@jloiselle1 @zer0trus7 @reprise_99 Considering its easier to find ops people than proper SecOps, market value which is dictated by supply and demand , states one is more valuable than the other
@fabian_bader If it truly is devicebound, then that is indeed awesome π i will have to see and test it before i trust that something is not overlooked π
@fabian_bader Then i would be a lot less concerned. But in the current form i fear the consequences of having that being the security frontier for the enterprise identity 2/2
@fabian_bader My biggest concern with passkeys is that the weakest link becomes the icloud account (or similair) which often is a personal account and thus often is subject to weaker security.
If it was possible to restrict the pass key from being roamable through icloud etc 1/2
@rootsecdev@fabian_bader@NathanMcNulty First step for sure is to move configurations needed out of gpo to either intune or another Endpoint management tool. It is indeed a journey, but the end result will be a much smoother running machine (we hope, we still arent fully there yet π)
@UlfLundh We did it personal. With a group enforcing passwordless as support helped the users one by one. Each in charge of their own area, with dashboard to follow progress
@JefTek@sahilmalik@ITguySoCal Or just show the login window in a proxied iframe, allowing them to record the session and abuse the token? Very curious if that is covered aswell
@patbatemansdong@PezRadar No. Players stop as it gets boring doing the same stuff after a while, even more so if there is no reward to chase. If drop rates went up it would just mean people would stop sooner
@EdgeAdsX@0gtweet@DrAzureAD@birdsarentreal That would be a terrible feature, imagine troubleshooting someone who wasnt quite sure and accidently put it in ultra ultra secure mode by swapping back and forth while thinking π
@NathanMcNulty Which makes it fragile if the computer is not often (or ever) used for internet browsing, thus not regularly logging into edge. But the fact that it matters even if using outlook, seems rather silly when its a hybrid joined device where user is logged in with UPN allready :-)
@NathanMcNulty What i mean is that even if the user is logged into pc which is hybrid joined and has active prt. It doesnt send device id for authentication through outlook, only if the user is logged into edge, then it correctly sends the device id. Which imho makes sense
@FractalPrism@Qwik No its not.. the resson it felt awefull is that people could buy their character more powerfull with real money.. you cant in d4 as its only cosmetics, skins, so pretty much like all other games atmβ¦