Mathematica Ken

1K posts

Mathematica Ken

Mathematica Ken

@MathematicaKen

Endpoint Automation. IAM.

Katılım Eylül 2016
131 Takip Edilen214 Takipçiler
Mathematica Ken
Mathematica Ken@MathematicaKen·
@SwiftOnSecurity @BillQueens IMO after Merills statement. I’d be avoiding unless absolutely necessary and using a managed service like AWS managed AD with checks from purpleknight or pingcastle and just knowing Netapp needs special care.
English
0
0
1
220
SwiftOnSecurity
SwiftOnSecurity@SwiftOnSecurity·
So what are we looking at these days when it comes to new companies having an Active Directory.
English
27
3
155
44.1K
EZ
EZ@IAMERICAbooted·
👀
Cyber Security News@The_Cyber_News

🚨 EY Data Breach - Hackers Gain Access to IT Support System and Download Documents Source: cybersecuritynews.com/ey-data-breach/ Ernst & Young LLP (EY) is notifying clients that an unauthorized third party breached a support ticket platform used by its IT staff, downloading documents containing client tax data during a roughly two-week window this spring. The Big Four accounting and consulting giant filed breach notifications with the California Attorney General's office on July 15, 2026, confirming the incident's scope. According to EY's notification letter dated July 13, 2026, the firm uses a third-party IT service management platform to help its information technology personnel support internal teams handling tax-related client work. #cybersecuritynews #Databreach

