Eplatforma
Disa here jam tu tentu me i marr ne telefon... Kurre nuk e hapin dhe thone "prisni qe nje agjent te lirohet..." dhe pastaj thjesht e mbyllin telefonin. Sherbim i tmerrshem. A din dikush si i kane oraret dhe qysh funksionon?
Disa here jam tu tentu me i marr ne telefon... Kurre nuk e hapin dhe thone "prisni qe nje agjent te lirohet..." dhe pastaj thjesht e mbyllin telefonin. Sherbim i tmerrshem. A din dikush si i kane oraret dhe qysh funksionon?
I am an position of a non-tech, but part of a tech team. For my daily work, i also need read access to staging cluster and have write access to testing environments also because i need it for work. That said, i have never been a Devops myself, i was a systems admin, i have solid networking foundations, and very very little experience in scripting. I do know how CI/CD work, how git works to a certain level and i can enter inside a container, see whats inside it, get pods, etc.
I have done bootcamps in the past - they didnt help. So now that i have real access to tech, i thought that my time has come to try and learn more about k8s.
My managers and teamates are extremely busy working on stuff and i dont want to bother them to spend time to babysit me.
I would like to find ways to ramp up my skills and become a real element in my team, by proving knowledge and propose initiatives that help.
Are there any public sources (not just AI) where i could learn and really become good? What would you recommend in general?
Many thanks!
Hello,
After 3 rounds of interviews, now I have a "Take Home Test".
I am currently a freelancer, but this is for a permanent position.
Can I send them a bill if I am not chosen?
It is 3 hours of work and my daily rate is around 700.
I just finished a migration from IMAP. Everything went smoothly. Except one user.
a stale b2b guest account used with the email address that previously on another tenant (on an old imap provider), when migrated, is unable to finish the first auth flow to an outlook client.
OWA works perfectly fine.
Tried so far:
- removed outlook profiles
- renamed on %APPDATA%
- cleaned WAM credentials on the device.
Sign in error shows exactly what it is:
User account '{user}' from identity provider '{idp}' does not exist in tenant '{tenant}' and cannot access the application '{application}'({appName}) in that tenant. The account needs to be added as an external user in the tenant first. Sign out and sign in again with a different Azure Active Directory user account
Additional Details
The account needs to be added as an external user in the tenant first. Sign out and sign in again with a different Azure Active Directory user account
This is only happening on Apps clients on Windows...
The auth flow still falls on its nown old tenant id of which it was a B2B Guest Account...
IMpossible for me to retrieve the owner of that tenant, having no contact with their IT Admin.
The error also shows that the object of the guest account was already removed and needs to be reinvited. Which I dont want. I want a clean new onboard on the NEW tenant as a full member of it. (Licensed with m365 business premium).
Anyone went through it?
What will happen to the other upn?
When they do the cutover from another provider to a custom owned domain... what happens to the .onmicrosoft.com email address that was authoritative? will they sitll have some "remnants" of those anywhere ?
for example:
microsoft authenticator will still keep .onmicrosoft.com ?
m365 (outlook) - will the "switch" to the account will be done automatically or is there a manual setup to be done there?
Many thanks
Hello,
I was wondering what causes this?
Is it because simply the user is on Windows Home instead of pro?
I inherited a bunch of pc bought with a home license in it and i am stuck doing mdm enrollement for those.
I have about 15 users.
WHat would be the best approach?
Edit:
my bad if i wasnt more specific.
I meant, how do you handle license provision to upgrade from home to pro for an NGO? i know that techsoup supports this, but are there any "volume" sort of licenses or how should we approach this? we are at very limited budget and we do not have a fixed IT team unfortunately because we cannot afford it. we are an association for protection of a marginalized community and we do not have so many funds.
So, i want to make them compliant but knowing that their budget is limited...
Is "upgrading" them directly from the microsoft store the right approach?
Cila nga makinat e kafese ne treg i bejne kafet "si ne Shqiperi" ?
Po shikoja kete:
Hello,
Anyone has come across their daily rate range? I wanted to engage as an associate auditor, but I want to make sure to make the right offer.
Their proposal is around 800€ per day, which seems a bit low to me.
