dice.camp is one of the many independent Mastodon servers you can use to participate in the fediverse.
A Mastodon server for RPG folks to hang out and talk. Not owned by a billionaire.

Administered by:

Server stats:

1.8K
active users

#azure

16 posts14 participants1 post today

Had a weird conversation with the #powerbi specialist at the company I’m contracted to.

She has a problem with the forcing of functionality in PowerBI to be only available in the #Azure controlled cloud held in the US. The cost and security were her main concerns. You can correct me if I misunderstood but in Australia it is starting to be noticed by companies and governments that they have security issues with all their #amazon cloud storage and the money going to US owned companies.

#hiring update:

Vážení,
pořád sháním 2 devopsáky:

1. anglicky hovořící seniorního Devopsáka na pozici "Azure Architect" na full #remote klientský projekt.
Azure DevOps jako takový tam není, mají Gitlab CICD.
ASAP, of course :)

2. seniorní "Devops a Infra Specialist" do interního týmu, hybrid #Praha, leadership skills vítány.
Je to DevOps role rozkročená mezi team leaderem, kontzultantem a cloud architektem.
Chceme vybrat dobře, ne rychle.

Slow password spray attack evaded detection by limiting login attempts per user and rotating IPs in Azure CLI. Tenant-wide log analysis revealed 24 accounts targeted in a stealth campaign. Highlights the need for broader detection strategies.

petrasecurity.substack.com/p/u

Microsoft Detection Deep Dives · Unmasking A Slow and Steady Password Spray AttackBy Adithya Vellal

Für alle Fans von #nextcloud und/oder #owncloud:

Das kann man im Privatumfeld verwenden, sicherlich auch in kleinen Firmen. Unperformant wird es dann, wenn man ein paar hundert Nutzer hat. Die will man nämlich nicht lokal haben, die will man in einem Directory haben (LDAP). Ja, das geht. Und es ist schmerzhaft. Probierts aus! Und wir reden noch gar nicht von Gruppen, das geht nämlich nicht, jedenfalls nicht in der freien Nextcloud-Version (korrigiert mich, wenn ich falsch liege)

Und damit zu #Azure: Dessen Stärke ist gar nicht so sehr das Teilen von Dateien, wie es NC und Dropbox und… können, nein, dessen Stärke ist #entra, also das Identity Management.
Du kannst halt andere Organisationen, die auch bei Azure sind, schnell (aber nicht unbedingt unkompliziert) zum Beispiel an Dein #Jenkins anbinden.
Ja, geht auch mit #keycloak. Wenn Du eine IT-Abteilung hast, die das pflegt.

TL;DR: Es gibt auf Jahre oder Jahrzehnte im geschäftlichen Bereich keine Alternative zu Azure.

Und nun haut mich 😀

Just spent like 3 days trying to figure out another Azure Tenants Intune rbac roles not applying... it was caused by the intune license group being nested under another group. Nested groups are a wonderful concept but the amount of times they have been the root of random issues is very high. #azure #intune #entraID

(sophos.com) Evilginx: How Attackers Bypass MFA Through Adversary-in-the-Middle Attacks news.sophos.com/en-us/2025/03/

A short descriptive article about Evilginx and how stealing credentials work, a few suggested ways of detecting etc.

Summary:
This article examines Evilginx, a tool that leverages the legitimate nginx web server to conduct Adversary-in-the-Middle (AitM) attacks that can bypass multifactor authentication (MFA). The tool works by proxying web traffic through malicious sites that mimic legitimate services like Microsoft 365, capturing not only usernames and passwords but also session tokens. The article demonstrates how Evilginx operates, showing how attackers can gain full access to a user's account even when protected by MFA. It provides detection methods through Azure/Microsoft 365 logs and suggests both preemptive and reactive mitigations, emphasizing the need to move toward phishing-resistant FIDO2-based authentication methods.

Sophos News · Stealing user credentials with evilginxA malevolent mutation of the widely used nginx web server facilitates Adversary-in-the-Middle action, but there’s hope

First dispatch from #SREcon, covering some interesting discussions about how supporting #LLM-based apps in production differs from traditional apps. Features a presentation by Brendan Burns about lessons learned from rolling out #Azure #Copilot.
#LLMOps #AI #genAI #generativeAI #microsoftcopilot #microsoft techtarget.com/searchitoperati

TechTarget · SREs map uncharted territory with LLMOpsBy Beth Pariseau