7 ms·
And God help them if they somehow have a work/school and personal Microsoft account and don't remember which one they used.
by discreditable 7y ago
And God help them if they somehow have a work/school and personal Microsoft account and don't remember which one they used.
- chris_wot 7y agoThe company I now work for has decided to separate out admin accounts in Windows. Fair enough, except it's not like a Unix system where you can quickly context switch. Trying to administer Office 365 with two separate Office 365 accounts is an absolutely nightmare!
- wickedwiesel 7y agoSorry, maybe I am missing something here. For local admin, I agree re context switching etc. But for O365 admin, we have a similar setup and I admin O365 through a separate container tab or Powershell where you need to connect to Azure separately anyways. Seems straightforward to me.
- goatinaboat 7y agoThe company I now work for has decided to separate out admin accounts in Windows Do they know that doesn’t work? If you do a run-as then you are as vulnerable to PTH as you would be if you just logged in with the admin account anyway... you need to go full PAW these days.
- vxNsr 7y agoCould you expand on this? we have a similar set up for our domain admin accounts and I heard it was the safest way to do things. What do you mean by PAW?
- wickedwiesel 7y agoA PAW is a "privilged access workstation", i.E. a dedicated, hardened machine just for the purpose of admin tasks. Due to the specialized tasks it needs to run, the workstation can be - cut off from general purpose Internet etc., - a non-mobile device, - etc.... See for instance Microsoft's documentation: https://docs.microsoft.com/en-us/windows-server/identity/securing-privileged-access/privileged-access-workstations https://docs.microsoft.com/en-us/windows-server/identity/sec...
- goatinaboat 7y agoPass-the-hash is a common attack on Kerberos - it doesn’t care if you are logged in as an admin or have merely done run-as an admin. See https://microsoft.com/pth https://microsoft.com/pth for more. For PAW see https://docs.microsoft.com/en-us/windows-server/identity/securing-privileged-access/privileged-access-workstations https://docs.microsoft.com/en-us/windows-server/identity/sec... conceptually I like to explain it as a client-side bastion host
- Marsymars 7y agoIs this somehow worse with MS accounts than with Google or Apple accounts?
- snazz 7y agoPeople use them less frequently, so they don’t type the credentials as often?
- iamnotacrook 7y agoYeah, I can't even log into my MS account to do MSDN stuff. Microsoft support: "Use any non-microsoft browser". I ended up creating a "personal" and "work/school" account as part of the process, and I think I have to pretend it's the personal account when I log in. I get the feeling I was creating two accounts - a live account and one related to the MSDN side of things, and they are linked in some way. Why...just why? Why can't I just create one account, and don't come up with this specious personal/private distinction. I wonder if they're making decisions on products etc based on what sort of users they think they're dealing with. Personal MSDN customers?
- aquark 7y agoMicrosoft accounts are definitely a mess. I had a Microsoft account from a long time back: me@company.com Years later the company decides to adopt the whole office365 thing and so company.com is now 'managed' by MSFT for email, etc .... so I have a me@company.com 'company' account as well as the 'personal' one. I'm sure there are a lot of complicated edge cases around all of this which make moving forward really tough for MSFT without breaking things, but the current status quo is confusing and very user hostile.
- vxNsr 7y agoIts compounded by the fact that we all had Lumias (I still like the UX over anything out today) and some used existing hotmail/live accounts while others created new ones, even though they had existing ones. At this point they have no idea what they used any more for what and it's often a hassle when they switch phones or get logged out.
- 7y ago