How do I emulate the extraction of cleartext passwords for the Scheduled Task LogonType password misconfigurations?
Microsoft Recommendation for configuration of Scheduled Task is "In the new task, if the Task Content: XML contains <LogonType>Password</LogonType> value, trigger an alert. In this case, the password for the account that will be used to…
How do I emulate the extraction of cleartext passwords for the Scheduled Task LogonType password misconfigurations?
Microsoft Recommendation for configuration of Scheduled Task is "In the new task, if the Task Content: XML contains <LogonType>Password</LogonType> value, trigger an alert. In this case, the password for the account that will be used to…
I am unable to update email on ESI portal which is causing me lot of issue for taking exam.
Unable to change my email address on ESI portal which is causing authentication issue for me while taking the system test prior to taking my certification exam. I just have to keep postponing my exam.
Unable to merge personal and company account on learn portal.
I have already registered for SC-900 exam however when trying to do a system test , getting error messages "Invalid Pearson VUE Browser lock startup Position(s)". I have booked this exam via the Microsoft ESI portal using my company…
ADMINISTRATION PROBLEM
So my mother originally set up an account on my computer which gives her administration. There are some applications I can't download or delete without permission, but the problem is: She forgot the password to it, and she said she can't reset it. I…
How to get RelaxMinimumPasswordLengthLimits GPO setting to show on DC
I have all Windows 10 21H1 clients and I have 2 Domain Controllers, 2016 and 2019. I have downloaded the latest GPO Templates for the 21H1 update and added those to my central store, but I cannot see the setting for…
Unable to open ports on Windows 10
I have set up rules to open ports 80, 500, 19284 on the Windows firewall. I have set up rules for UDP and TCP, however, I am unable to access the ports using the Telnet 127.0.0.1 command. I get the can't open port message. When I disable the firewall…
System Protection turned on, but won't save restore points on OS drive
I'm running Windows 10 Pro on a Dell T7910 Workstation housing 8 drives. I have System protection enabled on all of the drives with max usage set to 20% on each drive. I am able to create shadow copies on all of the drives EXCEPT the OS drive. Obviously,…
I am having trouble signing in to my work outlook account. I am not getting the notifications on my Authenticator app. What should I do. Reset my accounts?
When I go to Outlook I have to send a security code to my Authenticator to sign in. My problem is that when u get the code my Authenticator app is not responding. I’ve also had this problem when Microsoft sends me verification via email but I never get…
Registry under HKEY LOCAL_MACHINE is not working
I needed to give administration previligiles for c:\tensor\bin\startup.exe to all users in the windows machine. For that, I needed to create registry key following path. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows…
Microsoft Defender VPN - can I choose a location
I have just started using Defender VPN and now can't view TV programme on my iPad or computer - is there a way to choose location? Otherwise I will have to remove it
You can’t access this shared folder because your organization’s security policies block unauthenticated guest access
Hi Sir i have two PCs: PC-A: Windows 10 1909 PC-B: Windows 7 (have a shared folder) everything working well when PC-A is Windows 10 1803, after upgrade to 1909, i will get below error when accessing PC-B shared folder "You can’t…
Abc.exe need to run administrative privilege for all users in the windows machine.
While installing the build in windows10 the abc.exe will be copied to c:\folder\bin and shortcut on desktop. That exe needs the administrative privilege means by double click it need to run in administrator. Is there any way to give admin access for…
Disable Virtualization-Based Security Without Disabling Hyper-V
I am currently trying to run Hyper-V without virtualization-based security enabled, and I have encountered some problems. My first attempt at doing this involved enabling the "Virtual Machine Platform" feature, and setting some of the…
Program Requirements - Microsoft Trusted Root Program (EV code signing)
Hi there, I have questions regarding the EV code signing and MS's root program. In the following link https://learn.microsoft.com/en-us/security/trusted-root/program-requirements in 3.D.3 it says that at the beginning of August 2024, all EV Code Signing…
Microsoft XDR (Defender) - DeviceEvents - ShellLinkCreateFileEvent
Hi everyone, I've been trying to create a hunting query in the Defender portal to identify when a malicious .lnk file is created. I noticed that an interesting event to detect and analyze this is "DeviceEvents --> ShellLinkCreateFileEvent",…
why is my defender vpn shutting off when I close the lid of my laptop
As a recent victim of fraud, one of the things I decided to do is add vpn to my ms defender app. What i found is the vpn does not stay connected when I close my laptop cover. I find that I must initiate it every time I use the laptop. What can I do to…
How can we Block the StickyNotes through GPO ? So that user won't be able to access this.
Need to Block the StickyNotes App on windows 10 Pro Client Machine from GPO from Window Server 2019. I Tried the below mentioned steps, but didn't work. Can any one help me out?
My website has been deemed unsafe by Windows Defender. How do I clear this mistake so my clients can access it?
Please help. My website: <Removed> is being blocked by windows defender. Some potential clients and users see an error message (attached) that blocks them from going to my page saying my site has been reported for phishing. It's been cleared and…
Secure RDP/IPSec using connection security rules in Windows Defender
I am trying to configure RDP to use IPSec. I have configured two connection security rules for TCP and UPD, requiring authentication for inbound and requesting outbound connections. Authentication method is computer kerberos5. From there I am using a GPO…