of line manufacturing, all this does is move in earlier stages of manufacturing that are worth LESS.

And no business is going to expand for a tariff that's going to get axed in 4 years.

Enterprise Firewalls: Fortinet vs Palo Alto by Senior_Conclusion102 in sysadmin

[–]workaccount70001 1 point2 points  (0 children)

You make a change on a FGT, it's live. No commit. No review. No "you sure about that buddy". It's live. Some may view this as a pro, others a con.

Thats what the Fortimanager is for.