ChatGPT allegedly shares your chat query topics, user IDs, and email addresses with Google and Meta, according to a new class action lawsuit filed today.
PSA: Do NOT use Windows Server 2025 as the schema master before installing Exchange Server SE RTM. The Windows Server team is working on a permanent fix for this issue (to be released in the following months).
#WindowsServer2025#MSExchangeSE#ADSchema
https://t.co/rBmvqSIKst
On September 30, 2025, Microsoft will deprecate the legacy multifactor authentication (MFA) and self-service password reset (SSPR) policies in Microsoft 365.
To avoid any service impact, you must migrate these old MFA and SSPR policies to the new converged (unified) Authentication methods policies by September 30, 2025.
Read more:
https://t.co/VtB2Ir6kFm
You have one month left. Time is ticking.
#Microsoft365 #EntraID #Cybersecurity #IAM #MFA #SSPR
Microsoft just dropped a banger spreadsheet to help you level up your security! ๐
It's a FREE Zero Trust assessment tool with a clear roadmap covering SIX key pillars.
Let's break it down! ๐
๐ฅ Identity
๐ฑ Devices
๐ Data
๐ Network
๐๏ธ Infrastructure
๐ต๏ธโโ๏ธ Security Operations
๐ Secure Bits ๐ก
"๐ง๐ฟ๐๐๐ ๐ฅ๐ฒ๐น๐ฎ๐๐ถ๐ผ๐ป๐๐ต๐ถ๐ฝ ๐ฏ๐ฒ๐๐๐ฒ๐ฒ๐ป ๐๐ต๐ถ๐ ๐๐ผ๐ฟ๐ธ๐๐๐ฎ๐๐ถ๐ผ๐ป ๐ฎ๐ป๐ฑ ๐๐ต๐ฒ ๐ฝ๐ฟ๐ถ๐บ๐ฎ๐ฟ๐ ๐ฑ๐ผ๐บ๐ฎ๐ถ๐ป ๐ณ๐ฎ๐ถ๐น๐ฒ๐ฑ"
Do you really understand what this message means? Letโs break it down. ๐
When a domain computer boots, it tries to establish a Secure Channel with a domain controller. This channel is protected by a Session Key โ calculated using the Computer Account Password.
โ If both sides (computer and DC) calculate the same session key โ you're good.
โ If not โ you see:
"๐๐ณ๐ถ๐ด๐ต ๐๐ฆ๐ญ๐ข๐ต๐ช๐ฐ๐ฏ๐ด๐ฉ๐ช๐ฑ ๐ฃ๐ฆ๐ต๐ธ๐ฆ๐ฆ๐ฏ ๐ต๐ฉ๐ช๐ด ๐ธ๐ฐ๐ณ๐ฌ๐ด๐ต๐ข๐ต๐ช๐ฐ๐ฏ ๐ข๐ฏ๐ฅ ๐ต๐ฉ๐ฆ ๐ฑ๐ณ๐ช๐ฎ๐ข๐ณ๐บ ๐ฅ๐ฐ๐ฎ๐ข๐ช๐ฏ ๐ง๐ข๐ช๐ญ๐ฆ๐ฅ."
๐ช๐ต๐ ๐ฑ๐ผ๐ฒ๐ ๐๐ต๐ถ๐ ๐ต๐ฎ๐ฝ๐ฝ๐ฒ๐ป?
Most commonly when the computer tries to authenticate with an outdated password โ for example, after restoring a VM snapshot older than 30 days.
๐๐๐ป ๐ณ๐ฎ๐ฐ๐:
Windows stores two versions of the computer password in the registry:
โช๏ธCurrent password (CurrVal)
โช๏ธPrevious password (OldVal)
๐ But... this doesn't help when both passwords are already outdated across domain controllers.
(OldVal mainly exists to handle replication delays, not secure channel issues.)
๐๐ผ๐ ๐๐ผ ๐ณ๐ถ๐ ๐ถ๐ ๐ฝ๐ฟ๐ผ๐ฝ๐ฒ๐ฟ๐น๐?
You don't need to rejoin the domain!
Instead, use the PowerShell cmdlet:
๐๐ฆ๐ด๐ต-๐๐ฐ๐ฎ๐ฑ๐ถ๐ต๐ฆ๐ณ๐๐ฆ๐ค๐ถ๐ณ๐ฆ๐๐ฉ๐ข๐ฏ๐ฏ๐ฆ๐ญ -๐๐ฆ๐ฑ๐ข๐ช๐ณ -๐๐ณ๐ฆ๐ฅ๐ฆ๐ฏ๐ต๐ช๐ข๐ญ (๐๐ฆ๐ต-๐๐ณ๐ฆ๐ฅ๐ฆ๐ฏ๐ต๐ช๐ข๐ญ)
โก This will reset the secure channel.
โ ๏ธ Heads-up: You need an account with enough privileges over that computer account โ not always ideal, as it s usually domain admin...
๐ค๐๐ถ๐ฐ๐ธ ๐ฟ๐ฒ๐ฐ๐ฎ๐ฝ:
โช๏ธSecure Channel = communication protected by Session Key based on โช๏ธComputer Account Password.
โช๏ธCurrVal & OldVal = help with replication, not broken trust.
โช๏ธRejoin is not necessary โ fix it with Test-ComputerSecureChannel when possible.
How do you usually fix this issue in your environment?๐
#Windows #ActiveDirectory #SecureBits @BlueTeamDave
It's here! Modern auth for Entra Connect Sync is now available ๐
This finally moves from user/pass to auth with Entra to using a Service Principle with a certificate. Another benefit is misconfigs in CA policies will no longer break syncing :)
Docs:
https://t.co/kytbW8u7JD
Part 2 of the Azure Master Class v3, Identity, is up!
https://t.co/XZiJoXzaM9
00:00 - Introduction
01:55 - The need for identity
10:59 - Decentralized identity
18:52 - Enter Entra ID
30:00 - How do you get Entra ID?
38:01 - Entra ID Objects
57:46 - AD to Entra ID Sync
1:04:02 - Authentication & Authorization
1:05:14 - Authentication Options
1:13:41 - Roles and Administrative Units
1:27:31 - Privileged Identity Management
1:35:00 - Entra Permissions Management
1:36:27 - Access Reviews
1:39:13 - MFA and Strong Authentication
1:51:27 - Entra MFA Features
1:53:02 - Securing registration and SSPR
1:58:09 - Conditional Access
2:05:53 - B2B and External ID
2:17:52 - Entitlement management and workflows
2:19:59 - Internet and Private Access
2:24:19 - AD in Azure
2:28:00 - Close
#azure #cloud #microsoft #cloudcomputing #microsoftazure #azurecloud #youtubevideo #learning #azureadministrator #azurearchitect #microsoftcloud #entra #azuread #entraid
Another huge security improvementโกMicrosoft now allows you to federate your app registrations with a Managed Identity, perfect for securely accessing resources in other tenants with multi-tenant apps! > https://t.co/exiwDFfhpd
This change means that you no longer need to store and manage 'stealable' client secrets or certificates to facilitate your connection to multi-tenant applications, especially when using Azure resources such as Azure Automation to run scripts against external tenants!
Currently in private preview, Microsoft hahase released code examples for various Identity libraries, but no support yet for mainstream tools such as the Microsoft Graph PowerShell SDK or Entra PowerShell modules.
#Entra