I have created a tenant to migrate all my users from IMAP to m365. (also to the same existing domain which is yet to be verified before the cutover)
Possibly, due to the fact that the users were created more than 14 years ago, the MFA possibility has expired. I am getting a 0x80004136 error and when i check the sign in history, I see this for basically any possible way to sign in: OOBE, work/school account from Settings on a Windows computer... etc:
The user xxx was trying to sign into Microsoft Intune Company Portal and the sign-in was interrupted by Security Defaults. Microsoft Entra Security Defaults is a feature which helps keep your tenant secure by enforcing security best practices for your organization.
At the time of this sign-in, Security Defaults was enabled. The state of this policy as at the time of the diagnosis is Enabled.
This sign-in was interrupted since the user still needed to register for MFA. With Security Defaults, users have 14 days to register for Microsoft Entra multifactor authentication by using the Microsoft Authenticator app. The user cannot sign-in to applications until they have finished MFA registration once the 14 days have passed.
MFA helps keep your organization secure. Follow up with the user and encourage them to complete MFA registration.
See more information about the user's sign-in attempt below.
Is the only option disabling the security defaults at first log in for all users? I assume that all of the rest will have the problem during the switch over?
Disabling the security defaults would mean that MFA is not enforced anymore or will they be prompted anyway?
I have created a tenant to migrate all my users from IMAP to m365.
Possibly, due to the fact that the users were created more than 14 years ago, the MFA possibility has expired. I am getting a 0x80004136 error and when i check the sign in history, I see this for basically any possible way to sign in: OOBE, work/school account from Settings on a Windows computer... etc:
The user xxx was trying to sign into Microsoft Intune Company Portal and the sign-in was interrupted by Security Defaults. Microsoft Entra Security Defaults is a feature which helps keep your tenant secure by enforcing security best practices for your organization.
At the time of this sign-in, Security Defaults was enabled. The state of this policy as at the time of the diagnosis is Enabled.
This sign-in was interrupted since the user still needed to register for MFA. With Security Defaults, users have 14 days to register for Microsoft Entra multifactor authentication by using the Microsoft Authenticator app. The user cannot sign-in to applications until they have finished MFA registration once the 14 days have passed.
MFA helps keep your organization secure. Follow up with the user and encourage them to complete MFA registration.
See more information about the user's sign-in attempt below.
Is the only option disabling the security defaults at first log in for all users? I assume that all of the rest will have the problem during the switch over?
Disabling the security defaults would mean that MFA is not enforced anymore or will they be prompted anyway?
My brother has engineered a war against us.
I was raised to believe that as the youngest, it was my duty to care for our parents. I took it on genuinely, I thought it was a noble thing. It took me years to recognize the cost: severe compassion fatigue, deep wounds, and a slow erosion of my own life. When I finally found a way out, it felt like coming up for air.
Part of the original "deal" was that I'd inherit the family house in exchange for being the caretaker. My brother and his wife, both textbook narcissists spent years manipulating, gaslighting, and waging quiet war on everyone in the family. He's in conflict with literally every relative; the rest of us get along fine. By the end, I signed away my claim to the inheritance myself. Not because I wanted to, but because I was so depleted I just wanted out out of the fight, out of the contact, out of all of it. Also because he framed it as him taking over caretaker duty. He barely visits them.
Now the situation:
Three things I can't figure out:
I was raised to believe that as the youngest, it was my duty to care for our parents. I took it on genuinely, I thought it was a noble thing. It took me years to recognize the cost: severe compassion fatigue, deep wounds, and a slow erosion of my own life. When I finally found a way out, it felt like coming up for air.
Part of the original "deal" was that I'd inherit the family house in exchange for being the caretaker. My brother and his wife, both textbook narcissists spent years manipulating, gaslighting, and waging quiet war on everyone in the family. He's in conflict with literally every relative; the rest of us get along fine. By the end, I signed away my claim to the inheritance myself. Not because I wanted to, but because I was so depleted I just wanted out out of the fight, out of the contact, out of all of it. Also because he framed it as him taking over caretaker duty. He barely visits them.
