ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    What Are You Doing Right Now

    Water Closet
    time waster
    285
    88.9k
    41.3m
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • wrx7mW
      wrx7m @dbeato
      last edited by

      @dbeato said in What Are You Doing Right Now:

      @wrx7m said in What Are You Doing Right Now:

      @dbeato said in What Are You Doing Right Now:

      Dealing with this...
      https://github.com/OfficeDev/O365-InvestigationTooling/blob/master/RemediateBreachedAccount.ps1

      Oh no! How did you find out about the breach? Also, that is an interesting tool.

      a customer called and stated he was getting emails from clients that were from him. We noticed it was sent from the Office 365 account and they had a delete rule for all the incoming and sent email.

      Yikes!

      1 Reply Last reply Reply Quote 0
      • zachary715Z
        zachary715 @dbeato
        last edited by

        @dbeato said in What Are You Doing Right Now:

        Dealing with this...
        https://github.com/OfficeDev/O365-InvestigationTooling/blob/master/RemediateBreachedAccount.ps1

        Yeah we went through this a couple months back. Office 365 tools to help detect/prevent these types of things aren't strong unless you're willing to pay for Azure AD Premium. Thankfully minimal damage done.

        dbeatoD 1 Reply Last reply Reply Quote 1
        • dbeatoD
          dbeato @zachary715
          last edited by

          @zachary715 said in What Are You Doing Right Now:

          @dbeato said in What Are You Doing Right Now:

          Dealing with this...
          https://github.com/OfficeDev/O365-InvestigationTooling/blob/master/RemediateBreachedAccount.ps1

          Yeah we went through this a couple months back. Office 365 tools to help detect/prevent these types of things aren't strong unless you're willing to pay for Azure AD Premium. Thankfully minimal damage done.

          Did you enable MFA after that on the accounts?

          zachary715Z 1 Reply Last reply Reply Quote 0
          • zachary715Z
            zachary715 @dbeato
            last edited by

            @dbeato said in What Are You Doing Right Now:

            @zachary715 said in What Are You Doing Right Now:

            @dbeato said in What Are You Doing Right Now:

            Dealing with this...
            https://github.com/OfficeDev/O365-InvestigationTooling/blob/master/RemediateBreachedAccount.ps1

            Yeah we went through this a couple months back. Office 365 tools to help detect/prevent these types of things aren't strong unless you're willing to pay for Azure AD Premium. Thankfully minimal damage done.

            Did you enable MFA after that on the accounts?

            We looked into MFA before this ever happened, but it doesn't seem to work well since we have Office 365 through GoDaddy. The authentication seems to run through GoDaddy first so it makes it act fairly wonky. I'm now testing a "pure" Office 365 account and going to enable MFA there to confirm my suspicions that GoDaddy is where my issues lie.

            dbeatoD 1 Reply Last reply Reply Quote 1
            • dbeatoD
              dbeato @zachary715
              last edited by

              @zachary715 said in What Are You Doing Right Now:

              @dbeato said in What Are You Doing Right Now:

              @zachary715 said in What Are You Doing Right Now:

              @dbeato said in What Are You Doing Right Now:

              Dealing with this...
              https://github.com/OfficeDev/O365-InvestigationTooling/blob/master/RemediateBreachedAccount.ps1

              Yeah we went through this a couple months back. Office 365 tools to help detect/prevent these types of things aren't strong unless you're willing to pay for Azure AD Premium. Thankfully minimal damage done.

              Did you enable MFA after that on the accounts?

              We looked into MFA before this ever happened, but it doesn't seem to work well since we have Office 365 through GoDaddy. The authentication seems to run through GoDaddy first so it makes it act fairly wonky. I'm now testing a "pure" Office 365 account and going to enable MFA there to confirm my suspicions that GoDaddy is where my issues lie.

              Oh okay, this account is fully Office 365.

              zachary715Z 1 Reply Last reply Reply Quote 0
              • zachary715Z
                zachary715 @dbeato
                last edited by

                @dbeato said in What Are You Doing Right Now:

                @zachary715 said in What Are You Doing Right Now:

                @dbeato said in What Are You Doing Right Now:

                @zachary715 said in What Are You Doing Right Now:

                @dbeato said in What Are You Doing Right Now:

                Dealing with this...
                https://github.com/OfficeDev/O365-InvestigationTooling/blob/master/RemediateBreachedAccount.ps1

                Yeah we went through this a couple months back. Office 365 tools to help detect/prevent these types of things aren't strong unless you're willing to pay for Azure AD Premium. Thankfully minimal damage done.