ART
2
0
5
1K
Mathematica Ken
Mathematica Ken@MathematicaKen·
Wanna put your AIs to the test? Put in flights with a known weather delay and have it try and find the optimal route to get you there. I’ve managed to get all of them to disagree with each other and then argue about the validity of the radar data and plane data.
English
0
0
0
71
Mathematica Ken
Mathematica Ken@MathematicaKen·
@rekdt There is the whole part “unless there is evidence of compromise” 🧐
English
0
0
1
148
rekdt
rekdt@rekdt·
Yeah, so, NIST says you should not rotate passwords on any cadence and only force a password reset on detection of the password being compromised Also, the ATF dot gov website just made me reset my previously unique password Flip a coin where the failure is
English
24
15
402
14.4K
Mathematica Ken
Mathematica Ken@MathematicaKen·
@SwiftOnSecurity @CyberCakeX Anecdote: Years ago when I was verifying configs for things like blocking certificate padding I would query obscure GPOs or registry keys when github search used to work and nearly every time Cybercakes repo would come up.
English
1
0
5
1.2K
SwiftOnSecurity
SwiftOnSecurity@SwiftOnSecurity·
Oh my god. @CyberCakeX has progressed their Harden Windows Security app into something phenomenal. It's even on the App Store! hotcakex.github.io I've mentioned it before but this is $250k cyber consultant security advice and tooling for home user machines essentially.
English
10
125
818
88.1K
Mathematica Ken
Mathematica Ken@MathematicaKen·
@NathanMcNulty @SonBoyJim @IAMERICAbooted @fabian_bader @merill I remember the day the “Alchemy” service showed up in app registrations. SecOps had an easy question- we know it’s microsoft but what is it doing and what will break if we block it? Heard some rumors from people but to this day no published answer.
English
1
0
3
49
EZ
EZ@IAMERICAbooted·
Merill Fernando @merill and I sat down for another Entra Chat last month to talk about how attackers have been known to use those loose SECRETS SECRETS EVERWHERE, even to compromise Microsoft's tenant! If an attacker gets their hands on a secret or certificate+key for an app registration that has application (not delegated) permissions, your conditional access policies and named locations or zones WILL NOT MATTER. They will be able to leverage that API permission acting as an application, from anywhere. Attackers are smart. They will make it blend in with where those service principals normally act from. So, do your best to clean them up so you don't lose control of your environment. When an attacker comprmises a service principal via a compromised owner or compromised secret/cert+key, the will be acting in the context of that service principal when leveraging API access. That can be incredibly hard to see depending on the skill of the adversary. You really need to understand that there's no good way to secure Client Secrets or Certificate+Key. If you have 2 owners for every app registration, those owners can do the following things: 1. Add Secrets, Certificates+Keys, Federations 2. Change Manifests 3. Add/change redirect URIs 4. Change the audience to a multi-tenant app 5. Add dynamic or incremental delegated permissions at runtime that don't require admin consent 6. Provisioning 7. Add assignment 8. Harvest consents for lateral movement 9. Add additional owners 10. Move laterally to other tenants via consent phishing Often times, the application will have more permissions granted through the APIs than the application owner. This is a privilege escalation. Unfortunately, at this time, Microsoft recommends having 2 application owners for governance reasons. This recommendation does not account for the added attack surface. Adding app registration owners is giving someone the equivqalent of Application Administrator for that single application, at a minimum, and often more. If you can, use the serviceManagementReference tag to document application ownership for app registrations instead. When users leave, create an automation that checks thopse serviceManagementReference tags and update as necessary. Yes, we need to govern. We also need security. Only your the following roles should be managing anything related to your Entra App Registrations: Cloud Application Admin, Application Admin, Privileged Role Admin, Global Admin. youtube.com/watch?v=8kAO9T…
YouTube video
YouTube
English
2
6
51
6.3K
MikeTalonNYC
MikeTalonNYC@MikeTalonNYC·
@IAMERICAbooted I would do it with a two-year, pay-or-play contract. You fire my ass to cover up your incompetence, which we all know you're gonna do, I get paid.
English
1
0
3
248
EZ
EZ@IAMERICAbooted·
I see salary ranges for CISOs on LinkedIn. You couldn't pay me enough for that job.
English
5
0
23
3.4K
Mathematica Ken
Mathematica Ken@MathematicaKen·
@IAMERICAbooted It’s silly how un-unified they are. I also never got the justification override piece like whats the expected solution to capture that data and action on it?
English
1
0
1
15
Mathematica Ken
Mathematica Ken@MathematicaKen·
@IAMERICAbooted “How come you missed this msg center notification about a conditional access change being turned on that has a title and learn page thats takes 4 read throughs to determine its impact to us?”
English
0
0
3
87
EZ
EZ@IAMERICAbooted·
How many emails do you get per day about advisories for m365 services, especially copilot? Is it just me or has it become insane? It seems like things have become really unstable.
English
4
0
13
1.6K
Mathematica Ken
Mathematica Ken@MathematicaKen·
I spoke with several vendors/contractors around privileged access reviews and access reviews and I think some companies aren’t being held to same compliance standards as others and a large amount are providing incomplete or non-accurate data and getting away with it.
English
0
0
0
52
Mathematica Ken
Mathematica Ken@MathematicaKen·
@sil_views @IAMERICAbooted I had some issues with external sharing and email. In 2/3 of my support cases it was my DLP policy rules Order of operation within the individual ruleset. The other was an initial configuration could only be cleared by recreating the policy, modifications wouldn’t fix it.
English
0
0
0
9
Silviews
Silviews@sil_views·
@IAMERICAbooted Pro tip: Design your DLP policies with business continuity in mind and prepare for exception management to be labor intensive. Prepare for DLP policy blocking entire mail flow or external sharing across all services, because it will happen.
English
2
0
0
20
EZ
EZ@IAMERICAbooted·
In my opinion, the admin portals that take the most broad set of skills and experience go like this, in this order: Purview, Intune, Entra, Security Center, Exchange, SharePoint, Teams, App Admin Center Purview sits at the inner most layer of the security onion and requires knowledge and experience with all the others + network + PKI + Federation + Azure + SaaS + AD + 3rd party cloud.
Tomasz@Tomasz880001

@merill @IAMERICAbooted Is Purview management as bad as Intune for IT admins ? Or maybe it is a good change and there is a light in the tunnel ?

