Sander de Wit

1.1K posts

Sander de Wit

Sander de Wit

@Sander_deWit

Independent cybersecurity & cloud professional

the Netherlands Katılım Mart 2009
579 Takip Edilen176 Takipçiler
Sander de Wit
Sander de Wit@Sander_deWit·
@NickInformation that looks interesting. I’ve just updated my msix ps module as well. still need to quite a bit but I like my win11 sandbox integration. install-module msix
English
1
0
1
29
Sander de Wit
Sander de Wit@Sander_deWit·
@_dirkjan what does it do if json bulk requests are used against the graph bulk endpoint to run them in parallel?
English
1
0
0
62
Dirk-jan
Dirk-jan@_dirkjan·
Now I could easily avoid this by hardcoding a sleep timer between requests, but it's still odd that I get a confirmation from the graph and a separate audit event that the key was removed, while the next request simply puts it back.
English
3
0
1
2.2K
Sander de Wit
Sander de Wit@Sander_deWit·
@IAMERICAbooted the interesting part is, a gdap relationship can have privileged admin that never expires but not global admin (than it needs to expire)
English
1
0
1
207
EZ
EZ@IAMERICAbooted·
IDK who needs to hear this, but a Privileged Authentication Administrator has a privilege escalation path to Global Admin. Don't mind me. Just studying to be a different kind of "expert" :P
English
6
3
39
3K
Sander de Wit
Sander de Wit@Sander_deWit·
@MarkSimos great, when will we be able to create multi-tenant EntraID (scim-enabled) apps again. as currently that is 'paused' due to this initiative.
English
0
0
0
86
Mark Simos
Mark Simos@MarkSimos·
Microsoft's Secure Future Initiative (SFI) is a Zero Trust initiative tailored to Microsoft's needs. You can think of SFI as a kind of Zero Trust case study from Microsoft that you can learn from to improve your own security. microsoft.com/en-us/security… a short 🧵
Mark Simos tweet media
English
4
18
84
7.5K
Sander de Wit
Sander de Wit@Sander_deWit·
@UK_Daniel_Card forgot the easy integration with app control for business and all executables signed (via cat inside package)
English
0
0
1
14
Sander de Wit
Sander de Wit@Sander_deWit·
@UK_Daniel_Card its odd the industry doesnt adopt msix more. some of the pros: * update while in use. *download only changes not entire package, *ready for app isolation, *support app attach. etc
English
3
0
1
240
mRr3b00t
mRr3b00t@UK_Daniel_Card·
Deploying apps in intune sucks.... it's 2025.... it feels like 2005!
English
33
8
198
36.3K
Sander de Wit
Sander de Wit@Sander_deWit·
@EricaZelic it has potential but configuration issues are all too common with pp. I’ve seen many customers accidentally creating bypass issues and misunderstanding their entire mail flow. Exchange does risk management a bit better
English
0
0
2
28
IAM!ERICA
IAM!ERICA@EricaZelic·
I spent some time in Proofpoint last night. Essentially, it's just like Exchange Online with some Purview functionality AND it works better :p
English
14
0
63
5.6K
Sander de Wit
Sander de Wit@Sander_deWit·
@UK_Daniel_Card the amount of issues found in proofpoint configs that are often reviewed by proofpoint support has been mindblowing. while the product might be fine, the quality of the generic implementations is far below common quality standards in the industry
English
0
0
1
52
vx-underground
vx-underground@vxunderground·
Hi, we're doing giveaway number next. We're going to do something a little crazy. We're going to give 1 person $1,000 in BTC. If you'd like $1,000, leave a comment below. - Winners will be selected randomly in the next 24 hours. - We will DM winners. - If you do not confirm your win in 24 hours a new winner will be selected - If your DMs are closed, you automatically forfeit your prize
English
3.9K
299
2.5K
234.2K
vx-underground
vx-underground@vxunderground·
Hi, it's giveaway number ??? (we're almost half way there) Our friends at @cyberwarfarelab hooked us up with 5 vouchers for their Certified Exploit Development Professional course. If you wanna learn about about exploit development, leave a comment below. - Winners will be selected randomly in the next 24 hours. - We will DM winners. - If you do not confirm your win in 24 hours a new winner will be selected - If your DMs are closed, you automatically forfeit your prize Have a nice day
English
1.1K
57
684
59.5K
vx-underground
vx-underground@vxunderground·
Hi, it's tuts-for-nerds giveaway ??? (lost track of giveaways) Our friends at @MalDevAcademy hooked us up with x3 lifetime access plans and x3 database access plans Thank you, mr.d0x and friends for hooking us up and supporting our giveaways. If you'd like to learn about malware development, leave a comment below - Winners will be selected randomly in the next 24 hours. - We will DM winners. - If you do not confirm your win in 24 hours a new winner will be selected - If your DMs are closed, you automatically forfeit your prize Have a nice day
English
1.1K
56
795
56.2K
Jan Bakker
Jan Bakker@janbakker_·
@Sander_deWit A user can only have one TAP, so by creating a new one, any existing TAP will be deleted. Or do you mean deleted TAPs can be used even after they've been deleted?
English
1
0
0
112
Jan Bakker
Jan Bakker@janbakker_·
Earlier this week, I posted a Proof of Concept about requesting Temporary Access Passes on behalf of others using Entra ID Identity Governance. Today, we will go one step further and use the requestor information to determine the request's properties, like the TAP's lifetime. Here's how it's done: janbakker.tech/use-requestor-…
English
4
5
31
4K
Sander de Wit
Sander de Wit@Sander_deWit·
@JasonSandys @AxelGauliard @IntuneSuppTeam @JasonSandys that documentation is pretty scary. basically says to manually remove the policy which in case of signed policies would brick a device. better to keverage dgss to sign a new policy to has defined trusted signing as allowed. speaking of which seems dgss doesnt work
English
1
0
0
47
Sander de Wit
Sander de Wit@Sander_deWit·
@UK_Daniel_Card at that time packet injection, replays, deauths. one case of fakeap with impersonation.
English
1
0
1
26
mRr3b00t
mRr3b00t@UK_Daniel_Card·
@Sander_deWit Thanks dude! Any detail on the attack types detected?
English
1
0
0
34