Matthew Armitage's Avatar

Matthew Armitage

@mcsamatt

Microsoft Security, Identity and Systems Management nerd. Also enjoy home automation and tinkering with machines. FIDO auth FTW!

17
Followers
79
Following
18
Posts
10.11.2024
Joined
Posts Following

Latest posts by Matthew Armitage @mcsamatt

I generally enjoy your work Zach, but this may be my favourite comic of yours.

26.07.2025 17:30 πŸ‘ 4 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Migrate approved client app to application protection policy in Conditional Access - Microsoft Entra ID The approved client app control is going away. Migrate to App protection policies.

Should this graphic be updated given that β€œapproved apps” is being deprecated in Conditional Access? learn.microsoft.com/en-us/entra/...

09.03.2025 17:42 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Cryptomator - Cryptomator Cryptomator is an open-source encryption tool for secure cloud storage. Protect your privacy for free on Dropbox, Google Drive, OneDrive, and more.

I think Cryptomator is available in the UK. If you know similar software feel free to comment.

cryptomator.org/for-individu...

23.02.2025 11:14 πŸ‘ 4 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
A screenshot of the new profile editor in office.com

A screenshot of the new profile editor in office.com

Starting today you can udpate your profile in #Microsoft365 using a new and modern profile editor (replacing the #Delve experience). Go to office.com, search for your name and click on it and find the "Update your profile" button. The team is eager for feedback!

09.12.2024 09:29 πŸ‘ 60 πŸ” 28 πŸ’¬ 9 πŸ“Œ 2

XML in LDAP teaches you to see God in a new way

08.12.2024 06:58 πŸ‘ 65 πŸ” 1 πŸ’¬ 4 πŸ“Œ 1

802.1x what are you doing step bro you shouldn't be a fucking LDAP attribute

08.12.2024 06:56 πŸ‘ 52 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0
Preview
Home Updater Did you know your home device/computer needs regular updates to stay secure? Automate your patching for over 500+ applications free of charge.

You're welcome

08.12.2024 21:29 πŸ‘ 74 πŸ” 9 πŸ’¬ 8 πŸ“Œ 1

😍
Will there perhaps be more info available at an airlift soon?

09.12.2024 02:34 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Not as long as you might think :).

08.12.2024 16:06 πŸ‘ 7 πŸ” 1 πŸ’¬ 3 πŸ“Œ 0
Post image

I just sent out this week's Entra newsletter πŸ‘‡

entra.news/p/entra-n...

08.12.2024 11:25 πŸ‘ 38 πŸ” 8 πŸ’¬ 1 πŸ“Œ 0

Yes, and I wouldn’t set them up any other way (SSO or bust!). But the reliance on another entire overlay network, with additional network endpoints and additional security monitoring/vulnerability management seems like an area for improvement. The Kaseya breach still haunts me…

08.12.2024 21:17 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

If we have the GSA agent already on the endpoint, then why have another privileged control path? Just do RDP/VNC/SSH/Something else with the existing secure path, all secured by Entra ID Conditional Access.
If this isn’t on their roadmap, along with integrating Azure Arc, then maybe it should be πŸ˜€

08.12.2024 21:08 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I would, for example, love to have a remote support agent on endpoint PCs, and enforce access over the GSA network. Current remote support products like TeamViewer, Beyond Trust Remote Support and ScreenConnect all require a separate agent, which adds a net new security boundary to an Org.

08.12.2024 21:02 πŸ‘ 2 πŸ” 0 πŸ’¬ 2 πŸ“Œ 0

Oh don’t get me wrong, the network connector has its place, and leveraging the prior App Proxy was a good call. I think a good SASE/SSE product needs to have all three connectivity options. Agent service, Network Connector, and integration with existing networks.

08.12.2024 20:58 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

I think the real endgame here is moving from having Entra Private Network Connectors, to using a local agent on the systems themselves as the connection. Then firewalling everything else. Ala Tailscale, Cloudflared, or Azure Arc Remote Access. The sooner GSA moves to away from a central connector…

08.12.2024 16:07 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Back in the day, we would compose an email, put billg@microsoft.com in the To field, "Fire me, I'm irresponsible" on the subject line, and just leave it front and centre on their screen, before 3) locking it for them.

I was eventually reprimanded for starting that trend.

