home.social

#simplifynow — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #simplifynow, aggregated by home.social.

fetched live
  1. Ready for #MSExchangeSummit in Würzburg, Germany! Speaking today after lunch: “We need to talk about (on-prem) Exchange Server”
    #MSExchange #Microsoft365 #SimplifyNow #SMTP

  2. Ready for #MSExchangeSummit in Würzburg, Germany! Speaking today after lunch: “We need to talk about (on-prem) Exchange Server”
    #MSExchange #Microsoft365 #SimplifyNow #SMTP

  3. As a recipient org that receives forwarded mails, you might want to read up on Authenticated Received Chain or #ARC. While #SRS fixes any #SPF issues, that will still cause #DKIM and #DMARC validation issues. If the forwarding org has ARC, you can trust their authentication results by adding them as a trusted ARC sealer. More info: learn.microsoft.com/en-us/defe

    #SimplifyNow #MSExchange #SMTP

  4. As a forwarder you might want to read up on Sender Rewriting Scheme or #SRS, and how #Microsoft365 manages this. This is a solution for #SPF fails due to forwarding. Do note, if you route via an on-prem infrastructure, there might be a need to adjust a setting to force SRS. More info: learn.microsoft.com/en-us/exch

    #SimplifyNow #MSExchange #SMTP

  5. As a forwarder you might want to read up on Sender Rewriting Scheme or #SRS, and how #Microsoft365 manages this. This is a solution for #SPF fails due to forwarding. Do note, if you route via an on-prem infrastructure, there might be a need to adjust a setting to force SRS. More info: learn.microsoft.com/en-us/exch

    #SimplifyNow #MSExchange #SMTP

  6. As a recipient org that receives forwarded mails, you might want to read up on Authenticated Received Chain or #ARC. While #SRS fixes any #SPF issues, that will still cause #DKIM and #DMARC validation issues. If the forwarding org has ARC, you can trust their authentication results by adding them as a trusted ARC sealer. More info: learn.microsoft.com/en-us/defe

    #SimplifyNow #MSExchange #SMTP

  7. Reading #WeekITtip for the weekend. I am currently involved in a case in which mail (auto)forwarding is used but that is causing the forwarded mail to be rejected. When #SPF, #DKIM and #DMARC are implemented properly, this can break legitimate mail forwarding.

    #SimplifyNow #MSExchange #SMTP

  8. Reading #WeekITtip for the weekend. I am currently involved in a case in which mail (auto)forwarding is used but that is causing the forwarded mail to be rejected. When #SPF, #DKIM and #DMARC are implemented properly, this can break legitimate mail forwarding.

    #SimplifyNow #MSExchange #SMTP

  9. Also check several breaking changes in #MSExchange Online such as legacy tokens, EWS deprecation, but also external recipient rate limits. Some take effect in January, others (much) later but some mitigations might take time.

    Now you have some of your #SMTP New year resolutions! 😉 See you next year!

    #SimplifyNow

  10. Also check several breaking changes in #MSExchange Online such as legacy tokens, EWS deprecation, but also external recipient rate limits. Some take effect in January, others (much) later but some mitigations might take time.

    Now you have some of your #SMTP New year resolutions! 😉 See you next year!

    #SimplifyNow

  11. Now #Microsoft has announced the rollout for #Mobile Outlook iOS/Android in Message Center MC960818. You do not have to do anything, but evaluate if the older add-in is still required. See also: microsoft.com/en-US/microsoft-

    This might also be a time to do a (periodic!) review of your overall #Defender settings, processes, and awareness training (with an ethical attack simulation). Like previously indicated, there are still a lot of incoming threats via email.

    #SimplifyNow #Security

  12. Now #Microsoft has announced the rollout for #Mobile Outlook iOS/Android in Message Center MC960818. You do not have to do anything, but evaluate if the older add-in is still required. See also: microsoft.com/en-US/microsoft-

    This might also be a time to do a (periodic!) review of your overall #Defender settings, processes, and awareness training (with an ethical attack simulation). Like previously indicated, there are still a lot of incoming threats via email.

