@fabian_bader@N805DN Do you know if CA policies can be set to only allow TAPs for 1) Pwd/MFA resets and 2) Autopilot fresh machine and set up WHfB? (Don't see why you would ever want to allow TAPs for anything else)
@HackingLZ But if someone snatches passwords via some infostealer having yearly password rotations is a very very slim mitigation for lacking MFA. On average the attacker will have 6 months to use that password. MFA is a must for everything unless access is severely limited somehow.
So long WSUS!
Hope everyone has $5/month/server in their budget for Azure patch management. A service that previously was available for $0/server through Azure Automation.
https://t.co/giBet5GqMz
@duanegran@wimremes Don't think the question refers to TOTP (which is an open standard), but to the 2-digit code used when doing passwordless sign in with MS Authenticator.
@HackingLZ I understand why those titles are red flags for him since they are usually the type of people most able to see through the type of junk he seems to peddle.
@coulls@SwiftOnSecurity This doesn't filter for binaries but will include all files file writes MDE registers. Also only shows most recent file during the time window of the search. Not first time ever a file was seen.
@WellKnitTech@GossiTheDog Yeah. I'm not affected, just pointing out that a cyber insurance can potentially cover various types of outages, not only those due to attacks. But considering the scale I have a feeling insurance companies will find ways to avoid payments.
@jeremymoskowitz @MEM_MVP Would requiring third party kernel drivers to be written in Rust be an unreasonable ask? (Know this would only solve one type of bugs, but still)
While #CrowdSrtike had a massive outage, CISOs and many security managers asked me about delaying updates in Microsoft Defender.
This article discusses these possibilities in MDAV and MDI. Still, you should decide what is best for your organization and technological environment.
https://t.co/hhHXOwiI33
@JimSycurity@SamErde Good point. I guess setting prod servers to 'Critical' and most pre-prod to 'Current Channel (Broad)' with a few at '(Staged)' could be good. Hope is that MS would identify and fix bad updates before reaching our servers.