twheether's profile picture. 'We don't work on weekends'
- No Threat Actor ever

#CyberSec | Digital First Aider https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen

TheRRK

@twheether

'We don't work on weekends' - No Threat Actor ever #CyberSec | Digital First Aider https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen

How is the AzureAD PowerShell Module still a thing in @azuread supplied scripts? Let admins with Passkey-only authentication use Get-WindowsAutopilotInfo.ps1? Get lost! It's devastating how slowly GraphAPI is adopted, even when the alternatives are deprecated - esp. on MS side


TheRRK reposted

Good news from Microsoft 365 / Entra ID. Seems that MC718260 (mc.merill.net/message/MC7182…) is rolling out! Up until now, FIDO2(passkeys) where not supported for interrupt wizard. So if you enforce passkeys with Conditional Access Authentication strengths, and the user has not…

janbakker_'s tweet image. Good news from Microsoft 365 / Entra ID.

Seems that MC718260 (mc.merill.net/message/MC7182…) is rolling out!

Up until now, FIDO2(passkeys) where not supported for interrupt wizard. So if you enforce passkeys with Conditional Access Authentication strengths, and the user has not…

TheRRK reposted

Autopilot v2 🚀 The latest update to Autopilot is impressive. Now, there's no need to upload Hardware Hashes. Instead, you can simply assign the Autopilot Preparation Profile to a user, and the Autopilot Profile will automatically download after the user signs in. There are…


TheRRK reposted

My friends at @MicrosoftPress have given me a couple of copies of the eBook for The Definitive Guide to KQL to give away. Retweet or comment below and I will put you in the draw. To give everyone a chance, I will give it 48 hours and then draw two winners. aka.ms/KQLMSPress/Sto…


TheRRK reposted

If you've been holding off changing MDE connectivity to the new streamlined method, now is the time! 🔥 I can't tell you how many random networking issues this has resolved for various clients. Say "No" to giving poor network engineers a list of 26 DNS names and IP ranges :)

ANNOUNCING general availability!!! Microsoft Defender for Endpoint streamlined connectivity consolidates service URLs and provides IP ranges, for use in a variety of network scenarios. learn.microsoft.com/defender-endpo…



TheRRK reposted

👏 Folks! Provisioning security groups from Entra ID to on-prem AD just went GA! 🤩 With this, you can move to a cloud-first approach to managing groups in Entra ID while allowing on-prem apps to continue working. Even better, you can use ID Governance to govern access to…

merill's tweet image. 👏 Folks! Provisioning security groups from Entra ID to on-prem AD just went GA! 🤩

With this, you can move to a cloud-first approach to managing groups in Entra ID while allowing on-prem apps to continue working.

Even better, you can use ID Governance to govern access to…

Use Entra ID Governance to govern your AD based (Kerberos) on-premises apps by using cloud security groups that are provisioned to AD with Microsoft Entra Cloud Sync. This capability is now GA! #Cloudsync learn.microsoft.com/entra/identity…



TheRRK reposted

💻 Intune Offboarding v2 ▶️ Automate the offboarding of your devices in Intune, EntraID and Autopilot. ▶️ Run Playbooks e.g. List all Stale Devices, List all Devices with a End-of-Life OS Version and also List all Devices that you have in Autopilot but not in Intune ▶️ A…

UgurKocDe's tweet image. 💻 Intune Offboarding v2

▶️ Automate the offboarding of your devices in Intune, EntraID and Autopilot. 
▶️ Run Playbooks e.g. List all Stale Devices, List all Devices with a End-of-Life OS Version and also List all Devices that you have in Autopilot but not in Intune
▶️ A…

TheRRK reposted

Sad to see the creation of new free M365 dev tenants going away. Read this post for details: devblogs.microsoft.com/microsoft365de… If this impacts you please join the Research panel and help shape the future of the M365 dev program. ux.microsoft.com/Panel/M365Devs…

merill's tweet image. Sad to see the creation of new free M365 dev tenants going away. 

Read this post for details: devblogs.microsoft.com/microsoft365de… 

If this impacts you please join the Research panel and help shape the future of the M365 dev program.
 
ux.microsoft.com/Panel/M365Devs…

TheRRK reposted

If you don't encrypt your data with a quantum-secure algorithm, an attacker who steals your data now will be able to decrypt it in as soon as a decade. See our threat model for this and other post-quantum cryptography risks. bughunters.google.com/blog/510874798…


TheRRK reposted

Beginning February 1st, any email you send to Gmail or Yahoo must have SPF and DKIM. Failure to do so may result in delivery delays. Then in April, a % of emails will begin to be rejected. If you send > 5,000 emails then you must have a DMARC Record. sendgrid.com/en-us/blog/gma…


TheRRK reposted

A privilege escalation flaw has been found, and is being actively exploited, in Atlassian Confluence, and has been assigned a bug alert severity of 'very high'. Atlassian recommends removing installations from the Intern... bugalert.org/content/notice… #BugAlertNotice


TheRRK reposted

🚨 Wow. Imagine waking up, and your entire company's online presence is erased. Email. Domain. Documents. Databases. Gone Poof. Well, that's what happened to customers of two hosting providers this week. 👇


TheRRK reposted

Powerful The true dangers of sharing content online. The people that figures out how to combat this will become billionaires.


TheRRK reposted

Azure AD now supports FIDO2 Security keys on Safari on iOS! 🤯 Still no support for the embedded browser from what I can tell, but some apps, such as Microsoft Authenticator, now support device login (details and video in second post)


TheRRK reposted

I was, unfortunately, reminded today that not everyone is using Cost anomaly alerts for their Azure subscriptions These alerts are completely free, but you have to enable them. Please set this up to avoid unexpected bills due to attackers or accidents :( learn.microsoft.com/en-us/azure/co…

NathanMcNulty's tweet image. I was, unfortunately, reminded today that not everyone is using Cost anomaly alerts for their Azure subscriptions

These alerts are completely free, but you have to enable them. Please set this up to avoid unexpected bills due to attackers or accidents :(

learn.microsoft.com/en-us/azure/co…

TheRRK reposted

🧵👇🏾

merill's tweet image. 🧵👇🏾

TheRRK reposted

Looking to get started in Pentesting? Our Practical Ethical Hacking course is THE foundational course to take. We're currently offering the course for FREE! People over profits. We believe in affordable education. The sale ends 4/19/2023 at 11:59pm EST academy.tcm-sec.com/p/practical-et…

TCMSecurity's tweet image. Looking to get started in Pentesting? Our Practical Ethical Hacking course is THE foundational course to take. We're currently offering the course for FREE! 

People over profits. We believe in affordable education.

The sale ends 4/19/2023 at 11:59pm EST

academy.tcm-sec.com/p/practical-et…

TheRRK reposted

Introducing the Living Off The Land Drivers (LOLDrivers) project, a crucial resource that consolidates vulnerable and malicious drivers in one place to streamline research and analysis. loldrivers.io LOLDrivers enhances awareness of driver-related security risks and…


Loading...

Something went wrong.


Something went wrong.