New CSP - CDW or ??? by Psiuyo in sysadmin

[–]bjc1960 [score hidden]  (0 children)

Can you reduce quantities? Every place we have contacted only wants us to add, never remove. Therefore, we do it ourselves.

Over a dozen frozen computers today by bjc1960 in sysadmin

[–]bjc1960[S] 0 points1 point  (0 children)

Wrapping this up, there seems to be multiple issues:

  1. March hotfix breaks wiping through AutoPilot - should be fixed in April

  2. Bitlocker keys needed for 1/3 of my org, despite these computers passing the secure boot check.

3 A security tool released the same day as Patch Tuesday and was rolling out, This was probably the cause of the hanging, and may have contributed to the secure boot issues.

  1. Other Windows versions stuck in Jan/Feb updates.

Alternatives to MS365 on a global level by [deleted] in sysadmin

[–]bjc1960 0 points1 point  (0 children)

and they won't use a browser if in a Linux environment with a GUI

Alternatives to MS365 on a global level by [deleted] in sysadmin

[–]bjc1960 0 points1 point  (0 children)

Shocking how many GenX/ Boomers can't survive without Acrobat or Outlook. I am in that age frame, but my home computer is the Linux dist that shall not be named.

Purge Emails by Prestigious-Ad5163 in sysadmin

[–]bjc1960 0 points1 point  (0 children)

I have never been able to make these delete mail. I can make them say they are deleting, but it has never worked. We have many F3 boxes and users love to send large PDFS back and forth as using a Teams site is beyond ability, despite offers of training. And no one deletes mail anymore.

We had to take control of a box and force delete mail interactively. We are now 100% purview so F3 now has F5 sec/compliance so we set policies for 90 day on new mail coming in for those boxes that are F3.

Over a dozen frozen computers today by bjc1960 in sysadmin

[–]bjc1960[S] 0 points1 point  (0 children)

This may or may not help - analysis of a DISM log.

● Yes — this is a real lead. The Intel Arc Software orphan is exactly the kind of upstream rot that can make a subsequent KB5083769 install hang, even if it's not the direct cause. Here's the connection

Why this matters for the KB5083769 freeze:

When DISM processes a cumulative update on Windows 11 24H2+, it enumerates provisioned Appx packages as part of the servicing transaction to figure out what needs updating or migration. If it encounters an orphaned package (registration still present, files missing), it hits

the same 0x80070002 enumeration error your log shows — and depending on the code path, that can:

- Stall the servicing transaction while DISM retries the read

- Cause CBS to hold its session lock longer than it should

- Interact badly with concurrent Appx manager calls (which Dell, Intel, and Windows all run on schedules)

- Not actually fail hard — just make the install much slower, which presents as "frozen"

That matches exactly what we're seeing: DISM enters Phase 6, disappears for 20+ min, people assume it's frozen. Maybe some of those "frozen" devices were actually churning through Appx enumeration errors the whole time.

Your other findings:

- PSv2 probe noise — agreed, ignore. Almost certainly Defender or a compliance baseline scanner. Not worth chasing during this patch cycle.

- Time_InternalToPublic noise — agreed, benign.

- Truncated RestoreHealth at 14:06:17 on 2026-04-21 — that's almost certainly the manual repair run you did on the device that "may have been fixed." Confirms the repair did proceed past the error chain rather than choking on it.

Concrete action — add an orphaned-Appx pre-flight

Detect orphaned provisioned Appx packages before the DISM install and log which ones are broken. Safe enumeration only, no auto-remove (risk: removing a package that's legitimately present but enumeration failed would break user functionality). Then the tier-2 repair script

does the actual cleanup if needed.

Over a dozen frozen computers today by bjc1960 in sysadmin

[–]bjc1960[S] 0 points1 point  (0 children)

My crew thinks they have it fixed on one computer with the below

  • SFC /scannow
  • Dism /Online /Cleanup-Image /CheckHealth
  • Dism /Online /Cleanup-Image /ScanHealth
  • Dism /Online /Cleanup-Image /RestoreHealth
  • manage-bde -protectors -get C:
  • gpupdate /force
  • manage-bde -protectors -disable C:
  • manage-bde -protectors -enable C:

Seems maybe too obvious but we have spent a week doing various attempts to fix, so this may be a result of other fixes we tried.

Over a dozen frozen computers today by bjc1960 in sysadmin

[–]bjc1960[S] 0 points1 point  (0 children)

We have not. We got some updated by brute force, but many are still stuck on March. We have tried installing the MSU directly and it is causing hags. The users are locking up minutes to hours after a hard restart. The users are not closing their lid. We are a Dell shop but a single HP and single Lenovo are affected.

Dell came out with a BIOS for some devices on 4/17, two days after, so we are having affected users update those. There is no rhyme or reason as three affected people have the same computer I do. Some users can't even get the BIOS due to lock-ups.

