Sophos antivirus always updating
This issue yesterday was affecting about 30 of our 300 machines but would have affected more if not for the policy we pushed out early.The actual issue seems to be Sophos blocking all internet connections rather than simply stopping login due to the user profile service not running correctly for domain users.If NIST downgrading the importance of password expiration was a big marker, Microsoft doing the same signals that change is coming in the real world.sensible because, as numerous security compromises demonstrate, passwords today are often stolen and abused long before their owners realise.
Traditionally, for businesses it’s been things like complexity, minimum length, avoiding known bad passwords, and how often passwords are changed to counter the possibility of undetected compromise.It could be that Microsoft’s angst over its baseline is really asking a deeper question – should baselines and the endless compliance that follows in their wake be that important anyway?Margosis again: Removing a low-value setting from our baseline and not compensating with something else in the baseline does not mean we are lowering security standards.It constantly blocks legit apps and programs, which can be quite frustrating for many users.
The addition of full Android support is excellent news.
It simply reinforces that security cannot be achieved entirely with baselines.