Despite doubts, federal cyber experts approved Microsoft cloud service
51–60 of 249 posts
Re: Despite doubts, federal cyber experts approved Microsoft cloud service
#52Recently tried using Entra ID. There are 12 ways to enforce MFA, 20 days ways to disable users, 4 ways to authenticate users, Add conditional access stuff with 50 variables and templates etc. You can customize the way you want. After configuring it, my colleagues could not log in. Thats one way to secure your organization.
Out of all the SSO login flows Microsoft has to have the buggiest. It’s the only one I can remember routinely having issues with. Why are there so many redirects? And why doesn’t the “remember me” checkbox ever work?
Re: Despite doubts, federal cyber experts approved Microsoft cloud service
#53The government does most things poorly and with little regard to budget or quality. They can't solve problems that are much simpler than cloud computing, so why should I expect them to perform better at a more complex problem?
The government has historically, routinely, consistently, solved problems more complex than cloud computing.
The only way you'd think otherwise is if you had some other motivation to pretend otherwise... some sort of ideology.
Re: Despite doubts, federal cyber experts approved Microsoft cloud service
#54Recently tried using Entra ID. There are 12 ways to enforce MFA, 20 days ways to disable users, 4 ways to authenticate users, Add conditional access stuff with 50 variables and templates etc. You can customize the way you want. After configuring it, my colleagues could not log in. Thats one way to secure your organization.
Out of all the SSO login flows Microsoft has to have the buggiest. It’s the only one I can remember routinely having issues with. Why are there so many redirects? And why doesn’t the “remember me” checkbox ever work?
Re: Despite doubts, federal cyber experts approved Microsoft cloud service
#55Microsoft has never been good at security, and that is why their centralization to cloud is absolutely terrifying. I'm reminded of Storm-0558 [1] where a stolen signing key was able to forge authentication tokens for any MSA / Azure AD / Government AD user. They downplayed the severity. Just imagine if that level of access was used to pull a Stryker on a nation-wide scale. That is an economic disaster waiting to happ…
I'll do you one better: stealing the signing key was not even necessary. https://www.bleepingcomputer.com/news/security/microsoft-ent...
Re: Despite doubts, federal cyber experts approved Microsoft cloud service
#56Recently tried using Entra ID. There are 12 ways to enforce MFA, 20 days ways to disable users, 4 ways to authenticate users, Add conditional access stuff with 50 variables and templates etc. You can customize the way you want. After configuring it, my colleagues could not log in. Thats one way to secure your organization.
- FB's move fast and break things. Constantly launching new libs.
- Linus's we do not break user space. Great commitment to backwards compatibility.
- Never deprecating dead products until they've been de facto abandoned for like decades.
This combination means every MS product is a labyrinth of overlapping APIs with no guidance as to which one is actually the good one. Some are abandoned garbage, some are brand new and incomplete, and some are both, and there's no way of knowing which are which even experts can mislead you.
Re: Despite doubts, federal cyber experts approved Microsoft cloud service
#57Re: Despite doubts, federal cyber experts approved Microsoft cloud service
#58The experts were correct. Azure is the biggest pile of shit I've ever had to work with. Everything feels evolutionary. In other words, a new product in azure is barely a product at all, but a small appendage which totally inherits a bunch of preexisting Azure "stuff." And all this preexisting stuff may not really make sense for the product, and it might inherit stuff that makes the product much worse. But, it doesn't…
Re: Despite doubts, federal cyber experts approved Microsoft cloud service
#59Re: Despite doubts, federal cyber experts approved Microsoft cloud service
#60Decades ago, Lotus 1-2-3 on top of MSDOS was the lever; today it’s GCC High.