5 ms·
I spent the past year working for a company that relies heavily on Microsoft for email, productivity tools, and identity management. After that experience, I ca
by seanieb 11mo ago
I spent the past year working for a company that relies heavily on Microsoft for email, productivity tools, and identity management. After that experience, I can say with confidence: never again. The support is astonishingly poor, and user experience feels like an afterthought.
More importantly, using Microsoft at scale can leave your organization fundamentally insecure. The obscure, insecure defaults are, at best, dangerous missteps and, at worst, borderline negligent. I’m convinced that only a small fraction of enterprises using Microsoft have the expertise and budget required to secure it properly.
My personal view is that if your organization depends heavily on Microsoft, it’s not serious about security, whether they’re aware of it or not.
- LPisGood 11mo agoWhat kind of obscure insecure defaults are there?
- seanieb 11mo agoDirect Send was my favorite. Direct Send allows devices to send unauthenticated email to internal recipients using your organization’s domain, which can expose you to internal emails for phishing etc. It bypasses user authentication, making sender identity difficult to verify or audit. For all orgs made before mid 2025 it was enabled by default. I saw a great Blackhat talk this year about Entra misconfiguration that got Microsoft's own sensitive internal services owned by a researcher, one of them owned by their security team. After the report they reconfigure their services, didn't pay a bounty and considered the problems solved. What about their customers making the same config errors as the Microsoft team... no changes planned. There's much much more...
- e12e 11mo agoOne not-so-obscure problem is how hard it is to only elevate yourself to admin when you need it (and run as a regular user the other time). Essentially you need to pay double license for admin users so they can have two logins; and it's a pain to quickly elevate privilege to do day to day admin tasks. So if your friendly domain admin clicks the wrong link, your entire network is owned.
- downrightmike 11mo agoEverything on by default in general has plagued them, because they don't want users to complain it doesn't work.
- mr_mitm 11mo agoCheck out the Microsoft baseline security guidelines for Windows 11. It's about 400 entries. 400 settings that Microsoft themselves recommend changing from the defaults to achieve a baseline security. Why does windows 11 show stock values in the task bar by default? Why does it show ads, games and yellow press headlines when you click on it? On the enterprise edition! Xbox services are installed and running by default. Why?
- lokar 11mo agoChanging the default would cost sales and increase support costs.
- machomaster 11mo agoObscure from a typical user's POV: the fact that file extensions are not being shown by default. This makes it possible for the user to click on a file that has the extension and the icon of a picture (imbedded inside), but turns out to be an executable file.
- peebee67 11mo agoThey've apparently had a corporate philosophy of obfuscating the underlying system from the end user and deliberately inhibiting their ability to learn how it fits together since at least the early 2000's. I feel like the current ignorance of the average computer user was a deliberate outcome they've been working towards for more than 20 years. As someone who has been using computers since the late 80's, I find their current offerings harder to use than ever.
- project2501a 11mo agoWhere do I find money to fund my rewrite of Kerberos 5 in Rust, removing the dumb options and Kerberos 4 compatibility and eventually create Kerberos 6 + AD that will solve a metric buttload of issues in Linux and knock a major peg of MS off?
- NuclearPM 11mo agoDid you respond to the wrong comment?
- cyberax 11mo agoAsk IBM/RedHat. They did a lot of foundational work with SSSD (aka "too many 'S' D"). Kerberos is not a great protocol, though.
- kakacik 11mo ago> Kerberos is not a great protocol Understatement of the week
- project2501a 11mo agosssd is a dogpile of dogcrap. I have 15 tickets on github about fixing their manpages. and you really need to read the kerberos book before picking up sssd.