    #SimplifyNow #Security

  13. Day 23 of #ITAdvent. More than a week ago I posted about the Junk Report button being integrated within Classic #Outlook. New Outlook & OotW (Outlook on the Web) already had that button. This would remove the need to deploy the reporting add-in in those clients.

    #SimplifyNow #Security

  14. Day 23 of #ITAdvent. More than a week ago I posted about the Junk Report button being integrated within Classic #Outlook. New Outlook & OotW (Outlook on the Web) already had that button. This would remove the need to deploy the reporting add-in in those clients.

    #SimplifyNow #Security

  15. Third party sites might still have #MSExchange courses online, at least #Pluralsight has a few courses. CBTNuggets seems to still have a Certification preparation. But be aware that these courses may not be up to date anymore. You might find some YouTube channels, but I haven't checked myself.

    #SimplifyNow #Training

  16. There are still #MSExchange books being sold but be sure to check the most recent release. At least I know "Pro Exchange Administration" is relatively up to date: link.springer.com/book/10.1007 . For more #PowerShell focus the practicalpowershell.com books are an option (note: cocreator of those). For more general #Microsoft365 focus, I can recommend "Office 365 for IT pros": o365itpros.gumroad.com/l/O365IT which has monthly updates.

    #SimplifyNow #Training

  17. Unfortunately, these options are all provide you can self-learn or might miss important real-life nuance and trainer interaction. Of course you could use fora, social media to ask your specific questions. As a last resort you could ask known trainers (MCTs or often MVPs) to develop a custom course or workshop.

    #SimplifyNow #Training

  18. Third party sites might still have #MSExchange courses online, at least #Pluralsight has a few courses. CBTNuggets seems to still have a Certification preparation. But be aware that these courses may not be up to date anymore. You might find some YouTube channels, but I haven't checked myself.

    #SimplifyNow #Training

  19. Unfortunately, these options are all provide you can self-learn or might miss important real-life nuance and trainer interaction. Of course you could use fora, social media to ask your specific questions. As a last resort you could ask known trainers (MCTs or often MVPs) to develop a custom course or workshop.

    #SimplifyNow #Training

  20. There are still #MSExchange books being sold but be sure to check the most recent release. At least I know "Pro Exchange Administration" is relatively up to date: link.springer.com/book/10.1007 . For more #PowerShell focus the practicalpowershell.com books are an option (note: cocreator of those). For more general #Microsoft365 focus, I can recommend "Office 365 for IT pros": o365itpros.gumroad.com/l/O365IT which has monthly updates.

    #SimplifyNow #Training

  21. Day 22 of #ITAdvent. There is no #Microsoft #MSExchange specific #certification available. Which unfortunately also means that there is less training offered, as they are based on Microsoft Official Courseware or #MOC. So, I sometimes see the question what options there are.

    Obviously, #MicrosoftLearn sites were already a replacement for any books used during those MOCs. However, there is no Learning Path/Modules available that covers everything. learn.microsoft.com/en-us/trai

    #SimplifyNow #Training

  22. Day 22 of #ITAdvent. There is no #Microsoft #MSExchange specific #certification available. Which unfortunately also means that there is less training offered, as they are based on Microsoft Official Courseware or #MOC. So, I sometimes see the question what options there are.

    Obviously, #MicrosoftLearn sites were already a replacement for any books used during those MOCs. However, there is no Learning Path/Modules available that covers everything. learn.microsoft.com/en-us/trai

    #SimplifyNow #Training

  23. There are still #MSExchange books being sold but be sure to check the most recent release. At least I know "Pro Exchange Administration" is relatively up to date: link.springer.com/book/10.1007 . For more #PowerShell focus the practicalpowershell.com books are an option (note: cocreator of those). For more general #Microsoft365 focus, I can recommend "Office 365 for IT pros": o365itpros.gumroad.com/l/O365IT which has monthly updates.

