Jump to content

free780

Members
  • Posts

    3,614
  • Joined

  • Last visited

Everything posted by free780

  1. The question set has changed in January with further changes in Jan 2023 mainly MFA for all users not just admins.
  2. Cloud systems are now in scope. Many don't allow the controls that are required. SAML and/or MFA being the biggest issue. IP restrictions wouldn't be that hard to develop as a short term fix. I wonder if NCSC will have to re consider the requirements due to the lack of controls avaliable?
  3. Yes looks like a Chromium issue. https://bugs.chromium.org/p/chromium/issues/detail?id=1338586&q=extensions&can=2
  4. We started seeing this message this morning Edge ( Microsoft Edge 103.0.1264.37 ). We block all extensions except an allow list which allows LastPass and My Apps (Cyber Essentials and Auditors reasoning). The extensions work but I wondered if this is happening to anyone else. I've feedback to Microsoft.
  5. I guess for 1:1 you should have a compliance policy which prevents access to organisational data unless Windows is up to date. Shared devices should wake at night and update.
  6. Check Message Centre. Legacy auth is getting switched off in October. However SMTP is not being turned off for legacy auth. If you have unused protocols they may have already been disabled.
  7. It's to do with SPNs and Kerberos authentication. Users in Protected Users cannot use NTLM.
  8. According to IASME students are your customers so are not in scope. Ideally your customers should be on a seperate vlan etc. So unless you have lots of staff you basically need to enforce MDM for Staff personal phones and tablets. If you have 1:1 I'd just ban personal Windows and Mac.
  9. Check event viewer on the client. There is a Work Folders section. You can reset work folders for a user via a powershell command on the server.
  10. Yep works fine in Edge after the extension is installed. https://chrome.google.com/webstore/detail/gemalto-web-signer-for-ba/akfldeakecjegioiiajhpjpekomdjnmh/related The 30 days noticed for IE compatibility mode can be worked around with https://docs.microsoft.com/en-us/deployedge/edge-ie-mode-cloud-site-list-mgmt if you have any sites that need to be in IE mode.
  11. I do but gets interesting when someone has multiple monitors. Quick Assist also can struggle with multiple monitors.
  12. Really you need quite a few registry entries to force TLS 1.2 for client and server connections. Of course you need to make sure TLS 1.0/1.1 isn't in use anywhere.
  13. Thanks for all the replies. We are not using a cage. The early wake ups are probably just the time of year. I have vague memories of kids doing the same.
  14. Hi We've recently got a puppy. He's generally well behaved and my arm was twisted to get him. He wakes at 5am sometimes later. I'm a really light sleeper. He just naps throughout the day where as for me it's work/dad's taxi/DIY etc. Do other dog owners get woken up this early after the puppy stage? Sometimes I feel like a zombie when life isn't exactly quiet with 2 tweens and a dog.
  15. Is this a 100% on prem deployment with no mailboxes in the cloud?
  16. I think you can do some voodoo to have logins and a differential sync but actually the restriction is probably a good thing. You do need to be correctly licenced for FS Logix. You also need storage for all those profiles [emoji16].
  17. Have the students waited until the sync is complete?
  18. If you have intune/SCCM setup you can have the VPN config pushed out. Or you provide a very large route in the xml. 10.0.0.0/8 or similar There are some 3rd party GPOs you can buy to do the same thing. https://directaccess.richardhicks.com/2022/03/07/always-on-vpn-with-active-directory-group-policy/ .
  19. I never understood why micro USB wasn't the standard. Granted the grips become lose after a while.
  20. Have you got Google Workspace setup then if your not a M365 org? It's complex to setup as each org will have a different idP. It will be a right pain for someone to create Adobe accounts for each user. You can provision accounts using LDAP but you can only authenticate using SAML. ADFS might be an option.
  21. You have to delete the firewall rules via powershell script as a scheduled task. For Server 2016 there was a registry fix for RDS hosts. Clearly Windows 10 was/is aimed at 1:1 devices.
  22. There is a seperate Windows 10 product since 1903 I think.
  23. You can run a CLI to force updates on a scheduled task. https://helpx.adobe.com/enterprise/using/using-remote-update-manager.html The Creative Cloud Application keeps itself up to date even for standard users. There was an option when you create the deployment to force login via the default browser Edge/Chrome. It can be configured in a xml file. https://helpx.adobe.com/in/enterprise/using/customize-creative-cloud-app.html
  24. I spent the first 3 months of the year working on an IR plan. Phases are. Prepare Detect Contain Eradicate Recover You need leadership buy in and your leadership to give you a list of priorities. E.G Phones E-Mail MIS Then you need to draw up a list of dependencies. E.G Internet Access HyperVisor This is just for the containment phase. You have to think about containing ransomware if you can. Having some firewall rules that block all traffic in case you need to. Ideally having all you internal traffic flow through a firewall is best so you can isolate subnets/VLANs. You will need the authority to make the split second decisions to prevent a complete loss. E.G cut all internet access Each environment is different however. It’s probably best to audit all your services and what they require to function. You can then work out what can be isolated if need be. Of course you have to work out how your leadership will handle communication internally and externally so it is a whole organisation process.
×
×
  • Create New...