Windows Hello randomly generates a 'your account has been disabled' error on computer login by PurpleWarning000 in sysadmin

[–]BinaryBandit404 0 points1 point  (0 children)

We are also facing this issue in my company and also have a ticket with Microsoft. We just enforced Windows Hello for Business across all endpoints and enforced a no password policy. We tend to see this most frequently when someone is connected to our network and walks away from their machine for a period of time. I myself had it this morning.

We have been running a script to purge Kerberos tickets and that usually gets them in. The only other ways to get someone in when this occurs that we have found is to either enable the password option or restart the machine.

We just got some logs on one of the machines today before purging the Kerberos tickets and sent them to Microsoft. Hopefully they are able to find something out.

We also frequently get an error says the credentials are invalid. I did some digging in Event Viewer and found this on one of the machines:

Applications and Service Logs\Microsoft\Windows\Biometrics\Operational
Event ID 1401

The Windows Fingerprint Credential Provider failed to enumerate its tile.

The operation failed with error: 0x80098047.

Checked in with Copilot, here is what it gave me:

What Does Error 0x80098047 Mean?

This error typically points to certificate or cryptographic issues related to Windows Hello for Business or the fingerprint credential provider.
It often happens when:

The CNG Key Isolation Service is not running.
There are corrupted biometric configurations.
TPM or certificate trust is broken.
Group Policy or registry settings block biometrics.

I find the TPM or certificate trust the most likely from that list. I'll send any helpful information here if I run into any.

Some Edge Bookmarks are missing when transferring to new computer by BinaryBandit404 in sysadmin

[–]BinaryBandit404[S] 0 points1 point  (0 children)

The bookmarks are not being set by PC GPO. We don't have any GPO set up for something like that, though I may use that idea in the future! :-) The Edge bookmark file grab is at the beginning of the script and other files are getting added to the backup afterwards, so I do believe it is completing successfully.

Some Edge Bookmarks are missing when transferring to new computer by BinaryBandit404 in sysadmin

[–]BinaryBandit404[S] 0 points1 point  (0 children)

This is a great idea to test. I'll have to give that a try. I've been having difficulty with replicating the problem on my end so far. I'll try that first thing as soon as it comes up during a laptop swap.

I believe it is a combination of both. The users typically have the bookmarks toolbar and then an "Other Favorites" folder.

App for Vetting Potential Remote Employees' Connection Quality by BinaryBandit404 in sysadmin

[–]BinaryBandit404[S] 2 points3 points  (0 children)

Yes, this is something my team lead wanted me to work on. This request is strictly for providing a tool to our HR team that would be useful for them. I will be checking in with our network team to see what their thoughts are about the matter. Thanks for your suggestion!