@tazwake You only have to look at the systray on any Windows device and you will see a lot of 3rd party risk but this is the world we live in and must carefully navigate
@tazwake I think the broader picture here is that if you don’t trust the 1st party to protect you or provide functionality you have to engage a 3rd party and that will always carry some level of risk no matter which vendor you select.
@JefTek@rootsecdev Are these identity risk based controls required if you already have CAPs in place for all users for Require Compliant Device, Require TAP or Phishing Resistant MFA, Block All Countries unless Compliant, Block all OS’s except Windows, iOS or Android
@NathanMcNulty@shadow_pixel Once the Offboard API command has been run using Graph if the machine comes online again will the MS Sense agent on the machine attempt to checkin and then deregister itself or will it show back up again in the dashboard as an onboarded device
@NathanMcNulty@shadow_pixel Silly question, is there an easy way to offboard a device in MDE that you no longer have access to and cannot run the offboarding script locally on the device.
@david_obrien IMO if using Microsoft Entra as your IDP this is significantly more secure and a better user experience especially if using Entra Joined Devices and WHFB as you can easily setup Conditional Access Policies for Require Compliant Device and Require Phishing Resistant MFA
Anyone seen this error before with Microsoft Entra Global Secure Access Client. Was working on a brand new laptop for just under 24 hours and now the tray icon stays in a Disconnected state. #entra#globalsecureaccess
Have also replicated the issue on 2 x reimaged laptops so assuming this may relate to our conditional access polices for session limits or similar but cannot see anything relevant under Sign In logs
User token acquisition failed with the following error: One or more errors occurred. (Failed receiving token. Status=ProviderError, ErrorMessage=The Internet connection has timed out., ErrorCode=3399942154. CorrelationId=Shp/Ehtrg0+Nuqg2NNukuw.0).
@awakecoding We got around this years ago by implementing NRPT so that it doesn’t matter what DNS servers are provided by DHCP or VPN clients the device can always resolve internal resources using NRPT
@JefTek@NathanMcNulty@janbakker_ Out of interest do you guys have an easy way to join users into a security group who have registered strong authentication? Our theory is that once a user has registered FIDO2 auth (WHFB, Yubikey, Passkey) we want to dynamically bind them to a CA policy for phishing resistance
@rucam365 We have seen no adverse effect of having this enabled and it has dealt with the manual process of excluding devices that have been renamed, reimaged or reset which was painful in the past when focusing on improving Exposure Score or Secure Score
@NathanMcNulty Love the new Outlook especially for accessing Shared Mailboxes and not having to deal with large OST files. Only missing feature for me at present is support for .EML files when downloading emails from CRM etc