User Profile
sbonn
Copper Contributor
Joined 6 years ago
User Widgets
Recent Discussions
Re: Whitelisting domain in DLP policy
we too concluded that the administrativve overhead, plus the high amount of whitelisted domain to dept exclusions would lead to failure (a DLP policy has a size limit) so we end up without a solution for now and let everything out and a 1FTE monitoring everything that gets out.... not ideal204Views0likes0Commentssharepoint online DisableCompanyWideSharingLinks
reposting Igor's question here as per MSFT's suggestion : "How can I disable the 'Share with entire organization' option globally for OneDrive and SharePoint in Microsoft 365? I've examined the documentation athttps://learn.microsoft.com/en-us/microsoft-365/solutions/microsoft-365-limit-sharing?view=o365-worldwide#sharing-with-specific-peopleand discovered PowerShell commands such as 'Set-SPOSite -Identityhttps://contoso.sharepoint.com-DisableCompanyWideSharingLinks Disabled' for SharePoint sites and 'Set-SPOSite -Identityhttps://contoso-my.sharepoint.com/personal/my_alias_contoso_com-DisableCompanyWideSharingLinks Disabled' for OneDrives. The challenge is executing these commands for each site and user in our environment. Is there a method to apply this globally across the entire organization?"1.1KViews0likes3Comments- 1.3KViews0likes0Comments
- 1.3KViews0likes2Comments
Re: High CPU/Memory utilization using WMI to read Security Event log
scottystunz: we ended up compromizing with the infrastructure team by dropping the security.evtx to 2gb, they get some ram back, at the expense of loosing a bit of retention. noted that some of the events in theres are cherry picked to be sent to SIEM. the only theory of why it work like this is to be able to continue logging events if the system lose access to disk writes. that way, you can scrape the RAM for the latest evtx in forensic situations.11KViews0likes0CommentsRe: High CPU/Memory utilization using WMI to read Security Event log
Funny that the only posts n the internet regarding this New behavior where there is some kind of answers are not on the official Microsoft Forums m_giusti. why is Microsoft silent on this matter? Microsoft should be more transparent when making changes that have huge impact on memory as this. we log more and more stuff into security.evtx as per cybersecurity recommendation dictate, thus upping the evtx to 4GB to retain some acceptable retention, but this loading of the file in memory is now affecting our users windows machines as well as our servers's memory consumption. we now face a dillema, where we need some log retention, but also want to mitigate this memory usage issues...12KViews0likes0Comments