    #SimplifyNow #Training

  24. There are still #MSExchange books being sold but be sure to check the most recent release. At least I know "Pro Exchange Administration" is relatively up to date: link.springer.com/book/10.1007 . For more #PowerShell focus the practicalpowershell.com books are an option (note: cocreator of those). For more general #Microsoft365 focus, I can recommend "Office 365 for IT pros": o365itpros.gumroad.com/l/O365IT which has monthly updates.

    #SimplifyNow #Training

  25. Third party sites might still have #MSExchange courses online, at least #Pluralsight has a few courses. CBTNuggets seems to still have a Certification preparation. But be aware that these courses may not be up to date anymore. You might find some YouTube channels, but I haven't checked myself.

    #SimplifyNow #Training

  26. Day 22 of #ITAdvent. There is no #Microsoft #MSExchange specific #certification available. Which unfortunately also means that there is less training offered, as they are based on Microsoft Official Courseware or #MOC. So, I sometimes see the question what options there are.

    Obviously, #MicrosoftLearn sites were already a replacement for any books used during those MOCs. However, there is no Learning Path/Modules available that covers everything. learn.microsoft.com/en-us/trai

    #SimplifyNow #Training

  27. Third party sites might still have #MSExchange courses online, at least #Pluralsight has a few courses. CBTNuggets seems to still have a Certification preparation. But be aware that these courses may not be up to date anymore. You might find some YouTube channels, but I haven't checked myself.

    #SimplifyNow #Training

  28. Day 22 of #ITAdvent. There is no #Microsoft #MSExchange specific #certification available. Which unfortunately also means that there is less training offered, as they are based on Microsoft Official Courseware or #MOC. So, I sometimes see the question what options there are.

    Obviously, #MicrosoftLearn sites were already a replacement for any books used during those MOCs. However, there is no Learning Path/Modules available that covers everything. learn.microsoft.com/en-us/trai

    #SimplifyNow #Training

  29. Read this blog on how to do so: techcommunity.microsoft.com/bl

    Don't forget other upcoming potentially breaking changes, such as removal of legacy tokens, EWS and Client Access rules, enforcing external recipient rate limits to name some.

    #SimplifyNow

  30. Read this blog on how to do so: techcommunity.microsoft.com/bl

    Don't forget other upcoming potentially breaking changes, such as removal of legacy tokens, EWS and Client Access rules, enforcing external recipient rate limits to name some.

    #SimplifyNow

  31. ...The maximum results is increased from 1000 to 5000 though. You might have to change your scripts as this might be a breaking change, I know that I wil have to.

    Read more: techcommunity.microsoft.com/bl

    #SimplifyNow #Mail #SMTP

  32. ...The maximum results is increased from 1000 to 5000 though. You might have to change your scripts as this might be a breaking change, I know that I wil have to.

    Read more: techcommunity.microsoft.com/bl

    #SimplifyNow #Mail #SMTP

  33. The findings are interesting, and I wonder why the adoption is not higher. Most protocols are not that hard to adopt for most situations, but perhaps I am missing things. I for one am open to give workshops, trains and consult your org if needed. And I am sure a lot of other experts are willing as well.

    You can read the post here: forumstandaardisatie.nl/nieuws

    #SimplifyNow #Security #Compliance

  34. The findings are interesting, and I wonder why the adoption is not higher. Most protocols are not that hard to adopt for most situations, but perhaps I am missing things. I for one am open to give workshops, trains and consult your org if needed. And I am sure a lot of other experts are willing as well.

    You can read the post here: forumstandaardisatie.nl/nieuws

    #SimplifyNow #Security #Compliance

  35. Day 19 of #ITAdvent. The Dutch Forum Standarisatie is a Dutch Advisory commity on IT open standards in order to easily and safeliy exchange data between government bodies, companies, non-profits and citizens. They maintain lists of mandatory and recommended protocols for at least governmental bodies. But IMHO every organization should adopt these.

    #SimplifyNow #Security #Compliance

  36. Today they published the rate of adoptions of these protocols and concludes that there is a lot of work to be done and urges orgs to pick up the rate of adoption, make plans, set target dates and implement them. There are explicit mentions of #DANE and #IPv6 now that #MSExchange Online supports them.

