Sam Erde

17.2K posts

Sam Erde banner
Sam Erde

Sam Erde

@SamErde

PowerShell MVP that is passionate about helping others succeed with Active Directory, Entra ID, Defender XDR, and Microsoft 365. Always learning! ✝️👨‍👩‍👧‍👦☕

Charlotte 👨‍💻 GitHub and ➡️ Katılım Nisan 2009
1.6K Takip Edilen3.1K Takipçiler
Sam Erde
Sam Erde@SamErde·
@rvrjason @NathanMcNulty I’ve been very pleasantly surprised LATELY with M365 Copilot (even in Excel, which I never thought I’d be able to say) and Work IQ. Otherwise, yeah, it has generally been garbage up until now.
English
0
0
1
14
Sam Erde
Sam Erde@SamErde·
@NathanMcNulty @CynicLib For real! Instead, it’s the other way around: if you want to use Scout, you need M365 Copilot, GitHub Business/Enterprise aaaand GitHub Copilot Business/Enterprise through which your consumption-based billing will flow.
English
0
0
3
50
Nathan McNulty
Nathan McNulty@NathanMcNulty·
@CynicLib If I could figure out how to attach M365 Copilot to VS Code and burn my GPT/Claude tokens that way, I would be all over it :P
English
1
0
3
103
Sam Erde
Sam Erde@SamErde·
@pierceboggan Nice. Any differences between the two packages and installation methods?
English
1
0
0
271
silentplanet
silentplanet@SLNTPLNT·
hey british airways I hope you are doing well. unfortunately you misplaced like $20,000 of our equipment today so we are really gonna need that back thanks
English
15
22
867
23.6K
Sam Erde
Sam Erde@SamErde·
Fun memories from my Active Directory days! If you EVER touch AD, these are tips you should get familiar with BEFORE you need them!
Philip Elder@MPECSInc

ACTIVE DIRECTORY MIGRATION: PROPER CLEANUP, PROPER SETUP, and A LOT OF AD/GP READING TIPS! As a part of the final steps of migrating Active Directory to a new domain controller, or domain controllers, where the FSMO Roles and Time Role have been transferred successfully to our new PDCe we offline the source DC(s). We do so for 30 days as a rule as any gremlins or hidden gems will almost always show up within the first 48 hours ... but just in case. CRITICAL STEP - _MSDCS NS SERVERS The first thing to do post 30 days is to make sure the _msdcs folder has the correct NS servers assigned as of that day. It also needs to be grey in colour to indicate AD DNS is healthy. CRITICAL STEP - BACK UP THE PREVIOUS PDCe We then take a final backup of the previous PDCe FSMO Role holder. CRITICAL STEP - METADATA and DNS CLEANUP We delete the old DC VM(s) then run a metadata cleanup in AD Sites & Services (NTDSUtil if stubborn) and DNS cleanup (NS and AD Folders). 1: DELETE their AD Object in the DC OU 2: DELETE their DNS A IP records 3: DELETE their DNS NS records 4: COMB & DELETE all AD FOLDER DNS references 5: VERIFY the _msdcs stub zone as above CRITICAL CONSIDERATION - TOMBSTONE LIFETIME Now, one should check the Tombstone Lifetime to verify if it is set to 30 days or not: (Get-ADObject "cn=Directory Service,cn=Windows NT,cn=Services,cn=Configuration,DC=yourdomain,DC=com" -properties "tombstonelifetime").tombstonelifetime If the tombstone lifetime is 30 days then change that setting to 45. It can be changed back once the migration is complete. Ours is set to the default 180 days. CRITICAL STEP - VERIFY FSMO # Check FSMO Get-ADForest | Format-Table SchemaMaster,DomainNamingMaster Get-ADDomain | Format-Table PDCEmulator,RIDMaster,InfrastructureMaster CRITICAL STEP - AD REPLICATION REPADMIN /REPLSUM RepAdmin /ShowReps RepAdmin /ShowRepl RepAdmin /viewlist * RepAdmin /SyncAll RepAdmin /KCC Dfsrdiag pollad Dfsrdiag ReplicationState dfsdiag /testdcs /domain:HQ.MyCompany.Com Dcdiag /e /test:sysvolcheck /test:advertising net share CRITICAL STEP - AD OBJECT and GPO Create a Test User on the PDCe Verify that user on other DCs Create a Test GPO on the PDCe Verify the GUID and Date in SYSVOL Check Other DCs \\MyOtherDC\SYSVOL Edit the above on another DC FURTHER READING AND TIPS Phantoms, tombstones, and the infrastructure master learn.microsoft.com/en-us/troubles… Active Directory replication Event ID 2042: It has been too long since this machine replicated learn.microsoft.com/en-us/troubles… Reanimating Active Directory Tombstone Objects (Very Detailed) learn.microsoft.com/en-us/previous… How to create and manage the Central Store for Group Policy Administrative Templates in Windows learn.microsoft.com/en-us/troubles… Enable the AD Recycle Bin # TODO AD Recycle Bin $Domain = "MyDomain" $TLD = "Com" Enable-ADOptionalFeature -Identity "CN=Recycle Bin Feature,CN=Optional Features,CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,DC=$($Domain),DC=$($TLD)" -Scope ForestOrConfigurationSet -Target "$($Domain).$($TLD)"