                Did you enable MFA after that on the accounts?

                We looked into MFA before this ever happened, but it doesn't seem to work well since we have Office 365 through GoDaddy. The authentication seems to run through GoDaddy first so it makes it act fairly wonky. I'm now testing a "pure" Office 365 account and going to enable MFA there to confirm my suspicions that GoDaddy is where my issues lie.

                Oh okay, this account is fully Office 365.

                Yeah we ended up creating some new rules as a result and learned a whole lot about all the different Office 365 relevant portals to capture logs, etc that we weren't fully aware of prior. It's really quite scattered at the moment and the ability to setup alerting is pretty weak, especially on the Azure side. Now we're having to manually check the "Users Flagged for Risk" and "Risky Sign Ins" weekly to help identify any fishy (phishy?) business.

                1 Reply Last reply Reply Quote 2
                • EddieJenningsE
                  EddieJennings
                  last edited by

                  Updating my FreePBX VM at the colo.

                  scottalanmillerS 1 Reply Last reply Reply Quote 0
                  • scottalanmillerS
                    scottalanmiller @EddieJennings
                    last edited by

                    @eddiejennings said in What Are You Doing Right Now:

                    Updating my FreePBX VM at the colo.

                    We did that tonight. SO many updates.

                    EddieJenningsE 1 Reply Last reply Reply Quote 0
                    • EddieJenningsE
                      EddieJennings @scottalanmiller
                      last edited by

                      @scottalanmiller said in What Are You Doing Right Now:

                      @eddiejennings said in What Are You Doing Right Now:

                      Updating my FreePBX VM at the colo.

                      We did that tonight. SO many updates.

                      New install for me. Got ZeroTier installed on it, so I don't have to go through a fedora VM in VirtManager to get to the web interface 🙂

                      1 Reply Last reply Reply Quote 0
                      • scottalanmillerS
                        scottalanmiller
                        last edited by

                        Loads of FreePBX updates.

                        1 Reply Last reply Reply Quote 0
                        • scottalanmillerS
                          scottalanmiller
                          last edited by

                          Loads of NodeBB updates!

                          1 Reply Last reply Reply Quote 0
                          • scottalanmillerS
                            scottalanmiller
                            last edited by

                            Getting ready for MangoLassi to update as we are slow after a very busy day.

                            1 Reply Last reply Reply Quote 1
                            • scottalanmillerS
                              scottalanmiller
                              last edited by

                              First three NodeBB test sites are good.

                              1 Reply Last reply Reply Quote 1
                              • dbeatoD
                                dbeato
                                last edited by

                                Working on Emails and Updates

                                1 Reply Last reply Reply Quote 0
                                • scottalanmillerS
                                  scottalanmiller
                                  last edited by

                                  Backup taken. Okay, starting in a moment...

                                  dbeatoD 1 Reply Last reply Reply Quote 1
                                  • dbeatoD
                                    dbeato @scottalanmiller
                                    last edited by

                                    @scottalanmiller said in What Are You Doing Right Now:

                                    Backup taken. Okay, starting in a moment...

                                    Good luck 🙂

                                    scottalanmillerS 1 Reply Last reply Reply Quote 0
                                    • scottalanmillerS
                                      scottalanmiller @dbeato
                                      last edited by

                                      @dbeato said in What Are You Doing Right Now:

                                      @scottalanmiller said in What Are You Doing Right Now:

                                      Backup taken. Okay, starting in a moment...

                                      Good luck 🙂

                                      Thanks.

                                      1 Reply Last reply Reply Quote 0
                                      • scottalanmillerS
                                        scottalanmiller
                                        last edited by

                                        Here we go....

                                        1 Reply Last reply Reply Quote 0
                                        • scottalanmillerS
                                          scottalanmiller
                                          last edited by

                                          And we are back!

                                          1 Reply Last reply Reply Quote 0
                                          • scottalanmillerS
                                            scottalanmiller
                                            last edited by

                                            NodeBB 1.9.3 now.

                                            dbeatoD 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 2951
                                            • 2952
                                            • 2953
                                            • 2954
                                            • 2955
                                            • 4443
                                            • 4444
                                            • 2953 / 4444
                                            • First post
                                              Last post