English
5
6
73
21.5K
Mathematica Ken
Mathematica Ken@MathematicaKen·
@IAMERICAbooted I sat there for a few hours and performed each type of guest invite I could think of to see how it presented in audit logs.
English
0
0
0
24
EZ
EZ@IAMERICAbooted·
@MathematicaKen Omg Guests has been a PITA for me to learn about. So many gotchas
English
1
0
1
116
EZ
EZ@IAMERICAbooted·
Since many of you are experiencing Guest explosions due to the retirement IDCRL Protocol aka enablement of EnableAzureADB2BIntegration, and, many of you don't have experience with reconstructing Guest architecture to meet the organizations needs (yes, there are many different kinds of Guests), let me provide some insight on some settings you may want to look at. 1. In the admin center (admin.microsift.com), there are settings in the Org Settings for Microsoft365 Groups that allow you to disable the ability for group owners to add Guests to groups. The reality is that most organizations, even highly regulated organizations, do not require tight control of Group and Team ownership which use RSC permissions. Therefore, you may want to consider this setting. 2. If you want fluidity with ops with less administrative burden and user frustration, let Teams Admins and SharePoint admins determine trusted domains for Guests. If you're in the Defense Industrial Base, you might want to force B2B collaboration to the most restrictive settings in Entra where the domain is managed there too. Otherwise, it's probably not necessary unless you have PCI data in SharePoint or Teams (I really hope that's not the case). 3. Evaluate if turning off ability for group members outside your organization to access group content is right for your organization. When turned on, group members can invite Guests to the M365 group via Outlook on the web. It's turned on by default. 4. You need to understand how the organization shares and collaborates in depth before you go changing settings for external identities, like who can invite Guests and Guest access. 5. Governance of Guests should be automated. You will want to put all Guests in dynamic groups for access reviews. If they haven't logged in for x days, get rid of them. Not manually. Automated. 6. Require MFA for Guests! Don't rely on their home tenant settings. 7. In SharePoint for your sharing policies, you can set your sharing policies to Existing Guests when enforcing B2B Collaboration to reduce confusion for group owners. Make it easy for Group Owners to request Guest access. The business needs to collaborate and make money. 8. If you have a certain app you are hosting that some external people need to access, but dont require access to anything in M365, consider putting the app on a subdomain and adding local Guests for that scenario.
English
2
4
39
2.7K
Nathan McNulty
Nathan McNulty@NathanMcNulty·
@RowanSaintLouis There's a lot of nuance in that question ;) Are they using a separate machine for the secondary account? If not, it's just as exposed as the primary account. You could also consider either ZTNA (like Global Secure Access) or Entra auth so you can use CA or similar auth controls
English
2
1
16
1.1K
💫
💫@RowanSaintLouis·
Yo @NathanMcNulty We use separate AD accounts for users to query SQL DBs. The idea was that if a user’s standard account was compromised, an attacker couldn’t query our SQL DBs. What do you think? Should we just let users connect to SQL DBs with their standard account?
English
1
0
5
2.5K
Mathematica Ken
Mathematica Ken@MathematicaKen·
@merill I need a rebel tip for how to stop people from sharing phones for authenticator and making an MFA tree outside the warehouse.
Mathematica Ken tweet media
English
0
0
9
6.4K
Merill Fernando
Merill Fernando@merill·
Now that I'm no longer at Microsoft, I'm free to share some of my rebel tips 😎 Who wants me to post them?
English
91
16
617
148.5K
Mathematica Ken
Mathematica Ken@MathematicaKen·
@AdamGell Easy just say a few keywords that rhyme with çřypto, pòłymárkët, bǒt, or name some pôlitîcal figures.
1
0
1
36
Adam G
Adam G@AdamGell·
I need more followers to boost my ego. Please help me.
English
3
3
7
473
Mathematica Ken
Mathematica Ken@MathematicaKen·
@IAMERICAbooted Yes Scout desktop app does it - cowork does not. Rumors all around on all this changing.
English
0
0
1
15
EZ
EZ@IAMERICAbooted·
@MathematicaKen Does Scout do that? Im hoping for Cowork one day :p
English
1
0
0
50
EZ
EZ@IAMERICAbooted·
I can't wait to have an agent to handle all my email and Teams messages :p
English
1
0
5
419
Mathematica Ken
Mathematica Ken@MathematicaKen·
@QuinnyPig Uh I think we also learned from the Microsoft stories that they only needed a US citizen(without technical knowledge IIRC) to shoulder surf the support agent from another country.
English
0
0
8
926
Corey Quinn
Corey Quinn@QuinnyPig·
Because folks are confused: GovCloud guarantees the AWS employees touching it are US citizens. The account owner has to be a “US Person” but the IAM users and downstream app users? AWS says that’s your problem, not theirs. Which is why it doesn’t solve the Fable issue.
English
10
6
358
43.5K