ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    What Are You Doing Right Now

    Scheduled Pinned Locked Moved Water Closet
    time waster
    88.9k Posts 285 Posters 42.8m Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • wrx7mW
      wrx7m @dbeato
      last edited by

      @dbeato said in What Are You Doing Right Now:

      Dealing with this...
      https://github.com/OfficeDev/O365-InvestigationTooling/blob/master/RemediateBreachedAccount.ps1

      Oh no! How did you find out about the breach? Also, that is an interesting tool.

      dbeatoD 1 Reply Last reply Reply Quote 0
      • momurdaM
        momurda @dbeato
        last edited by

        I see scripts like that and realize how bad i am at scripting.
        That is really nice

        1 Reply Last reply Reply Quote 3
        • scottalanmillerS
          scottalanmiller
          last edited by

          Feeling tired, ready for the day to be over.

          1 Reply Last reply Reply Quote 0
          • dbeatoD
            dbeato @wrx7m
            last edited by

            @wrx7m said in What Are You Doing Right Now:

            @dbeato said in What Are You Doing Right Now:

            Dealing with this...
            https://github.com/OfficeDev/O365-InvestigationTooling/blob/master/RemediateBreachedAccount.ps1

            Oh no! How did you find out about the breach? Also, that is an interesting tool.

            a customer called and stated he was getting emails from clients that were from him. We noticed it was sent from the Office 365 account and they had a delete rule for all the incoming and sent email.

            wrx7mW 1 Reply Last reply Reply Quote 1
            • wrx7mW
              wrx7m @dbeato
              last edited by

              @dbeato said in What Are You Doing Right Now:

              @wrx7m said in What Are You Doing Right Now:

              @dbeato said in What Are You Doing Right Now:

              Dealing with this...
              https://github.com/OfficeDev/O365-InvestigationTooling/blob/master/RemediateBreachedAccount.ps1

              Oh no! How did you find out about the breach? Also, that is an interesting tool.

              a customer called and stated he was getting emails from clients that were from him. We noticed it was sent from the Office 365 account and they had a delete rule for all the incoming and sent email.

              Yikes!

              1 Reply Last reply Reply Quote 0
              • zachary715Z
                zachary715 @dbeato
                last edited by

                @dbeato said in What Are You Doing Right Now:

                Dealing with this...
                https://github.com/OfficeDev/O365-InvestigationTooling/blob/master/RemediateBreachedAccount.ps1

                Yeah we went through this a couple months back. Office 365 tools to help detect/prevent these types of things aren't strong unless you're willing to pay for Azure AD Premium. Thankfully minimal damage done.

                dbeatoD 1 Reply Last reply Reply Quote 1
                • dbeatoD
                  dbeato @zachary715
                  last edited by

                  @zachary715 said in What Are You Doing Right Now:

                  @dbeato said in What Are You Doing Right Now:

                  Dealing with this...
                  https://github.com/OfficeDev/O365-InvestigationTooling/blob/master/RemediateBreachedAccount.ps1

                  Yeah we went through this a couple months back. Office 365 tools to help detect/prevent these types of things aren't strong unless you're willing to pay for Azure AD Premium. Thankfully minimal damage done.

                  Did you enable MFA after that on the accounts?

                  zachary715Z 1 Reply Last reply Reply Quote 0
                  • zachary715Z
                    zachary715 @dbeato
                    last edited by

                    @dbeato said in What Are You Doing Right Now:

                    @zachary715 said in What Are You Doing Right Now:

                    @dbeato said in What Are You Doing Right Now:

                    Dealing with this...
                    https://github.com/OfficeDev/O365-InvestigationTooling/blob/master/RemediateBreachedAccount.ps1

                    Yeah we went through this a couple months back. Office 365 tools to help detect/prevent these types of things aren't strong unless you're willing to pay for Azure AD Premium. Thankfully minimal damage done.

                    Did you enable MFA after that on the accounts?

                    We looked into MFA before this ever happened, but it doesn't seem to work well since we have Office 365 through GoDaddy. The authentication seems to run through GoDaddy first so it makes it act fairly wonky. I'm now testing a "pure" Office 365 account and going to enable MFA there to confirm my suspicions that GoDaddy is where my issues lie.

                    dbeatoD 1 Reply Last reply Reply Quote 1
                    • dbeatoD
                      dbeato @zachary715
                      last edited by

                      @zachary715 said in What Are You Doing Right Now:

                      @dbeato said in What Are You Doing Right Now:

                      @zachary715 said in What Are You Doing Right Now:

                      @dbeato said in What Are You Doing Right Now:

                      Dealing with this...
                      https://github.com/OfficeDev/O365-InvestigationTooling/blob/master/RemediateBreachedAccount.ps1

                      Yeah we went through this a couple months back. Office 365 tools to help detect/prevent these types of things aren't strong unless you're willing to pay for Azure AD Premium. Thankfully minimal damage done.

