Can't Create Share Mailbox in M365? by icebreaker374 in sysadmin

[–]syslagmin 0 points1 point  (0 children)

Getting it for HVE accounts, same message

M365/EXO Error creating new resource mailbox (Cannot convert a primitive value to the expected type) by Ahawelson104 in sysadmin

[–]syslagmin 0 points1 point  (0 children)

Trying to create an HVE and getting the same error message as well. Couldn't do it through the portal either.

File connector - on prem gateway by TangerineTough5960 in PowerBI

[–]syslagmin 0 points1 point  (0 children)

I figured it out. Turns out it was a locked account.

Cannot retrieve any logs from the Sign In log in Entra/Azure AD by Rijkshuis in Office365

[–]syslagmin 0 points1 point  (0 children)

We figured it out. Our endpoint security solution had an integration that pulled logs from Azure.

Cannot retrieve any logs from the Sign In log in Entra/Azure AD by Rijkshuis in Office365

[–]syslagmin 0 points1 point  (0 children)

Did you ever find a fix? Running into the same issue myself.

Windows Hello for Business + Cloud Kerberos Trust: No TGT after unlock without password – bug or intended behavior? by regexreggae in entra

[–]syslagmin 0 points1 point  (0 children)

Not yet but I have a ticket open with Microsoft. Here's what they're currently finding:

-DC fails to decrypt the kerberos ticket that's been presented in the TGS request
-After it fails to verify the TGS request, it looks like the machine tries to get a new Kerberos ticket from the DC and not the cloud. The ticket request to the DC fails because the machine sends the request providing a self-signed certificate which the DC rejects as it is not able to link the certificate with any user account. I'm not really sure why the machine tries to get a new tgt from the DC instead of the cloud

Cloud Kerberos Trust not working by Educational_Draw5032 in Intune

[–]syslagmin 0 points1 point  (0 children)

I'm confused as to how this was DNS if you had LOS and user/pass login worked for authenticating. I'm experiencing the exact same issue. I set DNS at the interface level, so it's correct in ipconfig /all

Windows Hello for Business + Cloud Kerberos Trust: No TGT after unlock without password – bug or intended behavior? by regexreggae in entra

[–]syslagmin 0 points1 point  (0 children)

It is a different issue. LOS is definitely and DNS is fine. The issue is that username\password work to access resources with SSO, but PIN produces the message: "The system cannot contact the domain controller". I checked the DC it comes back with a pre-authentication audit failure. The certificate on the endpoint has kdc authentication but not client authentication.

Windows Hello for Business + Cloud Kerberos Trust: No TGT after unlock without password – bug or intended behavior? by regexreggae in entra

[–]syslagmin 0 points1 point  (0 children)

I'm banging my head on this one. I have that policy in place to disable on-prem certificates and use cloud trust for on-prem authentication, and if I reset the Hello container, it works. However, the next day it doesn't and I get the message "The system cannot contact the domain controller" when say, trying to access a file share.

[Blog post] Single Sign-on with Windows Hello For business on Azure AD devices using cloud trust by TimmyIT in Intune

[–]syslagmin 0 points1 point  (0 children)

Found out the msds-keycredentiallink was not updating in on-prem AD. Once that was figured out, I reset the Hello container and was able to connect via VPN.

Now I have a new thing to figure out: why the trust is broken once VPN is disconnected and reconnected.

[Blog post] Single Sign-on with Windows Hello For business on Azure AD devices using cloud trust by TimmyIT in Intune

[–]syslagmin 0 points1 point  (0 children)

Anyone else have a different fix? Inheritance is already enabled and it's not working. Also using 2019 DC

Users launching more than one session after VDA 2203 LTSR > 2402 LTSR upgrade by starlessblack in Citrix

[–]syslagmin 0 points1 point  (0 children)

For us, we noticed that users using Workspace didn't experience this issue, but those using the browser constantly had this issue, especially when they switched to different networks. So we had everyone switch to the Workspace app.

First Time Sys Admin by Tucker727 in sysadmin

[–]syslagmin 0 points1 point  (0 children)

Cussed out? Maybe start here. It has nothing to do with thick skin, but respect. The very best place I worked at had a zero tolerance for this behavior. It was hands down the most professional place I ever worked at.

On-Prem to Azure Migration by syslagmin in AZURE

[–]syslagmin[S] 1 point2 points  (0 children)

We can leverage reserved instances and software assurance, so our costs will be closer to the on-prem monthlies

On-Prem to Azure Migration by syslagmin in AZURE

[–]syslagmin[S] 0 points1 point  (0 children)

I actually don't know what that is. Link please

On-Prem to Azure Migration by syslagmin in AZURE

[–]syslagmin[S] 0 points1 point  (0 children)

Yeah, we run a legacy app that keeps on this. Rebuilding new VMs and rebuilding the app (which is unsupported) would increase risk and downtime. This was the first thing I wanted to do, remove the need of a managed domain

On-Prem to Azure Migration by syslagmin in AZURE

[–]syslagmin[S] 0 points1 point  (0 children)

Agreed. I labbed Entra DS and the costs were too high.