@IAMERICAbooted I had a group of individuals dismiss cloud strategies I had recently learned from Cloud Security Alliance because no one in the room had ever heard of it. It took 4 years to “discover” the foundational mistakes I tried to highlight in that meeting.
@merill@xenappblog I know you were asking Erik but whats wrong with just querying against: https://t.co/vOLjJSjpjw?`$filter=signInActivity/lastSignInDateTime lt $targetdatestr&`$select=accountEnabled,id,userType,signInActivity,userprincipalname
I saw a MS security script and ACSC do the same also.
@AdamGell I would reappropriate what google built for windows patching called “cabbie”. Linux can run sudo apt update && upgrade via chron deamon.
Another new security app and it has a whole API schema except for a query to gather the administrative users of itself. I need to accurately determine who has privileged access to this application on short notice intervals. What are people doing for this?
@IAMERICAbooted Meant more from the IT controls side where someone looks for the completeness and accuracy of every request for all privileged access. Manager + most applicable SME approval for chain of custody.
@0xcdn I have seen these systems microsoft owns automatically execute files as well but they were designed specifically to execute malicious files. The users were fake and it had a bunch of the shelf products like google chrome, Firefox, and MS visio viewer.
Client gave us an audit questionnaire - asking 40+ questions about AD domain controllers for access control questions. We dont even have AD but I’m not sure what to put down as its the only section to user access stuff. 🫠
@AdamGell A name that like 12 companies all decided to use to broadly lock you into their platform. MS foundry, Palantir Foundry, Cloud Foundry, Nvidia AI Foundry.
@shenetworks 5 years is excessive IMO but there are some apps that do take a bit of time to understand OOO, language, pitfalls. I think it’s also litmus of who has worked in a instance and can immediately know the business is operating with suboptimal or wrong expectations.
@reprise_99 Do not do this. I know someone who named their domain “🐶.🌲” and could never login again. Also not everything downstream supports unicode correctly like “memberof” synced to entra.