                      Did you enable MFA after that on the accounts?

                      We looked into MFA before this ever happened, but it doesn't seem to work well since we have Office 365 through GoDaddy. The authentication seems to run through GoDaddy first so it makes it act fairly wonky. I'm now testing a "pure" Office 365 account and going to enable MFA there to confirm my suspicions that GoDaddy is where my issues lie.

                      Oh okay, this account is fully Office 365.

                      zachary715Z 1 Reply Last reply Reply Quote 0
                      • zachary715Z
                        zachary715 @dbeato
                        last edited by

                        @dbeato said in What Are You Doing Right Now:

                        @zachary715 said in What Are You Doing Right Now:

                        @dbeato said in What Are You Doing Right Now:

                        @zachary715 said in What Are You Doing Right Now:

                        @dbeato said in What Are You Doing Right Now:

                        Dealing with this...
                        https://github.com/OfficeDev/O365-InvestigationTooling/blob/master/RemediateBreachedAccount.ps1

                        Yeah we went through this a couple months back. Office 365 tools to help detect/prevent these types of things aren't strong unless you're willing to pay for Azure AD Premium. Thankfully minimal damage done.

                        Did you enable MFA after that on the accounts?

                        We looked into MFA before this ever happened, but it doesn't seem to work well since we have Office 365 through GoDaddy. The authentication seems to run through GoDaddy first so it makes it act fairly wonky. I'm now testing a "pure" Office 365 account and going to enable MFA there to confirm my suspicions that GoDaddy is where my issues lie.

                        Oh okay, this account is fully Office 365.

                        Yeah we ended up creating some new rules as a result and learned a whole lot about all the different Office 365 relevant portals to capture logs, etc that we weren't fully aware of prior. It's really quite scattered at the moment and the ability to setup alerting is pretty weak, especially on the Azure side. Now we're having to manually check the "Users Flagged for Risk" and "Risky Sign Ins" weekly to help identify any fishy (phishy?) business.

                        1 Reply Last reply Reply Quote 2
                        • EddieJenningsE
                          EddieJennings
                          last edited by

                          Updating my FreePBX VM at the colo.

                          scottalanmillerS 1 Reply Last reply Reply Quote 0
                          • scottalanmillerS
                            scottalanmiller @EddieJennings
                            last edited by

                            @eddiejennings said in What Are You Doing Right Now:

                            Updating my FreePBX VM at the colo.

                            We did that tonight. SO many updates.

                            EddieJenningsE 1 Reply Last reply Reply Quote 0
                            • EddieJenningsE
                              EddieJennings @scottalanmiller
                              last edited by

                              @scottalanmiller said in What Are You Doing Right Now:

                              @eddiejennings said in What Are You Doing Right Now:

                              Updating my FreePBX VM at the colo.

                              We did that tonight. SO many updates.

                              New install for me. Got ZeroTier installed on it, so I don't have to go through a fedora VM in VirtManager to get to the web interface 🙂

                              1 Reply Last reply Reply Quote 0
                              • scottalanmillerS
                                scottalanmiller
                                last edited by

                                Loads of FreePBX updates.

                                1 Reply Last reply Reply Quote 0
                                • scottalanmillerS
                                  scottalanmiller
                                  last edited by

                                  Loads of NodeBB updates!

                                  1 Reply Last reply Reply Quote 0
                                  • scottalanmillerS
                                    scottalanmiller
                                    last edited by

                                    Getting ready for MangoLassi to update as we are slow after a very busy day.

                                    1 Reply Last reply Reply Quote 1
                                    • scottalanmillerS
                                      scottalanmiller
                                      last edited by

                                      First three NodeBB test sites are good.

                                      1 Reply Last reply Reply Quote 1
                                      • dbeatoD
                                        dbeato
                                        last edited by

                                        Working on Emails and Updates

                                        1 Reply Last reply Reply Quote 0
                                        • scottalanmillerS
                                          scottalanmiller
                                          last edited by

                                          Backup taken. Okay, starting in a moment...

                                          dbeatoD 1 Reply Last reply Reply Quote 1
                                          • dbeatoD
                                            dbeato @scottalanmiller
                                            last edited by

                                            @scottalanmiller said in What Are You Doing Right Now:

                                            Backup taken. Okay, starting in a moment...

                                            Good luck 🙂

                                            scottalanmillerS 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 2951
                                            • 2952
                                            • 2953
                                            • 2954
                                            • 2955
                                            • 4443
                                            • 4444
                                            • 2953 / 4444
                                            • First post
                                              Last post