    #SimplifyNow #Security #Compliance

  37. Day 19 of #ITAdvent. The Dutch Forum Standarisatie is a Dutch Advisory commity on IT open standards in order to easily and safeliy exchange data between government bodies, companies, non-profits and citizens. They maintain lists of mandatory and recommended protocols for at least governmental bodies. But IMHO every organization should adopt these.

    #SimplifyNow #Security #Compliance

  38. Today they published the rate of adoptions of these protocols and concludes that there is a lot of work to be done and urges orgs to pick up the rate of adoption, make plans, set target dates and implement them. There are explicit mentions of #DANE and #IPv6 now that #MSExchange Online supports them.

    #SimplifyNow #Security #Compliance

  39. Do note that I've just scratched the surface and there are a lot of nuances IRL. This is my attempt to create greater awareness of these protocols, the need for them and the need to configure and use them properly for your organization. Let's make mail a little bit safer!

    #SimplifyNow #SMTP #Authentication #Security

  40. Do note that I've just scratched the surface and there are a lot of nuances IRL. This is my attempt to create greater awareness of these protocols, the need for them and the need to configure and use them properly for your organization. Let's make mail a little bit safer!

    #SimplifyNow #SMTP #Authentication #Security

  41. - Mail is manipulated after DKIM signing has occurred, for instance by adding disclaimers or subject tags. So, be sure to check your mail infra.
    - Often a 1024 key length is still used, while 2048 is more robust. Solve this in #MSExchange Online by rotating your DKIM keys with PowerShell and setting a higher key length. See more here: learn.microsoft.com/en-us/defe

    Have you checked your environment for these issues? Did you see other issues with DKIM?

    #SimplifyNow #Security #Compliance

  42. - Mail is manipulated after DKIM signing has occurred, for instance by adding disclaimers or subject tags. So, be sure to check your mail infra.
    - Often a 1024 key length is still used, while 2048 is more robust. Solve this in #MSExchange Online by rotating your DKIM keys with PowerShell and setting a higher key length. See more here: learn.microsoft.com/en-us/defe

    Have you checked your environment for these issues? Did you see other issues with DKIM?

    #SimplifyNow #Security #Compliance

  43. Luckily, there are various tools & services that can check syntax or flatten your record by replacing includes with IP addresses, reducing the DNS lookups. Often, those services also offer DMARC reporting (I will come back to that on a later day) analysis.

    Did I forget any common mistakes? Do you have any you want to share?
    If you want to dig deep in SPF, read the RFC7208: datatracker.ietf.org/doc/html/

    #SimplifyNow #SMTP #Security #Authentication

  44. Luckily, there are various tools & services that can check syntax or flatten your record by replacing includes with IP addresses, reducing the DNS lookups. Often, those services also offer DMARC reporting (I will come back to that on a later day) analysis.

    Did I forget any common mistakes? Do you have any you want to share?
    If you want to dig deep in SPF, read the RFC7208: datatracker.ietf.org/doc/html/

    #SimplifyNow #SMTP #Security #Authentication

  45. Day 16 of #ITAdvent. Let's talk about #SPF or Sender Policy Framework! Especially the most common mistakes I see happening, be sure to check those periodically (but during the holiday period you also might have time to do this):

    - Forgotten sub domains: SPF does not inherit to subdomains
    - Not having a correct syntax: typos or linefeeds where they shouldn't.

    #SimplifyNow #SMTP #Security #Authentication

  46. Day 16 of #ITAdvent. Let's talk about #SPF or Sender Policy Framework! Especially the most common mistakes I see happening, be sure to check those periodically (but during the holiday period you also might have time to do this):

    - Forgotten sub domains: SPF does not inherit to subdomains
    - Not having a correct syntax: typos or linefeeds where they shouldn't.

