theo_logical Posted November 7, 2017 Posted November 7, 2017 A few days ago I configured a remote apps server, it works brilliantly internally and externally. It's very early days and I intended to use Microsoft's grace period while SLT had a bit of a play before we agreed to buy licenses and an SSL certificate. But I was amazed to see how some idiot with too much time found their way in to my server and leave me a message offering the chance to buy bitcoins for them, or something like that. B*rst*ds! So my question is, what is the best way to secure this server, is an SSL certificate the only and best way, along with secure credentials, or can I do more. Right now I'm a little nervous I can easily spin up another VM but how long will it last and how much more damage can they do? Thanks
free780 Posted November 7, 2017 Posted November 7, 2017 If you pay for Azure App Proxy you can enable 2 factor authentication.
TwistedHelixis Posted November 8, 2017 Posted November 8, 2017 You can have it only accept access from domain joined computers, specific user groups, based on a specific certificate to name but a few.
Steve21 Posted November 8, 2017 Posted November 8, 2017 I mean there shouldn't be a way an external person can connect at all unless you either changed to allow anonymous settings etc, or you have an account with a very simple password If you look in the logs on the server what account was used to login to it? I'm assuming you're using the standard webform login? Steve
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now