Taken from the Stryker Handala / Intune Detection Pack v2
"Check PIM role settings for Global Administrator, Intune Administrator, and Cloud Device Administrator. If you see only the "Require Azure MFA" checkbox and no Authentication Context configured, you have the same gap that enabled the Stryker wipe. Configure Authentication Context with FIDO2 or certificate-based auth today.
Enable Intune Multi-Admin Approval for wipe, retire, and delete actions. Tenant Administration > Multi Admin Approval. Under 10 minutes. No additional licensing required.
Deploy Rule 13 (bulk wipe threshold alert). Five wipes in 15 minutes from a single identity fires the alert. Wire it to a Logic App that calls revokeSignInSessions on the triggering account via Microsoft Graph.
"
link to Detection Pack v2 blog and direct download.
Please share so others can lock down their InTune environments please
https://t.co/nLhS49kxut
@DarrenBar88 Agreed Darren - my wife has #LongCovid 5 years now and the PEM/ME/CFS symptoms are real. Very spooky how a healthy person can suddenly become so disrupted by this scary disease, neuropathy is terrible and relentless - she cannot work, so creates a wave of impacts - try and stay +
Forgive your Entra ID admins, for they know not what they do. In most orgs, IAM is not owned by security. Therefore, security must inform IAM.
You MUST defend against modern cloud phishing techniques for INITIAL ACCCESS. Here are 4 of the top vectors when MFA is enforced:
AITM:
- user education
- use phishing resistant authn (i.e. FIDO2 hard keys, Windows Hello, CBA, Enterprise Passkeys)
- apply downstream Exchange Online Protections and Defender for Office365 defenses even if you have an MTA like Proofpoint (you'd be surprised how easy it is to bypass Proofpoint)
Device Code Phishing:
- user education
- block device code authn (this is high impact and extremely difficult)
- build custom solutions to look for it and sound the alarms - your MTAs and other security solutions are not going to stop it, especially from Teams
- require managed devices and device compliance (yes, I know this can be bypassed now but your STILL NEED TO DO IT)
Application consents:
- user education
- every consent should be HIGHLY SCRUTINIZED. Every one. Especially from multitenant apps.
- restrict non-admin users from consenting to 3rd party apps, even verified publishers
- enable the admin consent flow
- educate admins about how these attacks work, even when "Low Risk" API permissions are consented
- if you don't have an SSPM or CASB, use @merill's script to find Oauth2 consents in your tenant (you may be surprised how many there are) https://t.co/oqWo9X4Qfm
Team Phishing:
- use Teams ZAP
- user education
- don't allow users to upload custom Teams apps
- use permissions policies and group policies within teams
- apply CIS Benchmarks wherever possible
- setup enclaves used for external meetings where blast radius is minimized and access to Teams data is restricted
- make all your Teams groups PRIVATE wherever possible
- stop allowing so many Guests, they need to be vetted. There's a lot of impersonation in the world. Your Guest may be compromised. Consider that when you let them in.
@TELUSsupport@TELUS ummmm one of the biggest hockey games of the year is on right now and NOTHING is working. Any help or insight into how to watch Game 7 tonight ?
I am so excited to see this announced!
This solution brings Conditional Access to Kerberos authentication, which means we can now put MFA and other controls in place when accessing file shares, printers, SQL, Remote Desktop, PowerShell remoting, etc
This is going to be huge :)
Our limited edition South Asian Celebration t-shirts are 🔥
Our friends at @BioAroInc have a few to give away! Want to win one? RT this post and comment with your favourite play from last night's win over the Kings!
We'll randomly select winners on Monday!
@Honeywell_Home hello - I can’t seem to get any help on web - I have a vx1 he camera and it’s very unstable , always dropping WiFi where my mesh ap is 15 feet away - currently camera is frozen it’s offline and wired to house but won’t ring or do anything - how to reboot?!
@tskyyc_king Yeah crazy seeing people turning going west in east bound lane and go down the off-ramp - (near front ) hope the pool has drained and your back running …!
To help you take on Shadow Mewtwo, we’re giving away codes for Purified Gems if we reach 150k RT! To participate:
Follow us on Twitter
RT this post with #ShadowRaids
Receive confirmation reply
If we reach our target, we’ll send participants a code for Shadow Raid–themed items!