    #SimplifyNow #SMTP #Security #Authentication

  47. Obviously, there are other options available, some depend on which license the Meeting Organizer has. Do note that also the recording itself has additional configuration options, such as retention. support.microsoft.com/en-us/of

    #SimplifyNow #Microsoft365

  48. Obviously, there are other options available, some depend on which license the Meeting Organizer has. Do note that also the recording itself has additional configuration options, such as retention. support.microsoft.com/en-us/of

    #SimplifyNow #Microsoft365

  49. Do note: With MC841229 the recent rollout of the default Report button in Classic #Outlook was announced, no longer requiring an add-in be pushed. Be sure to check whether your users now might have two buttons to report and change your config and/or documentation.

    #SimplifyNow #Defender #MSExchange #Phishing #Junk

  50. Do note: With MC841229 the recent rollout of the default Report button in Classic #Outlook was announced, no longer requiring an add-in be pushed. Be sure to check whether your users now might have two buttons to report and change your config and/or documentation.

    #SimplifyNow #Defender #MSExchange #Phishing #Junk

  51. Besides having (filtering) protections in place, be sure to educate your users about what to do, for instance to report suspicious mail but also how they should respond if they do where tricked into clicking malicious mails. In various #Outlook clients, users can use a Report button. See: learn.microsoft.com/en-us/defe

    #SimplifyNow #Defender #MSExchange #Phishing #Junk

  52. Day 14 of #ITAdvent. In 2024 #Microsoft reported in their Digital Defense Report 2024 that #Phishing is still the greatest threat from #mail. So, it's good to periodically review your orgs #security preparedness on this.

    #SimplifyNow #Defender #MSExchange #Phishing #Junk

  53. Besides having (filtering) protections in place, be sure to educate your users about what to do, for instance to report suspicious mail but also how they should respond if they do where tricked into clicking malicious mails. In various #Outlook clients, users can use a Report button. See: learn.microsoft.com/en-us/defe

    #SimplifyNow #Defender #MSExchange #Phishing #Junk

  54. Day 14 of #ITAdvent. In 2024 #Microsoft reported in their Digital Defense Report 2024 that #Phishing is still the greatest threat from #mail. So, it's good to periodically review your orgs #security preparedness on this.

    #SimplifyNow #Defender #MSExchange #Phishing #Junk

  55. I couldn't quickly find an overview article from #Microsoft, but in my search I came across msshells.net/ that lists the different modules, their latest stable version and a way to install them. As far as I could tell it's still correctly maintained. Looks like a site to bookmark!

    #SimplifyNow #Management #Script

  56. I couldn't quickly find an overview article from #Microsoft, but in my search I came across msshells.net/ that lists the different modules, their latest stable version and a way to install them. As far as I could tell it's still correctly maintained. Looks like a site to bookmark!

    #SimplifyNow #Management #Script

  57. Day 13 of #ITADvent. Administrating #Microsoft365 comes with a lot of #PowerShell work, requiring to install and update lots of different modules. The ones I have to use frequently I know by heart. Others, not so much...

    #SimplifyNow #Management #Script

  58. Day 13 of #ITADvent. Administrating #Microsoft365 comes with a lot of #PowerShell work, requiring to install and update lots of different modules. The ones I have to use frequently I know by heart. Others, not so much...

    #SimplifyNow #Management #Script

  59. Day 12 of #ITAdvent. Be sure to check whether you have apps/devices that send #mail with multiple FROM: headers (or P2) without a SENDER: header. To comply with RFC5322 #Microsoft365 will reject those mails.

    Why? "Most of the traffic exhibiting multiple P2 From Addresses without a Sender Address will be inbound spam destined for your tenant sent by malicious spammers on the internet." as stated in #MC886603. However, you could have valid mail that does this.

    #SimplifyNow #SMTP

  60. Day 12 of #ITAdvent. Be sure to check whether you have apps/devices that send #mail with multiple FROM: headers (or P2) without a SENDER: header. To comply with RFC5322 #Microsoft365 will reject those mails.

    Why? "Most of the traffic exhibiting multiple P2 From Addresses without a Sender Address will be inbound spam destined for your tenant sent by malicious spammers on the internet." as stated in #MC886603. However, you could have valid mail that does this.

    #SimplifyNow #SMTP