egosumdns Profile Banner
Daniel Streefkerk Profile
Daniel Streefkerk

@egosumdns

Followers
543
Following
7K
Media
31
Statuses
332

Christian, Husband, Father, IT & Cyber Dabbler. Spent nearly 2 decades in the IT support & ops trenches before moving across to cyber security since 2019.

Straya
Joined July 2009
Don't wanna be here? Send us removal request.
@TomFabianoo
Tom
10 days
I can't believe I still see this in security recommendations, compliance requirements or advise given in social media.
@merill
Merill Fernando
2 years
It's 2023 and your IT team is still forcing the entire company to change their passwords every few months 🤦 PS. I work at Microsoft, and we stopped doing this nearly four years ago. Send the link below to your IT team šŸ‘‡
31
25
445
@dhh
DHH
18 days
We're saving well over two million dollars per year on this cloud exit. We got much faster gear (local nvme storage vs network mounts is a game changer!). We own all our hardware. And when things go down, we can actually do something about it ourselves.
Tweet card summary image
basecamp.com
We’ve run extensively in both Amazon’s cloud and Google’s cloud, but the savings never materialized. So we’ve left.
21
63
1K
@kennethvs
Kenneth van Surksum - MVP
27 days
When ā€œBlock Allā€ in Conditional Access blocks too much… šŸ”’ Until recently, guest users couldn’t change their MFA methods when you blocked all cloud apps. The My Sign-ins app is now selectable in Conditional Access šŸŽ‰ Finally possible: āœ… Limit guests to M365 resources āœ… Keep
Tweet card summary image
vansurksum.com
Introduction Configuring Conditional Access (CA) for guest users can be challenging when you want to strictly limit access to Office 365 and a few essential Microsoft services. Many Entra administr...
0
20
132
@IceSolst
solst/ICE of Astarte
29 days
There’s a less known edge case for fortinet devices where, rather than act merely as a remote code execution platform, they can serve as firewalls
30
61
633
@SenatorAntic
Senator Alex Antic
1 month
The Office of the eSafety Commissioner has produced a guidance note to assist social media companies with the fast approaching under 16 social media ban. The methods used to verify age are likely to include the disclosure of sensitive data like documents, facial scans, location
0
428
2K
@NathanMcNulty
Nathan McNulty
1 month
Did you know Entra ID Protection never automatically clears Medium or High risk? We either need to use Risk Based Conditional Access policies to remediate or an admin needs to manually remediate User risk = password reset Sign-in risk = require MFA https://t.co/T1KT4DQbhl
8
15
131
@NathanMcNulty
Nathan McNulty
1 month
Please stop using Private browser sessions for cloud admin accounts Look, we all know we shouldn't be using admin accounts while signed into our productivity account, but if you're gonna do it, at least use browser profiles so you can enforce compliance https://t.co/e8I882Lh9w
31
75
421
@dhh
DHH
2 months
Cookie banners have been a blight on the internet. Worse than the old scourge of pop-up advertisements! They need to die entirely. The idea has failed. Nobody reads any of it. If you want to ban targeted ads, do that. Let's see if the EU can correct,
Tweet card summary image
politico.eu
The European Commission wants to take a bite out of privacy rules that force websites to run cookie banners.
189
222
3K
@TJMoe28
T.J. Moe
2 months
This is the embodiment of Christianity. Forgiving the man who assassinated your husband while you’re grieving at his funeral because that’s what Christ did for you. God bless Erika Kirk.
71
357
3K
@egosumdns
Daniel Streefkerk
2 months
Is it just me, or does this UI choice in Firefox drive other people mad too? Burying "Close Other Tabs" in a sub-menu when something as rarely-used as "Close Duplicate Tabs" gets a spot on the main context menu.
0
0
1
@_dirkjan
Dirk-jan
2 months
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog:
dirkjanm.io
While preparing for my Black Hat and DEF CON talks in July of this year, I found the most impactful Entra ID vulnerability that I will probably ever find. One that could have allowed me to compromise...
143
906
3K
@egosumdns
Daniel Streefkerk
2 months
Was just looking at the issues on a MCP-related repo, saw this cheeky GitHub Issue... #mcp #promptinjection
0
0
1
@fabian_bader
Fabian Bader
2 months
Sentinel UEBA got a welcome set of new data sources ā—½Defender XDR device logon events ā—½Entra ID managed identity signin logs ā—½Entra ID service principal signin logs ā—½AWS CloudTrail ā—½GCP audit logs ā—½Okta MFA https://t.co/l9ZLvnDQ0U
Tweet card summary image
techcommunity.microsoft.com
Co-author - Ashwin Patil Security teams today face an overwhelming challenge: every data point is now a potential security signal and SOCs are drowning in...
1
13
63
@egosumdns
Daniel Streefkerk
2 months
This (in preview) feature in M365 looks like a great fit for sending emails from MFDs, line of business apps. It only permits sending to internal recipients.
Tweet card summary image
learn.microsoft.com
Learn how to manage high volume emails for Microsoft 365 in Exchange Online.
0
0
1
@egosumdns
Daniel Streefkerk
2 months
This "Always Works" command/hook for Claude Code is mega handy. I've lost count of the number of times it has told me that things are working when it hasn't even checked. https://t.co/U3OL1rGBy8
1
0
0
@rustla
Russ
2 months
A bunch of apps I’ve been poking around with lately interact with Dataverse using $batch queries. Not seen much chatter about it, but really handy to subvert intended logic when the queries and writes are just … there. Any authz issues are super obvious too šŸ‘ļøšŸ‘ļø
0
1
1
@NTFAQGuy
John Savill
2 months
Microsoft have released a great (free) Zero Trust Workshop that helps organizations with an actionable roadmap to achieving zero trust in their organization. https://t.co/dcqjcTcSXA https://t.co/08Gu0UVzjV 00:00 - Introduction 00:07 - Zero Trust 101 00:22 - NIST zero trust
microsoft.github.io
Check your Microsoft tenant configuration for zero trust readiness
8
91
436
@egosumdns
Daniel Streefkerk
2 months
A chat with my teenage son about SIEM detection rules (he saw me working on some) pivoted into MITRE, TTPs, network services/ports, and a trip around Shodan. Ridiculous what's still exposed to the web in this day and age. We just spent 15mins looking at RTSP and VNC screenshots.
0
0
1
@ITguySoCal
Joe Stocker
2 months
Even though Microsoft provided a PowerShell command in April 2025 to disable the SMTP DirectSend feature in Exchange Online, we are still seeing attackers successfully reach the inbox for organizations that do not have their DMARC DNS Record set to Reject or Quarantine. According
14
76
361
@egosumdns
Daniel Streefkerk
2 months
I also have some potential use cases for the hooks feature.
0
0
0