📢 BlueHat 2023: Applications to Attend are NOW OPEN! 📢 If you are interested in attending @MSFTBlueHat in Redmond, WA, USA, Feb 8-9, 2023, please submit your application here: https://t.co/yYUPQtGfWl (Applications close Jan 6, 2023)
@_wald0@inversecos@mcohmi@kfosaaen@merill@DrAzureAD I always reference the Azure AD Graph API docs for what methods are supported: https://t.co/GJimA15LuF
There are internal versions that the Azure portal uses that allow different operations as well: https://t.co/5VPQHER0bq
Noticed that the number of visits to these notes started growing even while they were WIP (yeah, I work in prod 😅), so here they are:
https://t.co/rx6MyZJnmd
Thank you for sharing @harmj0y@tifkin_@topotam77@ExAndroidDev , it's all beautiful!
It's been a while since our last thread and I need to kill time while a ginormous time travel trace file finishes copying, so let's talk a bit about LSA, the Windows Local Security Authority.
Automatic on-premises Exchange Server mitigation is now in Microsoft Defender Antivirus. We have taken this additional step to further support our customers who have not yet implemented the complete security update. Learn more: https://t.co/QUlXgUZdZp
The nmap script that tests for CVE-2021-26855 had false negatives with 301 and 302 redirects (typically federated auth). This was fixed yesterday. Latest version:
https://t.co/IknjN4vRkL
Run Exchange but are on an out-of-support Cumulative Update level and can't get updates for the March vulnerabilities?
The Exchange team has delivered: https://t.co/u7GnYChQV8
Providing alternative mitigation techniques to help Microsoft Exchange customers needing more time to patch deployments & are willing to make risk & service function trade-offs. These mitigations are not remediation & aren't full protection against attack. https://t.co/n6GD7vjMXD
@SwiftOnSecurity@azonenberg @johnmisczak @Tsigorf It is important for CDN data centers in not so friendly countries. Also, can prevent BMC compromise resulting in host OS compromise.