06.12.2024 17:54 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
NTLM v1 is removed from the latest version of Windows

NTLM v1 is removed from the latest version of Windows

Oh by the way

06.12.2024 01:08 πŸ‘ 101 πŸ” 35 πŸ’¬ 9 πŸ“Œ 6

A good write up on how Credential Guard prevented an common attack. isc.sans.edu/diary/Creden.... If you haven't looked at this in a while, now is a great time to start. learn.microsoft.com/en-us/window.... Kudos to @syfuhs.net and the team for doing all the hard work on this. #infosec

06.12.2024 16:33 πŸ‘ 39 πŸ” 14 πŸ’¬ 1 πŸ“Œ 1
Post image

This is pretty awesome - require PIM activation before you can RDP to a server, access a credential vault, etc.

This could even be done with approval workflow and authentication contexts to enforce very strong restrictions πŸ”₯

learn.microsoft.com/...

07.12.2024 08:53 πŸ‘ 63 πŸ” 10 πŸ’¬ 2 πŸ“Œ 1

I’m a fan of adding β€œSC” and β€œES”. Imo it makes it more versatile if changes are being made via Graph or directly in Intune.

06.12.2024 01:08 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image


Okay, the self-service site to get your account verified is almost ready to go.

But it's too late over here in Australia, and I'm not brave enough to hit publish on a new site and go to bed πŸ™ˆ

So the plan is to launch this πŸ‘‡ tomorrow!

Stay tuned...

01.12.2024 12:28 πŸ‘ 187 πŸ” 19 πŸ’¬ 11 πŸ“Œ 2
Defender’s Mindset This is a collection of thoughts, quips, and quotes from tweets, blogs, and presentations over the years. If you find them helpful, drop me…

One of the highest importance things in Security is thinking as a Graph not a List. Owning Twitter doesn't get you Twitter. It gets you everything that trusts Twitter.

John Lambert, one of the seniormost Microsoft people who has his hand fighting their greatest battles.
medium.com/@johnlatwc/d...

01.12.2024 21:35 πŸ‘ 113 πŸ” 24 πŸ’¬ 1 πŸ“Œ 0

If, like me, you're retaining your account to prevent someone else from scooping it up, you should go delete all of these. Settings and privacy > Security and account access > Apps and sessions > Connected apps

01.12.2024 21:22 πŸ‘ 88 πŸ” 35 πŸ’¬ 3 πŸ“Œ 1

i think i may start doing 'skytalks' on how not to get fucked when starting a company, getting investment, and building a team

there's a lot of folks in infosec and adjacent industries that have stars in their eyes and brilliant ideas, but have no idea what a bad deal looks like

27.11.2024 00:59 πŸ‘ 156 πŸ” 14 πŸ’¬ 25 πŸ“Œ 1
Platform SSO for macOS

Platform SSO for macOS

Microsoft Intune now allows you to configure Platform SSO (Single Sign-On) for Apple macOS devices. Platform SSO is an extension to the existing Microsoft Enterprise SSO plug-in that brought single sign-on (SSO) to macOS using Microsoft Entra ID accounts.

27.11.2024 08:56 πŸ‘ 8 πŸ” 3 πŸ’¬ 2 πŸ“Œ 0
Post image

"Management" asks for changing default fonts, or right-click menu's, or moving the start button are unsustainable.

Say "No".
Empower your users with training or KB's.
Stop assuming you know what every individual needs to be productive.

#SomeExclusionsApply

27.11.2024 15:47 πŸ‘ 19 πŸ” 4 πŸ’¬ 6 πŸ“Œ 0

Depends on the date, is it before or after 2023-07-11?

27.11.2024 02:41 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
A screenshot from a login screen with two SSO buttons, one for Azure AD, one for Entra ID

A screenshot from a login screen with two SSO buttons, one for Azure AD, one for Entra ID

Which do I pick for SSO?!?

#EntraID vs #AzureAD

27.11.2024 01:23 πŸ‘ 5 πŸ” 1 πŸ’¬ 3 πŸ“Œ 0

A win for repairability!

Not so much for security 🫣

27.11.2024 02:38 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

If you like using #kql then this is an absolute must! Mark and Team did a great job with the book and applying that to doing the missions in #kc7 is just nerdy fun! Have you tried it yet?

27.11.2024 01:03 πŸ‘ 3 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0