ddench who art in infosec exchange 

33 Followers
47 Following
558 Posts
I don't like to share. I'm a bit grumpy sometimes. I smile regardless, as often as possible, because a smile can heal the unhappiest of days. I like to make people's lives easier through functioning technology. Sweets. I don't like to share sweets...
@eljefedsecurit I love the idea of burning it closed. Usually I just keep going. The fam won't mind. a bit of extra sauce
@oruth Clearly Chuck Norris would take her Maj down. However the queen mother, who, as we all know, was actually a robot for the last 30 years of her "life" would simply transform Autobot stylee and stamp out a Norris pancake...
I’ll give journalists in Ukraine pro-bono cybersecurity guidance, inc. security keys for enhanced two-factor auth for email and social media. If you know folks at Kyiv Independent, Kyiv Post or elsewhere who would benefit from this, please put us in touch: runa at granitt dot io.
@jerry I know you always will apologize, and that's fine cos it show's how decent a fellow you are. But really you don't have to. It's not your fault, it's some dickwad's who thinks they're being clever. Well they're not big and they're not clever and we'll have stern words with their mother when we find them. Ooohh they'll be in trouble !!
@hackdefendr @BlueBee yeah, so where I am now we have iPads managed via a combo of meraki and apple school. It works well and is quite flexible, I can restrict apps and os features, set up users synced with ADDS but doing it with mac's is a little different, the surface that is exposed is far greater. You'd have to be sure of the degree of control JAMF actually offers. Things that can't be done with meraki and iOS ( afaik) include blocking access to settings app, because ( I believe) Apple doesn't allow it - what can't be done on macos? And is it a problem?
@hackdefendr @BlueBee oh, I've heard nothing but good things, however we used a third party support contractor to once in a while pop in and 'do some work' to get the MACs talking to AD... so very glad I'm no longer there. The thing with JAMF and the like is that they try to apply policies, wherever possible. The problem is that in too many cases it simply isn't possible to do certain things, so if you're a hybrid environment that cares about policy and procedures and having a maintainable stack of management tools etc, it becomes a pain. For instance: all client endpoints must have enterprise managed firewall configured centrally with x config. Or AV must be installed that applies following settings... if you can't do that with JAMF or [enter AV vendor] then you have to find Yet Another Tool. If your not a hybrid environment and its all MAC then the decision has been made at another level to make do, so all your policies will have to reflect the limitations (or not) of the chosen client OS. Personally I think MACs are too limited in how they can be configured in an enterprise, but then I haven't used them (properly) that way for an age, and I'm becoming an old timer who wants to control every aspect of how a machine works. MDMs just don't cut the mustard for me.
@BlueBee my short answer would be Mac for personal Windows for enterprise. My long answer is that it doesn't really matter for either, what matters is how you use, manage and secure the systems, and what your actual (not percieved) risks are. I use Linux for personal and Windows in the Enterprise, except for mobile, which is iPadOS, though I'd happily shift to ChromeOS. When I worked for an org that used MAC OS, it was a nightmare trying to ensure they met any kind of policies at all, let alone security ones - though I think a large part of that was mismanagement.

The new and improved Windows LAPS! (Local Administrator Password Solution) is finally here for both cloud and on-premises environments.

check it out!

https://aka.ms/Techcommunity/LAPS

#LAPS #AzOps

By popular demand: Windows LAPS available now!

Welcome to the new and improved Windows LAPS! That's Local Administrator Password Solution. We've been listening to your feedback and requests, and the day is finally here for both cloud and on-premises environments. We're very happy to announce that new LAPS capabilities are coming directly to your...

TECHCOMMUNITY.MICROSOFT.COM
@paco This is the way