Now the situation:
Three things I can't figure out:
TL;DR: Small NGO, Synology NAS, everyone shares one local account over SMB through OpenVPN. I want per-user identity (ideally Entra ID SSO) without taking drive letters away from non-technical users. Looking for the cleanest free/cheap architecture.
Current state
- Synology NAS, single shared local user, SMB shares
- OpenVPN on the Synology, port 1194 forwarded, dynamic DNS (ISP rotates IP every ~5 days)
- Users now are finally on M365 / Entra ID, managed via Intune
I am trying to achieve:
- Per-user authentication and audit on the NAS (no more shared account)
- SSO via Entra ID if possible
- Users still see a mapped drive (NAS_SERVER\ etc.) - they will not accept anything that looks like a web UI
What I've tried / considered:
- OpenVPN with username+password works for the tunnel, but the NAS auth underneath through SMB still needs username and password.
- Thought about pushing SAML SSO via Intune, but I still need something to mount the share
- some friends of mine suggested ditching SMB for S3/HTTP, which is architecturally cleaner but the "map the server" kind of approach by the users as requirement kills it
Replace OpenVPN with Tailscale (if i can get the free tier, Entra SSO, ACLs, no port forwarding, survives IP changes and CGNAT)
Join the Synology to Entra ID (or LDAP-sync users) so each person has their own NAS account
Push a mapped-drive script via Intune so users still get Z:\
Anyone running this Tailscale + Entra-synced Synology + Intune-mapped-drive combo in production? Gotchas?
- Better alternatives I'm missing?
- Is there a sane way to do Entra SSO directly to SMB shares on Synology, or am I always going to need an LDAP/AD bridge?
Users of a NGO (that are not techies) are migrating from IMAP to M365.
I did a test with one of the users who explicitely refuses to use Microsoft Authenticator (and that is allowed by the director) but instead wants to use SMS.
- i disabled registration campaign
- made sure SMS is enabled as mfa option
Signed them out of all sessions, re-required mfa setup, but i can only see the Microsoft Authenticator screen.
This is for a first time ever login.
The only thing that seemed to do the trick is me manually adding their phone numbers on Entra.
Could somebody support what am I missing?
Hello,
I would like to advise proton pass to a ngo as password manager. I was wondering does protonpass support auto provisioning / deprovisioning from hris systems, active directory or ldaps?
Psh ti thush ndonjerit me zinxhir te trashe ne qafe: "pse pshtyve ne toke, merr fshije tashi" ose "ngri cik kte plehren qe e hodhe ne mes te rruges"🤔
Hello berliners,
I have seen these kind of posts on Immobilienscout:
Müggelheim (Köpenick) | Mietkauf+ | StV 134m² | EBK + Garage | keine Stromkosten durch Solar
I was wondering how legit they are and why do they seem "cheap" ?
Does anybody have any experience with this kind of services?
My understanding is that an amount of your "miete" would go into the eventual purchase of the house/apartment? How does it actually work?
Looking for some help from the community 🙏
I am looking to break into becoming a CISO, with all the stress, challenges, perks and growth opportunities that comes with it. I genuinly think I am ready. I talk middle management language, I can sit in a room with DevOps for 3 to 4 hours, I have led and hosted audits with VP level individuals. Have confidently responded to audits as an interviewee in multiple occasions. Yet, I remain in operational roles as information security consultant/expert/specialist/coordinator, while i strongly believe that I could be much more valuable at strategic levels.
Here is my background:
CISSP-certified cybersecurity leader based in Western Europe (Luxemburg, Netherlands, Belgium, France or Germany).
15+ years of experience spanning GRC, security operations, cloud security and IT infrastructure.
