Jocke A's Avatar

Jocke A

@rekjocke.bsky.social

Senior Solution Architect with passion for identities, federations and security. Trying to enjoy the outdoor life as much as possible.

23 Followers  |  94 Following  |  23 Posts  |  Joined: 09.12.2024
Posts Following

Posts by Jocke A (@rekjocke.bsky.social)

I did a thing!

15.10.2025 14:08 β€” πŸ‘ 21    πŸ” 2    πŸ’¬ 1    πŸ“Œ 0

Som dessutom ska tΓΆmmas var 6:e vecka (istΓ€llet fΓΆr varannan). Blir hΓ€rlig jΓ€sning i solen pΓ₯ sommaren.

msva.se/avfall/narso...

12.06.2025 18:32 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
AppSec Cheat Sheet: Session Management

Session management is a critical component of application security. In our new blog, Senior Security Consultant Aaron James provides a quick reference cheat sheet and detailed guidance on cookie session testing to help you yield high rewards. Read it now!

trustedsec.com/blog/appsec-...

22.05.2025 15:29 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

nginx 1.19.2 🫣

15.05.2025 16:54 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

πŸ˜† MIM just started

22.04.2025 15:43 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

How do you meaningfully improve the security of your AD environment?

Run these free tools quarterly:

- PingCastle
- ScriptSentry
- Locksmith
- ADeleginator

21.04.2025 18:40 β€” πŸ‘ 8    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
Preview
Securing our future: April 2025 progress report on Microsoft’s Secure Future Initiative | Microsoft Security Blog The Microsoft Secure Future Initiative (SFI) stands as the largest cybersecurity engineering project in history and most extensive effort of its kind at Microsoft. Now, we are sharing the second SFI p...

Read about our progress on securing Microsoft in our Secure Future Initiative update:

21.04.2025 17:52 β€” πŸ‘ 33    πŸ” 9    πŸ’¬ 0    πŸ“Œ 0

I think they in general will resell it to the customer with some additional $ added to the bill.

17.04.2025 17:49 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

I'm not 100% updated on W2025SB/OSConfig but it sure looks amazing.

What's applying the settings under the hood?

What happens if W2025SB conflict a GPO setting?

Will they fight each other for eternity like GPO vs DSC or is there some WARN about conflicts?

15.04.2025 16:25 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Free Windows Server 2025 Security Advice Book | Microsoft Community Hub Windows Server 2025 introduces a suite of new and enhanced security features tailored to tackle modern threats across on-premises, hybrid, and cloud...

PLEASE RP: free Windows Server 2025 Security Advice Book...

techcommunity.microsoft.com/blog/itopsta...

15.04.2025 16:08 β€” πŸ‘ 4    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0

I think Cloud Identity summit is still open
@identitysummit.bsky.social

www.identitysummit.cloud

15.04.2025 10:13 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Yes, I was thinking about ATA πŸ‘

08.04.2025 19:07 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Like the software that you port mirrored the traffic to/from DCs to find lateral movement etc. and had installed in your local datacenter without Azure involvement.

08.04.2025 17:50 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

Cloud #IdentitySummit 2025 is back!
Save the date and join this community event with #IdentitySecurity, #MicrosoftEntra, and #CloudIdentity deep dive sessions in Dortmund, Germany.

Call for Papers is open now:
sessionize.com/cloud-identi...

Stay tuned for more details:
www.identitysummit.cloud

08.04.2025 05:23 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

Det framgΓ₯r ju inte riktigt om de bara klickat pΓ₯ en lΓ€nk eller om de ocksΓ₯ gjort nΓ₯got mer. Men absolut bΓΆr man ha mer rigorΓΆsa mekanismer pΓ₯ plats som skyddar IT-miljΓΆn Γ€n bara de facto att en lΓ€nk har besΓΆkts.

06.04.2025 14:42 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

8-9 char password? 🀯

27.03.2025 10:49 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
[D25] Exploiting Token Based Authentication - Dr Nestori Syynimaa
YouTube video by Disobey [D25] Exploiting Token Based Authentication - Dr Nestori Syynimaa

So pin/cert possible to steal during some circumstances. Otherwise PRTs are popular hunting stuff when hybrid/cloud mode is used (often the case with WHfB enabled)

Some sessions about it
youtu.be/mFJ-NUnFBac?...

youtu.be/b-9d5UXOcaA?...

20.03.2025 12:47 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

100% secure?! 🀯 Against what?

20.03.2025 06:54 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Elcykel med extra batterier ger skjuts en bit i alla fall

16.03.2025 20:51 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

But your findings with CertRefreshInterval/fMonitorCertificate + techcommunity.microsoft.com/blog/askds/r... indicate otherwise I guess, where Enroll is enough since the service handle it automatically anyway.

13.03.2025 20:32 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Thanks a lot, awesome findings.

It's a bit confusing that online material and even documentation like this learn.microsoft.com/en-us/previo... says that the template should have auto enroll enabled.

13.03.2025 20:31 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

And then, since the template only needs enroll, the terminal service also must keep track of expiration date etc. I assume? So the service knows when to fire a new request against the configured GPO template name.

13.03.2025 18:47 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Remote Desktop Services enrolling for TLS certificate from an Enterprise CA | Microsoft Community Hub Hey! Rob Greene again.  Been on a roll with all things crypto as of late, and you are not going to be disappointed with this one...

The template should have only enroll techcommunity.microsoft.com/blog/askds/r...

@awakecoding.com do you know if there is any more info available regarding the magic that happens behind the scene when Remote Desktop Configuration service enroll new certs for remote desktop authentication?

13.03.2025 18:34 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Trying to understand a bit more about the "Remote Desktop Authentication" certs and the setting enroll vs auto enroll on the template.

Should the template have enroll or auto enroll configured?

13.03.2025 12:05 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

No worries, just a last minute patch πŸ˜†

12.03.2025 14:43 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

My @disobeyfi.bsky.social talk is finally out! Link to video and slides available at aadinternals.com/talks

And yes, @notmynick.bsky.social used some weird filter, I'm not that fat nor old 😜

11.03.2025 17:14 β€” πŸ‘ 16    πŸ” 5    πŸ’¬ 1    πŸ“Œ 0
Video thumbnail

πŸŽ™οΈ BIG NEWS: I'm launching Entra.Chat - the podcast identity pros have been waiting for!

After years in the identity trenches, I've seen a lot - the midnight calls, the authentication puzzles, and those "how is this even possible?" moments.

10.03.2025 23:01 β€” πŸ‘ 61    πŸ” 14    πŸ’¬ 2    πŸ“Œ 3

"Hon har varnat fΓΆr att verktyget krΓ€ver en stor investering fΓΆr skolorna nΓ€r det gΓ€ller nΓ€tkapacitet, federerad inloggning [...] och multifaktorautenticering"

Inkluderar man detta i kostnaden fΓΆr alla skolor sΓ₯ misstΓ€nker jag siffrorna Γ€r betydligt hΓΆgre.

08.03.2025 07:00 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

security.txt existerar vΓ€ldigt sΓ€llan, tyvΓ€rr. Γ„ven om det bara Γ€r en liten del i det hela.

19.02.2025 17:43 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Yes, how TLS is used in RDP.

I was thinking about the padlock in mstsc that you get when remote host has a certificate enrolled with the correct EKU saying something like the connection was secured with Kerberos and server certificate. And how Kerberos and TLS play together in that part.

19.02.2025 17:39 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0