Jump to content

free780

Members
  • Posts

    3,614
  • Joined

  • Last visited

Everything posted by free780

  1. I think the fundamental issue is that some staff believe they are free lancers and that any content they have is owned by them regardless of how it was obtained. In reality the ownership of the data is the organisation they work for. This is why removable media is used for control of data and probably files copied from other organisations. If you don't prevent Dropbox or Google drive data will end up on personal accounts via policy or technical controls. Fundamentally the organisation needs to use Onedrive for Business or Google Drive and make it clear that you cannot take data with you when you leave the organisation.
  2. I wish they could just integrate it with AADConnect. I'm guessing larger organisations may have some mailboxes on prem and it can get quite complex to support mailboxes in the cloud and on prem.
  3. Annoyingly you are not supported to make changes to Exchange Attributes unless you have a hybrid exchange server. MS need to correct this as many orgs don't need on prem Exchange anymore.
  4. It's a big project to upgrade to a new version of exchange. You also may need on prem exchange for compliance reasons. You don't know which apps are using the existing servers. If the patches are kept up to date and some decent antimalware software is deployed the servers should suitably protected. You also are required to use exchange for some admin tasks even in a hybrid deployment. Ideally don't nt expose your exchange servers to the Internet if you don't need to. Not sure when Exchange 2013 is EOL though.
  5. How come people don’t use Microsoft’s built in Defender attack simulations? Adding the IPS to the Connection filter should override high confidence phishing. You can also use the tenant allow feature to allow a domain for 30 days. You can do this after you report an email is clean in threat explorer.
  6. Limited to 10 users per device unfortunately.
  7. Also be aware you don’t want to reverse changes to lessen security. Only administrators can now install print drivers if all defaults are kept.
  8. Make sure Microsoft 365 domains are not intercepted By SSL interception and ideally not proxied.
  9. I used winget to install Ubuntu the other day. No sure if you can push out a script to install iTunes. I’m guessing the intune/SCCM methods still work. You might need one of these setting up.
  10. You can use winget to install apps without using a Microsoft account.
  11. Just a nudge. This is the Server 2016 version. https://docs.microsoft.com/en-us/windows/release-health/status-windows-10-1607-and-windows-server-2016#2748msgdesc https://support.microsoft.com/en-gb/topic/november-14-2021-kb5008601-os-build-14393-4771-out-of-band-c8cd33ce-3d40-4853-bee4-a7cc943582b9 You may need to manually add this patch to your WSUS Server/manually install. If you use Azure App Proxy with Windows Authentication it breaks after your DC(s) have the November update with PAC errors. I believe its related to this. Other Apps that rely on on IWA may also be affected. https://support.microsoft.com/en-gb/topic/kb5008380-authentication-updates-cve-2021-42287-9dafac11-e0d0-4cb8-959a-143bd0201041
  12. You can use IE Enterprise mode with Edge which can use Java. However there are Java licensing requirements so be careful. I can’t believe Java is still in use in browsers.
  13. The November Windows updates have introduced some changes that will enforce in 2022. It might be worth checking for any impact on your environment.CVE-2021-26414 https://support.microsoft.com/en-gb/topic/kb5004442-manage-changes-for-windows-dcom-server-security-feature-bypass-cve-2021-26414-f1400b52-c141-43d2-941e-37ed901c769c Enforcement won’t be until Q2 2022. CVE-2021-42278 https://support.microsoft.com/en-us/topic/kb5008102-active-directory-security-accounts-manager-hardening-changes-cve-2021-42278-5975b463-4c95-45e1-831a-d120004e258e Enforced after November 2021 updates. CVE-2021-42287 https://support.microsoft.com/en-us/topic/kb5008380-authentication-updates-cve-2021-42287-9dafac11-e0d0-4cb8-959a-143bd0201041 Enforcement 12 July 2022. CVE-2021-42291 https://support.microsoft.com/en-us/topic/kb5008383-active-directory-permissions-updates-cve-2021-42291-536d5555-ffba-4248-a60e-d6cbc849cde1 Enforcement is scheduled for 12 April 2022.
      • 4
      • Thanks
  14. This was released this week. https://docs.microsoft.com/en-us/windows/release-health/status-windows-10-1607-and-windows-server-2016#2737msgdesc Dynamic Ports must be reachable by clients in order for printers to work.
  15. I watched the session from JISC. I can honestly see ISO27001 or a different compliance standard become the norm for education. The steps they described from a technical point of view are not too much work if you have AAD and A3/A5 configured. Yes it will annoy staff; however when your funding relies on CE compliance you have to comply. Given the threat landscape government bodies will put pressure on education to achieve CE and CE+ currently. The other area that will be difficult is monitoring personal devices that connect to a RDS gateway when not accessed via the Azure App Proxy. Limiting this for Staff to Staff Devices may be a way to mitigate this.
  16. Thinking about this further (FE and HE), MIS systems where staff and students login might got need some conditional access for each group. VLEs may be the same. This of course assumes you have all your authentication going through AzureAD. 1:1 isn’t strictly needed but I think it comes back to the remote working question for staff. I think a RDS gateway is the other way around it but I’m guessing the client device the user uses needs to be a supported OS with some sort of check. I guess the other option is to exclude personal devices from scope.
  17. We can’t forget the £900 apple monitor stand that looked like a cheese grater.
  18. Having gone through CE and CE+ this actually makes sense. Logically you must move to 1:1 devices for staff and limit business data apps to organisational owned devices. This can be done with conditional access polices and hybrid azure joined devices. Given the increase in Ransomware the backlash from staff can no longer be a block to a more secure environment.
  19. Is this the 11.4 version or something newer? Surely smart should test throughly on all supported versions of Windows 10 including those on release preview.
  20. Every org really needs Identity Protection now. Which requires P1/P2. Then you get SSPR anyway.
  21. I’ve read about people deploying applocker via PowerShell within intune.
  22. This is really useful for getting an understanding or having to explain the need for SPF,DKIM and DMARC to managers etc In larger organisations different departments will sign up for mailchimp etc and send spoofed email with no consideration of the security concerns.
  23. Wash your mouth out. This is exam software we are talking about. You need to configure GPP or some other bodge to point to a proxy it’s part of the “fun”.
  24. I found it depends on the printer driver and also if you map the printer in the user context. GPP User Context and PowerShell in the user context worked. However if you use the per machine Group Policy Printer connections the mapping fails. The Toshiba universal print driver doesn’t seem to like any method other than setting the registry setting to 0 which makes you vulnerable to attacks.
×
×
  • Create New...