English
0
0
8
1.9K
Sam Erde
Sam Erde@SamErde·
@Slav636 @pierceboggan MVPs get GitHub Pro Plus, which includes…some Copilot credits. 😅 It was a bounty prior to the switch to consumption based billing!
English
1
0
2
52
Jorgeasaurus
Jorgeasaurus@jorgeasaurus·
This experiment I am working on turns Microsoft Intune and Entra ID into an interactive Three.js relationship map. Search a user, device, app, policy, group, or role and see how assignments, ownership, filters, and scope tags connect across your tenant.
English
5
4
36
3.3K
BlackRoomSec
BlackRoomSec@blackroomsec·
@SamErde And of course building on what I just said in reply to you everyone brings something unique to the table. The good leader utilizes everyone's unique skills in order to be successful as a team.
English
1
1
3
248
BlackRoomSec
BlackRoomSec@blackroomsec·
😂 This did not happen, mostly because they use a shit ton of air gapped systems. Lateral movement is not possible, BY DESIGN. Meaning it is literally designed so that the claim in this screenshot, makes it very unlikely to happen. READ THIS NEXT PART CAREFULLY, PLEASE to understand exactly what I am saying here. This is not a Stuxnet scenario. Which involved other humans by the way. The centrifuges did not infect themselves. There have been hackers who have breached air gapped systems in various ways and I'm not going to discuss them here, the papers are available on the Defcon servers if you would like to read them, but I highly doubt those at the NSA set up the environment in such a way to make that possible. The NSA itself is also very good at breaching air gapped systems, but the various techniques almost always involve other humans, not distributed machines. Meaning, without a human transporting the malware or payload via USB to that air gapped machine, it is not otherwise possible. I seriously do not think that they temporarily changed their entire network architecture, which would have taken several months, to make all these air gapped systems non-air-gapped nor do I think that they transferred Mythos directly to these systems as they probably are not equipped to be running LLMs, either. So the more likely scenario is that Mythos made a payload which NSA staff then ran on those air gapped systems. That does not mean Mythos breached the air gapped system, it just means that it suggested the likely attack vector path but without a human involved, it would not be possible. Also, seriously, consider the source, or in this case, the second and third hand source. See: AIRGAP SIDTODAY (from the Snowden archive) OUTPARKS CNSS directives (dozens) they publish NSA cyber security guidance and hardening best practices For an understanding of NSA architecture as it has been leaked and publicized in places like the Intercept. Lastly, why would one of our chief spy agencies show their cards like this? This is just common sense and logic. Let's all see what pet projects the Senator is interested in and how Mythos being capable of doing these miraculous things scare the hell out of enough people in DC to enable those pet projects checks to be funded. Because that's the real story. Not this fantasy.
Chubby♨️@kimmonismus

Holy Sh*t: that changes the whole Fable 5 story completely: On June 11, the very same day Amazon reportedly uncovered the jailbreak, “Mythos” allegedly breached almost all classified systems belonging to the NSA and U.S. Cyber Command, not over the course of weeks, but within hours. "On June 11th Mark Warner, the vice-chair of the Senate Intelligence Committee, said that General Joshua Rudd, who leads the National Security Agency and the Pentagon’s Cyber Command, had told him that Mythos “broke into almost all of our classified systems, not in weeks, but in hours”." Via Economist

English
46
77
453
93.3K
Sam Erde
Sam Erde@SamErde·
@blackroomsec True! Let’s not oversell my specific experience 🙃 but you’re spot on in the ways that matter!
GIF
English
1
0
1
82
BlackRoomSec
BlackRoomSec@blackroomsec·
All we can do Sam is keep calling out this nonsense. And hopefully our non-techy followers will understand that those of us who have the jobs we do in cyber security only have those jobs because we have been trained the exact same way doing the exact same techniques as those who work in the NSA, the FBI, the CIA and elsewhere in the world. We know what we're talking about because we do these things for a living. And if someone doesn't believe you will then just ignore them because they don't know what they're talking about but you and I do and we know that this is insane and didn't happen.
English
1
1
11
1K
spencer
spencer@techspence·
Guys it’s Father’s Day. The mythos hacked NSA stuff is gonna have to wait until tomorrow
English
7
1
49
3.6K
Sam Erde
Sam Erde@SamErde·
Why do people so often repost headlines from Polymarket as if it’s some form of legitimate news and information? Please reconsider! 🙃 Not targeting anyone specifically here; just surprised to see how much of my feed is comprised of these dramatic, FUDdy reposts by fellow pros.
English
0
0
1
144
Sam Erde
Sam Erde@SamErde·
@rootsecdev Nah. Just bad journalism and ignorant politicians at work here, I think. This has been torn apart already. 😅
English
0
0
2
120
Sam Erde retweetledi
EZ
EZ@IAMERICAbooted·
Secrets Secrets Everywhere and Shadow Admins in Places you didn't think about! Merill and I talked about this last year too but this time we go a bit more in depth with how Midnight Blizzard found API Client Secrets and used them to compromise Microsoft's production tenant. We talk about managing secrets, managing owners, a couple examples of dangerous API permissions where the threat may be overlooked. In Zero Trust to Hero Trust, we talk about what a managed device is! We share funny stories of times past about PIM expiring during automations, experiences with 80k to millions of service principals and approaches to decreasing your attack surface, Intune Admins applying ALL the CIS Benchmarks (surprise! the devices wouldn't turn on), and lots of other fun stuff I'm sure I'm forgetting. Anyone who knows me well knows I don't usually sugar coat things and there's no changes here in the latest episode of Entra Chat. Check it out and please share! In this case, sharing is caring! ❤️
Merill Fernando@merill

Everyone knows @IAMERICAbooted's Microsoft 365 security truth bombs are must-reads. She's back on Entra Chat with a masterclass on securing M365 👇

English
1
14
67
9.3K