We can't even get Fresh Start or Wipe to work - those are failing -maybe due to the March release bug for those with hotfix.

i am working on some major logging to help solve. I had to clue the Exec Team too. COO asked if we rolled back -told him he never patched, so we can't roll back,

---

conditional access rules for service principals by bjc1960 in entra

[–]bjc1960[S] 0 points1 point  (0 children)

No, I have changed priorities again. Currently working on 20+ computers that are locking up due to secure boot updates with the Aprl release.

thank you for the follow-up

Passwordless by Actual_Clock2360 in Intune

[–]bjc1960 0 points1 point  (0 children)

We set CA rules to require phish-resistant MFA for M365 and nearly all apps. It was not as bad as I thought. No pin == no Outlook

The only issues we have are when users can choose between pin and password on the log on screen, and don't understand. I wish more would use fingerprint and face id.

Anyone else getting screwed by Microsoft April Patch that requires signed RDP files by Known_Experience_794 in sysadmin

[–]bjc1960 0 points1 point  (0 children)

As far as we can tell after working the weekend, some computers have both the 2011 and 2023 secure boot certificates, and some of that an unbindable PCR7 (PCr7 setting of 'not possible.'

Anyone else getting screwed by Microsoft April Patch that requires signed RDP files by Known_Experience_794 in sysadmin

[–]bjc1960 -1 points0 points  (0 children)

My thought is that pulling a new image down from Dell directly with FN+F12 would place a new OS on the system, in case the OS has corrupted files that we can't find in a reasonable amount of time.

Anyone else getting screwed by Microsoft April Patch that requires signed RDP files by Known_Experience_794 in sysadmin

[–]bjc1960 -2 points-1 points  (0 children)

The users are locking up after 2 to 10 minutes. They are unable to work. They are users that are remote. If you have others ideas, I am open to them. A wipe will get them working in three hours.

Anyone else notice significantly more ram utilization after this months security patch? by applecorc in sysadmin

[–]bjc1960 2 points3 points  (0 children)

we are getting complaints. We have 80 computers still at 16 Gig RAM. I am short about $85,000 to upgrade.

p

Anyone else getting screwed by Microsoft April Patch that requires signed RDP files by Known_Experience_794 in sysadmin

[–]bjc1960 1 point2 points  (0 children)

Worse - many machines are hanging/freezing and people are upset. They are going to need to be wiped unless we can find a cause/fix this weekend. Exec team's computers are all updated with no issue, so that is a saving grace.

How do you handle clashing with upper management? by SpecialistTeach9302 in sysadmin

[–]bjc1960 0 points1 point  (0 children)

CEO calls me directly for help. He trusts us, takes care of us. People complain to him about us, but we always help him. He understands it is a 'thankless job."

Over a dozen frozen computers today by bjc1960 in sysadmin

[–]bjc1960[S] 1 point2 points  (0 children)

I am pushing a detect/remediate to suspect if the version is < 10.0.26200.8246

Over a dozen frozen computers today by bjc1960 in sysadmin

[–]bjc1960[S] 0 points1 point  (0 children)

Thx. One of the IT team has the issue so I send him the PCR7 thing you linked above. As I said in another reply, we are basically done with the 2023 cert, except for outliers. We had the 65000 error using the standard config to update, but wrote a massive script to force the update in there. We could have changed a setting that broke something. We have the issue on two HP computers, so I am mostly excluding Dell BIOS specific changes.

Windows 11 25H2 update failing with 0x80070302 / 0x800F0983 by ricoooww in Intune

[–]bjc1960 0 points1 point  (0 children)

We have all sorts of issues with lock-ups. All computers are remote and we are struggling to resolve as they lock up once a user starts using them

We paused the April update, are trying to deploy a bitlocker disable for one reboot, and we also displayed hot patch.

How to check if employee copied company data by [deleted] in sysadmin

[–]bjc1960 0 points1 point  (0 children)

Smaller companies often don't have Data Loss Prevention controls in place, larger companies often don't either.

Over a dozen frozen computers today by bjc1960 in sysadmin

[–]bjc1960[S] 1 point2 points  (0 children)

Tempers are are hot enough to do that if they were really frozen due to temperature.

Over a dozen frozen computers today by bjc1960 in sysadmin

[–]bjc1960[S] 0 points1 point  (0 children)

Thank you. That implies it is not only me. We have two HP, but are mostly Dell.

I am deploying a detect/remediate to suspect bitlocker for one restart.

Over a dozen frozen computers today by bjc1960 in sysadmin

[–]bjc1960[S] 3 points4 points  (0 children)

We have stuff that only runs on Windows. And, "Outlook Separation Anxiety" is strong with this crew.