New Setting Users Can Create Azure AD Tenants (updated 2024 new graph module) Paid Members
New setting means more control In november 2022 (I haven't the exact date but it seems since 18th november 2022), many folks warned on a new setting in Azure AD: "Users can create Azure AD tenants". What? Microsoft created a new security hole? 😱 This setting is
Out of the band updates for November 2022 updates Paid Members
Microsoft has released optional out-of-band (OOB) updates to fix known issues with Kerberos sign-in failures and other authentication problems on domain controllers. These problem arise after installing November 2022 Cumulative Updates. To the remind, the November updates (KB5021131) were here to fix CVE-2022-37966. With them,
KB5021131 - How To Detect RC4 Accounts Paid Members
In the Microsoft article about the November 2022 updates KB5021131 for CVE-2022-37966, Microsoft provides a detection rule: ((msDS-SupportedEncryptionTypes & 0x3F) != 0) && ((msDS-SupportedEncryptionTypes & 0x38) == 0) This rule is not an expression you can user as-is with Get-ADUser or Get-ADObject. If you
Download old Azure AD Connect versions / Entra Connect Sync [updated September 2026] Paid Members
💡This page is updated as soon as a new version of Azure AD Connect/Entra Connect Sync is available. If you work with Microsoft 365, Azure AD Connect (Entra Connect Sync) is the masterpiece to synchronize the on-premise Active Directory to Azure Active Directory. Microsoft provides 12 months support
Augmentation des audits logs à 365 jours dans Microsoft 365 (with PowerShell) Paid Members
Présentation Le journal d’audit de Microsoft 365 est le meilleur endroit pour identifier les actions utilisateurs et administrateurs (comme la liste des changements de droits sur les comptes admins). Par défaut, la rétention standard est limitée à 90 jours (180 jours depuis le 17 octobre 2023), sauf pour les
Microsoft 365 audit logs are now retained for 365 days for all tenants (with PowerShell) Paid Members
Overview The Microsoft 365 audit log is the best place to identify user and admin actions (like track admin roles changes). By default, standard retention is limited to 90 days (180 days since October 17, 2023), except for tenants with Office 365 E5 or Microsoft 365 E5 licenses who can
Mitigate PetitPotam in Active Directory Certificate Services Paid Members
💡Please refer to the links at the bottom of this article for the most up-to-date links by Microsoft. Uninstall ADCS web enrollment A quick method is to uninstall the ADCS web enrollment (reboot required). After this, you can’t use https://yourserver.domain.com/certsrv Uninstall-WindowsFeature ADCS-
How to get Microsoft Technet Gallery scripts Paid Members
Microsoft closed Technet Gallery and Script Center in early 2021. On this page, you will find a selection of scripts. Please note, however, that the licenses for some scripts do not permit free distribution. If you are seeking any specific script from Technet, feel free to contact me – I have
Accès au fichier cloud est refusé avec Uninstall-Module Paid Members
Une incohérence entre OneDrive et PowerShell Lors de la désinstallation d’un module PowerShell avec la commande Uninstall-Module il peut arriver l’erreur suivant: PackageManagement\Uninstall-Package : L’accès au fichier cloud est refusé Au caractère C:\Users\xxxxx\OneDrive – YYYY\Documents\WindowsPowerShell \Modules\PowerShellGet\2.1.5\PSModule.
Get the Microsoft 365 admin roles and track the changes [updated january 2025] Paid Members
Admin roles are the key of your kingdom Office 365 allows organizations to granularly delegate administrative privileges. Office 365 contains a lot of built-in aministrative roles. Among them we find Global Administrator, Exchange administrator, User Account Administrator, Billing Administrator, Global reader, etc. Those privileges must be audited regularly. When
WMI Filter to identify 32 and 64 bits Paid Members
A lot of bad WMI filter on the Internet I create Group Policy Objects for years and I am often consulted to solve GPO issues. Lately I had to debug GPOs created by an IT admin. This GPO has applied randomly on the workstations. All these GPO use the following
Filtre WMI pour identifier 32 et 64 bits Paid Members
Beaucoup de mauvais filtres WMI sur Internet Je crée des objets de stratégie de groupe depuis des années et je suis souvent consulté pour résoudre les problèmes de GPO. Dernièrement j’ai dû déboguer des GPO créés par un administrateur. La particularité de cette GPO est s’appliquent de manière