GeoffP's Avatar

GeoffP

@thesleepyadmins.com

A sleepy admin with an interest in Azure / VMware / ConfigMgr / PowerShell and other bits. Opinions my own. https://thesleepyadmins.com/

21
Followers
75
Following
1
Posts
24.12.2023
Joined
Posts Following

Latest posts by GeoffP @thesleepyadmins.com

Preview
Tiny Tool Town 🏘️ A delightful showcase for free, fun & open source tiny tools. Stupid-delightful software made with love.

www.tinytooltown.com

12.02.2026 04:28 πŸ‘ 79 πŸ” 17 πŸ’¬ 3 πŸ“Œ 0

PLEASE RP: WINDOWS SERVER 2025 ACTIVE DIRECTORY IMPROVEMENTS!

Windows Server 2025 AD has major improvements across the board with hardened defaults, new security features, new crypto, new forest, and domain functional levels, and much more... Today let's discuss the 32k DB page size feature...

15.07.2025 16:26 πŸ‘ 5 πŸ” 3 πŸ’¬ 1 πŸ“Œ 0

FREE Student Security Operations Center (SOC) Program Foundations training from Microsoft

Course available at: microsoft.github.io/SOC/source/c...

01.06.2025 12:51 πŸ‘ 3 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - microsoft/mcp-for-beginners: This open-source curriculum is designed to teach the concepts and fundamentals of the Model Context Protocol (MCP), with practical examples in .NET, Java, TypeScr... This open-source curriculum is designed to teach the concepts and fundamentals of the Model Context Protocol (MCP), with practical examples in .NET, Java, TypeScript, JavaScript and Python. - micro...

MCP For Beginners

github.com/microsoft/mc...

20.05.2025 22:18 πŸ‘ 7 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
Free Windows Server 2025 Security Advice Book | Microsoft Community Hub Windows Server 2025 introduces a suite of new and enhanced security features tailored to tackle modern threats across on-premises, hybrid, and cloud...

PLEASE RP: free Windows Server 2025 Security Advice Book...

techcommunity.microsoft.com/blog/itopsta...

15.04.2025 16:08 πŸ‘ 4 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Preview
What's new in Windows Server 2025 Learn about the features and enhancements in Windows Server 2025 that help to improve security, performance, and flexibility.

PLEASE RP: WINDOWS SERVER 2025 SECURITY LINKS...
Based on your queries, this thread is chock full of Windows Server links for you with a focus on security.

learn.microsoft.com/en-us/window...

15.04.2025 16:13 πŸ‘ 6 πŸ” 4 πŸ’¬ 1 πŸ“Œ 0
Post image

Threat hunters rejoice! This is HUUUGE news πŸ‘

Microsoft just introduced linkable identifiers in Microsoft Entra ID logs.

The bad guys πŸ₯· are going to hate this so much πŸ˜‚

Learn more at learn.microsoft.com/...

Share the good news πŸ‘

01.04.2025 03:55 πŸ‘ 59 πŸ” 19 πŸ’¬ 4 πŸ“Œ 2
Preview
Subnet Peering | Microsoft Community Hub The Basics: VNET Peering Virtual Networks in Azure can be connected through VNET Peering. Peered VNETs become one routing domain, meaning that the entire IP...

Exciting news: Subnet peering is now available in all Azure regions!

This feature is accessible through the latest versions of:

- Azure CLI
- Bicep
- ARM Templates
- Terraform
- PowerShell

Portal support should be added soon

More details at techcommunity.microsoft.com/blog/azurene...

28.03.2025 19:49 πŸ‘ 5 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

Folks, I created these mindmaps to highlight the AMAZING ID Governance deployment guide that was just published by Microsoft.

You are going to want to bookmark this.

πŸ§΅πŸ‘‡

28.03.2025 04:50 πŸ‘ 27 πŸ” 6 πŸ’¬ 2 πŸ“Œ 1
Post image

Export as Bicep is fully available today! πŸ’ͺ

Test it out yourself in the portal, instructions can be found here: learn.microsoft.com/en-us/azure/...

