Profile avatar
plasticlicker.bsky.social
InfoSec Director for non-profits (Nation State threats, non-profit budgets!) I talk mostly about Cybersecurity and Tech but occasionally cats (got my handle from one of them), urbanism, transportation politics and woodworking. My tweets are my own.
87 posts 65 followers 101 following
Regular Contributor
Active Commenter

We're capping a month-long WIC celebration with a full day of content, commentary, and discussion. Women in Cybersecurity Month Caps off with Our First Day-long Conference www.microsoftsecurityinsights.com/p/women-in-c... Register to attend: developer.microsoft.com/en-us/reacto...

Judge John Bates characterized the government’s position as “we’re not an agency where we don’t want to be an agency, but we are an agency this one instance where we want to be.”

I think this may be a first for me, SSO included in the base tier! 🤯Who says miracles can't happen!

⚠️FLOOD YOUR FEEDS!⚠️ Della MacDonald, 14, was last seen at the Virginia Museum of Fine Arts on Saturday. Police said she has not contacted her family since that day.

Reminder: supporting the war in Ukraine is literally the most cost effective project the US military has ever undertaken. For a something like eight percent of the Pentagon’s annual budget, we have reduced the Russian military by something like half, a decades-long setback. Don’t let Russia win now.

👀

As someone with horrible spelling skills, why isn’t spell check universal in Microsoft tools?!? It could be at the Windows OS or Edge browser level or at the product level (or all of the above), I’m begging! 🙏 @jenmsft.bsky.social can you poke people?

I really wish Microsoft Defender Attack Simulation provided randomization options, both for delivery and campaign. I want to be able to spread out the campaign delivery over time and randomize what people get.

I have one caller confirmed, and another pending. Looking to fill the last slot for next Friday afternoon!

Great insights with greats tips for specific licensing levels in your Entra ID tenant. Have you checked these strategies yet?

👀

Strawman scenario for the weekend. What security controls would you want in place at your organization before you’d accept “coffee shop” WiFi for your office network (WPA2-PSK or lower)? Client isolation and no services available on the network are a must; anything else?

CNN with an absolutely gigantic story: "Elon Musk’s top lieutenants at the Treasury Department asked its acting secretary, a career civil servant, to immediately shut off all USAID payments using the department’s own ultra-sensitive payment processing system." edition.cnn.com/2025/02/06/p...

Car culture in this country is just so sad.

Using Windows Autopatch? You might need to take action! #WUfB #Windows #WindowsAutopatch

Just stumbled upon this cool lab for Defender for Identity Most of the time, IT teams are implementing the solution and don't usually know how to validate I love that these labs give a bunch of examples and how to handle the alerts that get generated :) microsoft.github.io/...

Patrick Mahomes has replaced two decades of playoff heartbreak with a postseason run so routine that is has its own conspiracies. From Star columnist Sam McDowell:

I think the most common misunderstanding of Conditional Access is its relationship to authentication, and this results in not understanding how the rest of the controls actually work Conditional Access performs authorization by evaluating tokens from the authentication service

Why is EVERY SINGLE TIME I don’t check a carry out order it’s wrong. 🤬

The amount of pearl clutching by Bamboo Studio users who dismiss cybersecurity as a reason for the update who then go in to demonstrate how little they understand cloud security is amazing.

The US government can’t be under cyberattacks by nation state actors if we can’t detect the hacking

This is what happens when populism and anti-science people get together.

📰 OIB 3.4 News! I'm busy finalising changes/updates to v3.4 of the #OpenIntuneBaseline. Some forewarning of a "breaking change" in that all policies have been renamed to show where they actually exist (ES - Endpoint Security, SC - Settings Catalog). I still don't like it :(

Entra doesn't have a description field when we allow/block AAGUIDs for passkeys, so I wrote a script to get the MDS from the FIDO alliance and give a description for each allowed/blocked AAGUID on the tenant :) github.com/nathanmcn... Thanks to @janbakker_ for the nudge :)