-
Posts
3,614 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by free780
-
I’d always use a FQDN. The fqdn will need to be in the SAN as well.
-
Android Managed Play Store - Available Apps Intune/MEM
free780 replied to free780's topic in Cloud Services
I don't have Google Workspace setup. Microsoft Support seem confused about it. There's some issues with Android 12 enrollment but this device is Android 11. I'll have to get some logs to send to support. -
Hi I can't seem to get available apps to show up in the Managed Play Store on a Personally owned Android Tablet (Samsung) enrolled (MDM into intune/MEM. This is using a Work Profile. Has anyone got this working? I have tried different combinations of assignment enrolled or enrolled and without enrolment. Quite happy for someone to say I've done something daft.
-
I'd read the release notes every patch Tuesday/Wednesday. https://support.microsoft.com/en-us/topic/april-12-2022-kb5012647-os-build-17763-2803-9a10c5c9-e65f-4ae1-a9c4-2db9a8eca4fc Release Health will also show issues. https://docs.microsoft.com/en-us/windows/release-health/status-windows-10-1809-and-windows-server-2019 Having a dev domain is a good idea to test updates. Also be aware that some updates require you to monitor event logs and an enforcement update may occur in the future. Reviewing MS SRC is useful.
-
I actually heard someone from Smoothwall say. Eventually every young person will have to decide if they click that link or not. They can’t be filtered for their whole life. If students have mobile phones they should be treated like an employee with a phone. You should not be on it all the time. I believe it’s a policy control rather than a technical control here. There is also the role of parents to know what children are accessing.
-
Doesn’t always work with the files on demand. DelProf2 running as the SYSTEM account should delete the profile correctly.
-
OMG. I started in IT in 2008 and was dealing with Java in IE for ECDL. They need to use a html 5 version its 2022 and all major browsers do not support it. You *may* be able to use IE mode in Edge but will have to keep Java up to date which is a pain.
-
SPF, DKIM and DMARC walkthrough and tester
free780 replied to TechMonkey's topic in Enterprise Software
Not done it yet. But would need to set a web server with inbound access in the DMZ. Its a shame that requirement is there as smaller organisations won't be able to implement it without a web server somewhere. -
Mainly because it's meant for 1:1 devices and technical confident users who can enroll their own device.
-
Probably something without a DNS A record.
-
Setting Acceptable User Policy - using 3rd party software
free780 replied to genesis's topic in Learning Network Manager
There is terms of use in Microsoft 365 Condional Access. It would only occur when login to 365 happens. -
Storm Dudley, Eunice & Franklin - How are you doing?
free780 replied to elsiegee40's topic in General Chat
-
Very much depends on what the mail is classed as: This is a balance between security and user choice. I think when just using EOP (No 365 Defender) you can set the Junk Mail as the destination which would fulfil the need. The worry is a e-mail that classed as spam could be phishing. Malware - Admin Only Quarantine Spam - Junk Mail High Confidence Spam - Junk Mail High Confidence Phishing - Admin Only Quarantine Bulk - No Action (User can mark as Junk)
-
Wordle 226 4/6 [emoji834][emoji834][emoji834][emoji834][emoji834] [emoji834]🟩[emoji834][emoji834][emoji834] [emoji834]🟩🟩🟩🟩 🟩🟩🟩🟩🟩 I was surprised how quick I got today's.
-
So the decisions in the series of patches concerning Print Nightmare would have been from a security perspective. It may be possibly to deploy drivers on machine leavel and use printui or powershell to map the printers. The main focus was remeidaiting the CVES. I may do some further testing as this is bound to come up again.
-
This isn't to do with the new Cyber Essentials requirements is it? Removing the ability to AAD register doesn't stop authentication in the browser. You can inflict MDM on personal devices or MAMWE. In an ideal world every user would have an organisational owned device but it's not ideal.
-
Should have MFA enforced when using a RDS Gateway.
-
Looks like MS have pulled the updates causing the issues. https://www.bleepingcomputer.com/news/microsoft/microsoft-pulls-new-windows-server-updates-due-to-critical-bugs/ It would be nice to get some official communication and if its fine to carry on patching Server 2016.
-
I do think this is a whole area (See Cyber Essentials post about BYOD) where management need to make it clear what is allowed and if necessary use technical controls. Rather than you can access organisational data on any device. Either you can with MDM/MAM controls or you don't have access. Equally there is the mental health, work/home life balance to strike. Worrying about issue x while reading work emails isn't helpful. If your expected to be on call then a organisational device should be issued.
-
Cyber Essentials - BYOD
free780 replied to georgeescott's topic in Data Protection & Information Handling
I did some work on Windows only in terms of personal devices. Just AAD Registered doesn't give the make,model of the device which is the CE requirement. A MAM-WE approach (Mobile Application Management Without Enrolment) can provide Windows Information Protection which can stop copy and paste of business data. However the Make and Model are not gathered. A MDM join sends the Make and Model to Intune satisfying the CE requirement. It may be easier to block access on Windows unless it's a organisational device. Possible if you have 1:1 devices for staff. You may be able to book access via conditional access and device filter after your IT department has got a record of the device. I imagine most departments won't have the staff to make this happen. There is also the issue of Remote Desktop Gateway which won't be subject to Condional Access policies if your not using the HTML5 rdp client. Mobile devices are more difficult. MAM -WE may gather more info on Android and IOS. You probably need to enforce the Intune app and Organisational versions of Outlook,Onedrive etc. I don't see any point reducing the scope as this will lessen security as a whole. I can't see funding getting away from the requirement and some other contracts are requiring it in FE/HE. Personal Devices are a risk from a data loss point of view as well. So probably disabling copy and paste and download from organisational apps is wise. There is also the issue of work life balance and having work emails on your phone can disrupt this. I imagine a lot of push back when schools/colleges/universities implement this. I wish we had budget to issue each staff member a phone and laptop (if role requires it). -
2 Week deadline under Cyber Essentials [emoji16] Why are people still running 2012 R2?
-
Ah but then you have the joy of Exchange updates [emoji1].
-
https://techcommunity.microsoft.com/t5/exchange-team-blog/basic-authentication-and-exchange-online-september-2021-update/ba-p/2772210 All suppliers should now move to use modern authentication (OAUTH) for IMAP/POP. Or you have to pay for an SMTP sending service or an on prem mail relay as others have said. In October legacy auth will start to be turned off for tenancies. If your a global admin you should get a monthly report of legacy auth use.
-
Hybrid Azure Devices and Other BYOD stuck on 'pending'
free780 replied to Warwick_Tech's topic in Cloud Services
Yep startup script or scheduled task. Each devices needs to leave AAD and then join again. Unless they are hybrid with SCCM and a VPN where you can push out a script to correct the issue. There is a attribute in powershell to filter the personal devices which might help next time.
