Jump to content

free780

Members
  • Posts

    3,614
  • Joined

  • Last visited

Everything posted by free780

  1. Don’t share credentials. Particularly for global admin! Can you not get FIDO2 key for each tech which can be used for multiple accounts? More secure than voice,sms and app.
  2. Out of Tune does seem to be slow. Only using it to push VPN configs via custom XML. On win 10 seems fine. But in Win11 there seems to be numerous issues. You have to delete remnants of a VPN to amend a ccnfig. I might look at using PowerShell scripts and a scheduled task. Seems a lot of work just to push VPN configs. Don’t want to use MECM which relies on VPN connectivity. We had an issue where out of tune wouldn’t recognise some user licenses. It took 5 months to get resolved. As for Microsoft now splitting some features as separate licences seems greedy. Having no GPP or secpol is also an issue. GPO and MECM work well and you can find lots of logs to sort out issues.
  3. Isn’t the fundamental issue you need to SSL inspect all traffic to correctly do this? Of course apps like YouTube may break and require exceptions. Would the filtering be effective?
  4. Or just require Hybrid Joined device for Windows/Mac. App Protection for iOS/Android. CE compliant as well.
  5. MS state mailbox creation could take up to 24 hours. People still fire emails to accounts just created like we are back in the on prem days.
  6. I managed to configure a dialup VPN a Fortigate which works with the Windows client. Generally been more reliable than RRAS. Win11 seems to do some random disconnect/reconnect. I think it’s due to Intune rather than the VPN.
  7. There always promox,nutanix,kvm. Just make sure you pay for support.
  8. Maybe Google are starting to enforce the changes for 1st February. https://support.google.com/a/answer/14229414?hl=en I’m surprised there hasn’t been more noise about these changes. It’s quite easy to exceed 5000 emails from a domain in a day. You need SPF and DKIM setup for authentication. You only need alignment for either SPF or DKIM. I would comply with the criteria for 5000+ senders even if it never happens. There is also a move to require p=quarantine and p=reject in the future. I wouldn’t be surprised if there are mail delivery issues to consumer gmail and yahoo accounts in the coming weeks.
  9. The licencing requirements may be a barrier. https://learn.microsoft.com/en-us/microsoft-365-copilot/microsoft-365-copilot-requirements#license-requirements
  10. If they are able to steal a token. They may find a remote access system and gain access. This access may be sold on the dark web. The phishing may just propagate to contacts.
  11. There has been a store app for ages.
  12. You can just use the web client. Other than that use the new client from the ms store.
  13. Can you force Creative cloud auth to the browser. Users still need to enter the domain of their UPN or their UPN but if Edge/Chrome is setup for SSO it might take some pain away.
  14. So not Organised Crime Gang Not line of Duty.
  15. https://beta.jisc.ac.uk/janet/issues Quite a few orgs switched to Cloudflare or Google as a quick workaround.
  16. There is an issue with Edge if it’s below v118 creating multiple shortcuts with OneDrive. Not sure if it’s the same issue.
  17. Anything to do with this. https://support.sophos.com/support/s/article/KB-000045741?language=en_US
  18. I've seen the same with Work Folders. Tried deleting the work fodlers database on the client and running the powershell repair commnad on the server. Still occurs. I can't replicate either. All I can think it s a bug introduced at some point in Edges release history and when the profile was created. Next step is probably to ask the user to delete their Edge profile and the shortcuts and re-create.
  19. There’s also the privacy concerns. You’ll find a lot of sites will not function correctly with SSL Interception enabled E.G Banking. Yes there is risk of malicious content being reachable. I think Android will constantly tell the use that a MITM cert is in use.
  20. Type sysdm.cpl in the run box/cmd/powershell . Works on everything from XP onwards. Might need to prefix with a & in PowerShell.
  21. If you do retire the server / migrate to server 2022 and exchange 2019 (or newer) just check the server 2012 isn’t being used as a mail relay. You’ll need to point any services to the new server or see if they can authenticate to 365 directly.
  22. I wonder if this breach is repeated to the capita beech?
  23. Don't put you Veeam Server(s) on the same doamin as your production domain! In case you get Ransomwared! Either standalone or a seperate AD domain.
  24. Unless it’s the MAM for Windows that requires Edge. Stops you copying and pasting from Edge etc.
×
×
  • Create New...