- bodeadly 11mo agoUltimately Kerberos is used to authenticated basically everything in a Windows on-prem environment and in a way that is largely transparent to the user. Silent SSO is a very nice feature. Even if you're doing OIDC or SAML, those protocols do not define what is actually performing authentication at the IdP which, again, ultimately ends up being Kerberos if you're people are on-prem. So whatever your feelings are about Kerberos as a protocol, it doesn't matter if that's what Windows uses. And again, it cannot be obsoleted by other protocols. Even if you're using a newer fido thing like passkeys or client certs or whatever, ultimately the device has to be authenticated to get that passkey or cert or whatever it is installed into the authenticator app of the device. So Kerberos is king on prem. MIT Kerberos on Linux is not really compatible with Windows Kerberos in ways that cause problems that are not solved by re-writing Kerberos in another language. More important issues have to do with sharing credentials and getting trust info and other such things.
- mcv 11mo agoI work for a company that now uses everything from Microsoft. They used to have Jira, AWS and tons of other different products, but now everything is Microsoft, and it's terrible. Azure DevOps is particularly horrific. It's like Jira+Jenkins except you can never find anything. Nothing about it makes sense to me. As far as I can tell, the databases on Azure are all either slow, expensive, or both. And of course it means we hand over all of our highly sensitive data to a company that has said that US law will overrule EU law. How can anyone trust a company that says they will not obey the law?
- another_twist 11mo agoDont know why employers do this. Why pay for shitty tools your employees hate ?
- wiether 11mo agoCorporate people who decide what services to buy don't care about what the employees think about those services. And regarding Microsoft, it's easy: paying for the whole package is much easier in terms of contract overhead and with MS the discounts are quite advantageous as soon as you increase the width of the package. Short term and if you only look at the bill, it makes sense. Long term, forcing your teams to work with shitty services is a terrible idea.
- toast0 11mo agoThe top of the stack loves Outlook/Exchange. They want that calendar experience and that's what they're going to get.
- mcv 10mo agoThat's the thing. The decision makers are not programmers who care about good dev tooling, but executives who care about good agenda management. So Microsoft's agenda management is great, and their dev tooling sucks. It really feels like ADO was just quickly patched together to they can offer it as part of a complete package.
- 11mo ago
- BenFranklin100 11mo agoThis is blatant nonsense. The best security choice for any small business that doesn’t have a dedicated full time security staff is Microsoft 365.
- seanieb 11mo agoHave you admined a Google Apps account and an MS365 account? I'm curious why you think Microsoft is more secure? For me they are completely different, Google is secure by default, Microsoft is not. Do you have "Direct Send" enabled on your account for example?
- BenFranklin100 11mo agoBecause outside of a handful of nerdy tech companies, all small businesses need to use Microsoft Office. From there, it’s a no brainer to stay in the MS ecosystem and use Sharepoint etc… For a small business without a dedicated IT team, simply hire a IT contractor to harden the tenant (MFA etc…), have them review every six months and be done with it and focus your resources on running your business.
- tfourb 11mo agoMy father’s decidedly non-nerdy logistics consulting business with roughly 20 employees ran (and runs) on Mac OS since the founding of the company in the mid 1990s with my mom being the „IT team“. There are some situations where companies rely on certain compatibilities requiring windows. But most could do completely fine without, especially nowadays.
- Closi 11mo agoYou can run a logistics consulting business without windows, but you will struggle without Excel and PowerPoint, and 365 with SharePoint is basically needed for collaboration in any consulting business. Im also a logistics consultant… try to parse a multi-million line orderlines extract in Google Sheets compared to excel. I’m also on Mac but to be honest it’s a challenge - there are still enough industry specific tools that are windows only so I have to run a parallels VM to get by.
- isk517 11mo agoI'm always amazed at how needlessly complicated and useless administration of Microsoft products and services are. So much of 365 feels like it is 75-90% completed then abandoned. Every time I find something that sounds like it should be really useful, it turns out to lack at least one function or feature needed to do what I would need it to.
- Spooky23 11mo agoEven if you do, you’re still going to get breached. They drop features all of the time that open potential vulnerabilities. I used to run a Microsoft productivity ops team. Email/SharePoint/etc. Our headcount was about 20-24. O365 dropped that to ~8. Now? I’m told it’s about 60, much of it relating to security.