19.03.2025 18:50 πŸ‘ 26 πŸ” 15 πŸ’¬ 1 πŸ“Œ 0
Post image

This is huge!!! We can now see the impact a policy would have had historically without ingesting sign in logs to Azure Monitor 🀯

There's a new Preview on CA policies that provides insights on a per-policy basis, and the way they implemented this is so elegant and fast. I love it! :)

13.03.2025 16:02 πŸ‘ 43 πŸ” 8 πŸ’¬ 2 πŸ“Œ 0

All the #KQL queries from the book @rodtrent.bsky.social , Matthew Zorich & I wrote are available for free on the GitHub repo. github.com/KQLMSPress/d.... Please run these and fix what you find! If the book was helpful let us know & leave a review. We are burried behind all those "For Dummies" books

28.02.2025 19:43 πŸ‘ 21 πŸ” 7 πŸ’¬ 2 πŸ“Œ 0
Preview
Free Windows Server 2025 Security Advice Book | Microsoft Community Hub Windows Server 2025 introduces a suite of new and enhanced security features tailored to tackle modern threats across on-premises, hybrid, and cloud...

PLEASE RP: free Windows Server 2025 Security Advice Book...
techcommunity.microsoft.com/blog/itopsta...

18.02.2025 18:38 πŸ‘ 5 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Post image

πŸ‘‹ We just sent out this week's Entra newsletter.

Read at entra.news/p/entra-n...

16.02.2025 11:15 πŸ‘ 28 πŸ” 9 πŸ’¬ 2 πŸ“Œ 1

Had this saved in the WIP folder forever
KQL for anti-forensics activities

github.com/AttacktheSOC...

So much can be added to this. Think 3rd party tools to aid anti-forensics, browser forensics... too much to name
OMG, look at this😢updates to come! github.com/MikeHorn-git...

14.02.2025 22:29 πŸ‘ 9 πŸ” 3 πŸ’¬ 1 πŸ“Œ 0
Post image

🚨 Time to check your detection queries for MDE:

DLL load events are recorded in DeviceImageLoadEvents table, NOT DeviceEvents table. I keep seeing people sharing queries with the wrong table and even with the wrong ActionType filters.

08.02.2025 11:51 πŸ‘ 6 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Attn: Microsoft 365 admins, devs & cybersec folks
NEW Least Privilege 
Microsoft Graph Permission πŸ‘‡

If an app only needs to update 

User.AccountEnabled

Don’t grant
User.ReadWrite.All 


instead grant
User.EnableDisableAccount.All

Attn: Microsoft 365 admins, devs & cybersec folks NEW Least Privilege Microsoft Graph Permission πŸ‘‡ If an app only needs to update User.AccountEnabled Don’t grant User.ReadWrite.All instead grant User.EnableDisableAccount.All

✳️ Quick heads up.

Microsoft just dropped a bunch of new least privilege Graph permissions.

Avoid granting super privileges like Directory.ReadWrite.All and User.ReadWrite.All to apps. Instead use these new least privilege permissions where possible.

05.02.2025 10:41 πŸ‘ 38 πŸ” 11 πŸ’¬ 2 πŸ“Œ 0
Preview
Create a PowerShell Custom Exception class Create a PowerShell Custom Exception class. GitHub Gist: instantly share code, notes, and snippets.

#pwsh tip of the day! You can throw your own custom exceptions in PowerShell by creating a class that inherits from System.Exception.

If you don't do much with classes, this is a pretty friendly way to ease into them. Check the gist linked for a quick sample.

Happy Scripting!

04.02.2025 17:25 πŸ‘ 3 πŸ” 3 πŸ’¬ 1 πŸ“Œ 0
Preview
Free Windows Server 2025 Security Advice Book | Microsoft Community Hub Windows Server 2025 introduces a suite of new and enhanced security features tailored to tackle modern threats across on-premises, hybrid, and cloud...

PLEASE RP: free Windows Server 2025 Security Advice Book...

techcommunity.microsoft.com/blog/itopsta...

04.02.2025 18:28 πŸ‘ 6 πŸ” 4 πŸ’¬ 4 πŸ“Œ 0
Preview
CVE-2025-0411: 7-Zip Vulnerability Exploited in Attacks on Ukraine Learn about the zero-day vulnerability in 7-Zip and the homoglyph attacks used by Russian cybercrime groups to target Ukrainian organizations.

securityonline.info/cve-2025-041...