Certifications: CISSP (ISC2), ISO 27001 Lead Implementer (PECB), ISO 27001 Lead Auditor, SOC Analyst
Languages: French (native), English (fluent), German (B1)
EXPERIENCE
----------
[2024–Present] Information Security Manager
Pharma SaaS company (regulated cloud product), Remote/Hybrid Germany, france, Italy, Netherlands and Belgium
- Led end-to-end SOC2 type I and type II attestation, owning the full compliance lifecycle from scoping and control design through Big 4 auditor engagement and successful attestation
- Defined Target Operating Model (TOM) for cloud security compliance
- Authored security policies, procedures and controls aligned to BSI C5, NIS2 and ISO 27001
- Served as strategic interface between executive and technical stakeholders across multiple geographies
- Coordinated global cross-functional delivery teams (IT, Risk, Manufacturing, Security)
[2023–2024] Technical Security Consultant / Enterprise Systems Security Administrator
Freelance — Critical infrastructure and financial sector clients, Germany & Belgium
- SIEM integration and configuration (Microsoft Sentinel, Splunk) for critical infrastructure
- Managed Azure and Microsoft 365 security; deployed XDR solutions
- ISO 27001 internal reviews and gap assessments
- DORA resilience implementation for financial sector clients
- Security product evaluation and selection
- Security awareness training and phishing simulation programmes
[2022–2023] Information Security Engineer / IT Operations Engineer
Digital SaaS company (~500 employees), Berlin
- Adversarial simulations and phishing campaigns; assessed effectiveness of countermeasures
- Incident response; tuned SIEM detection rules and playbooks
- DevSecOps collaboration: integrated security controls into SDLC
- Security policies and controls authored to regulatory standards
[2021–2022] IT Systems Administrator — Network & Security
Dating/social platform (~300 employees), Berlin
- Hardened Linux environments; managed PostgreSQL, Apache/NGINX
- Configured Juniper SRX and Palo Alto NGFW firewalls; enforced network access policies
- AWS cloud workloads (EC2, EBS, VPC, S3, FSx); applied cloud security controls
- Virtualisation (VMware vSphere, Hyper-V)
[2009–2021] Information Technology Expert
Consultant — Various major European organisations (EU institutions, telecom operators, financial sector)
- On-site provisioning administrator and 2nd-line technical support at two major national telecom
operators (2011–2013): service provisioning workflows, escalated technical issue resolution
- Network segmentation (VLANs, DMZ, firewall ACLs), RBAC in LDAP/Active Directory
- Policy drafting, asset inventory, risk management framework participation (as auditee)
- ICT support at EU institutions, including VIP-level technical resolution
SKILLS
------
Frameworks: ISO 27001/27002, NIS2, BSI C5, DORA, GDPR, EU CRA, NIST CSF
Security Operations: SIEM (Sentinel, Splunk, Kibana), XDR, Threat Detection, Incident Response
Cloud: Azure Security, M365 Security, AWS Security, IAM
Infrastructure: Linux, VMware, Docker, Kubernetes, Terraform, Python
Leadership: Security Transformation, TOM Design, Global Delivery, Stakeholder Management
WHAT I AM LOOKING FOR / CONTEXT FOR FEEDBACK
---------------------------------------------
I have been applying to CISO and Director of Information Security roles in Europe
(primarily Germany, Belgium, Switzerland) without success so far. I hold CISSP,
ISO 27001 Lead Implementer and Lead Auditor, and have recently completed a full
scale SOC2 type I and type II attestation as well as have end to end certified three health tech / fintech clients with ISO27001.
I have interim CISO experience but no formal CISO title on my CV.
My questions for the community:
Is my profile realistic for CISO roles?
My background has moved between consulting, freelance and FTE roles — does that fragmentation hurt my candidacy?
Education: I do not hold a university degree. Is that a hard blocker at CISO level in Europe?
Any other gaps or red flags you see that I might be blind to?
Honest and critical feedback very welcome.
I was raised to believe that as the youngest, it was my duty to care for our parents. I took it on genuinely, I thought it was a noble thing. It took me years to recognize the cost: severe compassion fatigue, deep wounds, and a slow erosion of my own life. When I finally found a way out, it felt like coming up for air.
Part of the original "deal" was that I'd inherit the family house in exchange for being the caretaker. My brother and his wife, both textbook narcissists spent years manipulating, gaslighting, and waging quiet war on everyone in the family. He's in conflict with literally every relative; the rest of us get along fine. By the end, I signed away my claim to the inheritance myself. Not because I wanted to, but because I was so depleted I just wanted out out of the fight, out of the contact, out of all of it. Also because he framed it as him taking over caretaker duty. He barely visits them.
Now the situation:
Three things I can't figure out: