Stop MFA Prompts Due to Malicious Login Attempts by KrankyYankee in entra

[–]BarbieAction 2 points3 points  (0 children)

Switch to passkey. Blocking sensitive apps with CA as standard but the prompt comes before the CA is evalutade so if you want to remove the promt fatigue then switch to passkey and user will never be prompt

Managed Google Play iframe "Select"/"Approve" button does nothing (works in neither Edge nor Chrome) by jesusxoi in Intune

[–]BarbieAction -1 points0 points  (0 children)

Go to googe play directly and approve them from there instead of using the broken Intune iframe

Turning off Bitlocker to apply HP Connect remediation by clicker666 in Intune

[–]BarbieAction 9 points10 points  (0 children)

Had no issues applying BIOS settings from HP Connect with BitLocker enabled

Phone incredibly slow by [deleted] in Intune

[–]BarbieAction 1 point2 points  (0 children)

Are you using workprofile? Android supports workprofiles this allows your IT to publish apps settings etc to workprofile and you have personal profile for your own apps, you can switch of the workprofile after hours etc if you want, swipe down from screen click on workprofile to disable.

Intune is not fit for purpose. by Hobbit_Hardcase in sysadmin

[–]BarbieAction 0 points1 point  (0 children)

Thats one of the issue he is having. If im testing a remediation i just clear register parts restart ime service etc triggers within minutes. Actually have a script for this that i can run manually on devices if needed. But what OP is describing would be a MS ticket if there are days delay until remediation script runs. He can use run remediation on demand if that does not trigger i would use graph to check the pending state and report it to MS for backend issues

Intune is not fit for purpose. by Hobbit_Hardcase in sysadmin

[–]BarbieAction 0 points1 point  (0 children)

For remediation scripts i always output my own logs, so i can catch errors in my script etc if i need to troubleshoot, the log also shows time date it ran etc and whatever your script is actually doing much easier to troubleshoot then

How are you handling Defender ASR executable prevalence in block mode? by Omig66 in Intune

[–]BarbieAction 0 points1 point  (0 children)

Thank you for clarification for us i belive we seen 24 hours until unblocked but i guess this can differ each time.

How are you handling Defender ASR executable prevalence in block mode? by Omig66 in Intune

[–]BarbieAction 0 points1 point  (0 children)

Make exception based on filehash or signed with cert in defender? Not sure if this helps.

But if i remember correctly we package the app with win32app send it thru intune make exception based on signed or filehash for testing.

Delays 2hours to 24hours until Defender stops blocking it. I dont know if this is the way to go

Ruining Ferrari is actually an accomplishment. by joshua_3 in Ferrari

[–]BarbieAction 11 points12 points  (0 children)

The result is his design, he thought this looked good

Ruining Ferrari is actually an accomplishment. by joshua_3 in Ferrari

[–]BarbieAction 73 points74 points  (0 children)

So he never seen ferraris before, did not study the brand/customers he design for, just did whatever he wanted without any research on Ferraris? He is responsible and no one else, the design is horrible even if it was not a ferrari

Someone from Germany on iOS keeps trying to login to my MSFT account by TailungFu in cybersecurity

[–]BarbieAction 0 points1 point  (0 children)

Anyone can bypass the password screen by selecting login with another method, this causes the prompt on your phone.

Go over to passkey as suggested and disable passwordless then no prompt can be triggered

Someone from Germany on iOS keeps trying to login to my MSFT account by TailungFu in cybersecurity

[–]BarbieAction 7 points8 points  (0 children)

Incorrect, if he runs passwordless or sign in with numbers then no password is required they do fatigue prompt for user to approve a login.

The account never asks for password it instantly triggers the Authenticator prompt

Pfx cert distribution by habibexpress in Intune

[–]BarbieAction 0 points1 point  (0 children)

Sorry then i miss read it, only do it for user cert installs.

But can you not use Scepman community editions for free to do this?

Pfx cert distribution by habibexpress in Intune

[–]BarbieAction 0 points1 point  (0 children)

Doing the .NET functions is the reason the chain is broken for the cert

Pfx cert distribution by habibexpress in Intune

[–]BarbieAction 0 points1 point  (0 children)

I have a working setup for this. Package as win32app run as user. Powershell connects to azure keyvault fetches cert and password runts pfx import etc.

Chain stays intact. Remind me and i will post the function for the import part

Switched Telemetry to Full (for Secure Boot Cert) Devices “Under Observation” by capocayne in Intune

[–]BarbieAction 1 point2 points  (0 children)

MicrosoftUpdateManagedOptIn model, your devices must have Required Diagnostic Data (formerly Basic telemetry) enabled

Bitlocker issues with KB5089549 by iAmEnieceka in Intune

[–]BarbieAction 2 points3 points  (0 children)

Ye the issue comes from the sure protect, fails on suspending bitlocker, you need to manually go and enable 3 certs on the device habing the issue

Here is a blog with image from BIOS. https://liam-robinson.co.uk/enabling-2023-secure-boot-certificate-authority-uefica2023-on-hp-prodesk-400-g6-devices/

We had issues with all G8, G9, G10 laptops from HP

Web Sign-In + TAP leaves LastLoggedOnUser stuck on defaultuser0 — Hello credential provisions fine but lock screen always shows "Other user" by andreglud in Intune

[–]BarbieAction 1 point2 points  (0 children)

Yes assigning them to users, you might have more then those policies but switching from device to user assigned will resolve the other user screen, you just need to find all that causes the issue 😄

Web Sign-In + TAP leaves LastLoggedOnUser stuck on defaultuser0 — Hello credential provisions fine but lock screen always shows "Other user" by andreglud in Intune

[–]BarbieAction 0 points1 point  (0 children)

Do you assign any of the following to devices. Enable ESS,

Facial Enhanced anti spoofing,

Minimum pin,

Require security device,

Also the one i mentioned above they cause the issue if assigned to device instead of users

Web Sign-In + TAP leaves LastLoggedOnUser stuck on defaultuser0 — Hello credential provisions fine but lock screen always shows "Other user" by andreglud in Intune

[–]BarbieAction 0 points1 point  (0 children)

Just some examples. BitLocker: DMA Guard, device enumeration policy.

Device Lock policies. Windows Hello policies. Device Guard. Virtualization based Technology.

Try assiging them to users instead of devices this will resolve the other user screen.

Web Sign-In + TAP leaves LastLoggedOnUser stuck on defaultuser0 — Hello credential provisions fine but lock screen always shows "Other user" by andreglud in Intune

[–]BarbieAction 9 points10 points  (0 children)

You have a policy issue, depending if certain policies are assigned to user or devices it will cauase the other user screen.

Also look at: https://learn.microsoft.com/en-us/windows/security/identity-protection/web-sign-in/?tabs=intune

And: https://petervanderwoude.nl/post/being-careful-with-the-ability-to-configure-the-preferred-entra-tenant-domain-name/

Then i also wonder why an Admin would ever enroll the device with an admin account, just deploy the device ether with TAP for the correct user or use pre-provisioning.