04.02.2025 09:47 πŸ‘ 1 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0

I think the most common misunderstanding of Conditional Access is its relationship to authentication, and this results in not understanding how the rest of the controls actually work

Conditional Access performs authorization by evaluating tokens from the authentication service

24.01.2025 23:12 πŸ‘ 67 πŸ” 16 πŸ’¬ 5 πŸ“Œ 0
Video thumbnail

The power of combining two PowerShell modules, PSBluesky and PoshTaskbarItem:

github.com/jdhitsolutio...

The icon shows the number of unread notifications as a badge. If you click the icon the notifications page will be opened by your browser.

Please Like β™₯️ this post to test if it really works😁!

23.01.2025 12:55 πŸ‘ 20 πŸ” 8 πŸ’¬ 3 πŸ“Œ 0

#100DaysOfKQL

Day 6 - Files Potentially Holding Sensitive Information (MDE)

Query in the same spirit as the one shared on Day 4, but based on file events! Fast tracked it following @nathanmcnulty.com comment on Twitter yesterday! πŸ˜‚

SharePoint/OneDrive next?πŸ‘€

github.com/SecurityAura...

07.01.2025 02:26 πŸ‘ 3 πŸ” 2 πŸ’¬ 1 πŸ“Œ 0
TokenSmith Meets Evilginx: Token Theft Combined with Entra Conditional Access Bypass
TokenSmith Meets Evilginx: Token Theft Combined with Entra Conditional Access Bypass YouTube video by SYNACK Time

Unfortunately, that was only a matter of time!

This video combines two of the most dangerous tools at the moment associated with phishing - and it's surprisingly simple!
www.youtube.com/watch?v=Dp1z...

Do we have defense options? Read on πŸ‘‡

17.01.2025 07:21 πŸ‘ 10 πŸ” 4 πŸ’¬ 1 πŸ“Œ 0
Kubernetes Security Fundamentals: Authentication - Part 3
Kubernetes Security Fundamentals: Authentication - Part 3 YouTube video by Datadog

The next in my #Kubernetes #Security fundamentals video series is up now.

This time I'm looking at how service account authentication works in Kubernetes, with some hopefully interesting details on how bound service account tokens work.

youtu.be/jTswj4CS4IA?...

14.01.2025 17:38 πŸ‘ 35 πŸ” 9 πŸ’¬ 0 πŸ“Œ 1
Preview
Action required: MSOnline and AzureAD PowerShell retirement - 2025 info and resources | Microsoft Community Hub As announced in Microsoft Entra change announcements and prior blog updates, the MSOnline and Microsoft AzureAD PowerShell modules...

πŸ‘€ MSOnline PowerShell will retire (and stop working) between early April 2025 and late May 2025.

AzureAD PowerShell will no longer be supported after March 30, 2025, but its retirement will happen after July 1, 2025.

13.01.2025 21:31 πŸ‘ 5 πŸ” 4 πŸ’¬ 0 πŸ“Œ 0
Post image

Did you miss the security announcements at Ignite in November? Tomorrow I'll be giving you the TL;DR at 9.30am AEDT, register below. Shib for attention.

#Cybersecurity #MSIgnite2024

msevents.microsoft.com/event?id=327...

13.01.2025 04:37 πŸ‘ 12 πŸ” 4 πŸ’¬ 0 πŸ“Œ 0
Post image

New video: 5 more Defender for Endpoint mistakes commonly seen in the wild.

Watch: youtu.be/PBy1dxoqakY

09.01.2025 13:55 πŸ‘ 6 πŸ” 2 πŸ’¬ 1 πŸ“Œ 0
Preview
What is Tier Zeroβ€Šβ€”β€ŠPart 1 Tier Zero is a crucial group of assets in Active Directory (AD) and Azure. Its purpose is to protect the most critical components by…

Unequivocally one of the best pieces of writing on Tier 0 there is...

07.01.2025 18:15 πŸ‘ 13 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Preview
about_Profiles - PowerShell Describes how to create and use a PowerShell profile.

#pwsh tip of the day!

Your PowerShell profile is a powerful tool to bootstrap your shell experience.

Define a custom prompt, define/load functions, or any other items you need to happen when you launch your shell!

The about_profiles help topic has all the info need to start!

Happy Scripting!

07.01.2025 19:56 πŸ‘ 11 πŸ” 5 πŸ’¬ 0 πŸ“Œ 0