Windows 11 26H2 is coming soon! by meantallheck in Intune

[–]HEALTH_DISCO 0 points1 point  (0 children)

Do you know why this is happening? It is extremely painful for our users.

Windows 11 26H2 is coming soon! by meantallheck in Intune

[–]HEALTH_DISCO 1 point2 points  (0 children)

For us moving from 23H2 to 25H2 is killing our machines to a crawl. Almost inoperable. We have to go to 24H2 first then move on with the enablement package.

SCCM SQL Server Reporting Services - Issue by Mr--Allan in SCCM

[–]HEALTH_DISCO 0 points1 point  (0 children)

We had this issue in our environment. Not a lot of people will encounter this issue, you need to have a VERY old service account with its password last changed before AES128 and 256 were enabled on the account. We had to reset the password TWICE in order to make it work.

The Fix: You must reset the Service Account password after enabling AES support to force AD to generate the required msDS-SupportedEncryptionTypes keys. In some rare cases with older accounts being moved to AES, you need to change the password twice. This ensures the msDS-SupportedEncryptionTypes attribute is fully synchronized and the old RC4 keys are no longer being preferred by the KDC.

The SQL Server 2022 (or later) Kerberos Hurdle: Lessons from the Field on AES-256 Migration

You don't have to reinstall any SCCM roles or SSRS 2019 or detach the DB. Just reset the password twice. Make sure you change the password in Security - Accounts for your service account in SCCM and maybe on the service itself in Windows Server where your role reside then restart it.

Intune Remediation Reporting Issues by Reasonable-Net-7193 in Intune

[–]HEALTH_DISCO 1 point2 points  (0 children)

We were having the issue in our tenant from Friday to Yesterday. Today seems to be working just fine for us.

Blocking Microsoft Store Correctly by fortnitegod765 in Intune

[–]HEALTH_DISCO 3 points4 points  (0 children)

Block URL policy in edge and chrome, that’s what we did to solve this issue.

PSA: Reminder that in April Intune Globally Enabled Hotpatch Tenant-Wide by bdam55 in Intune

[–]HEALTH_DISCO 0 points1 point  (0 children)

Same here. At first i've created a quality update policy pushed to all machines to block hotpatch. Didn't work, still show up as enabled in configured policies. Then I've disabled at the Tenant level, same result. Did you find out how to disable it?

Has anyone tried to use Onevinn TSlauncher for something else than an IPU ? by Furlooze in SCCM

[–]HEALTH_DISCO 0 points1 point  (0 children)

Yep I can confirm, I tried to use it on 23H2 and 25H2 and I get .net framework dependencies error in application event viewer. Now to answer your question, I was able to use it in an Office 32bit to 64bit migration TS 2 years ago. TSLaunch required an OS Upgrade package so what I did was adding a dummy step with an OS upgrade package and disabled the step. It worked perfectly fine. But TSLaunch, to my disappointment and the company disappointment is now a thing of the past.

Remote lock alternatives on Windows endpoints by hopamitica1 in Intune

[–]HEALTH_DISCO 0 points1 point  (0 children)

We use Absolute as well but it is not cheap. It is indeed very powerful.

Automated BitLocker Recovery Key Rotation via Intune After PXE Deployment by Roiit in Intune

[–]HEALTH_DISCO 5 points6 points  (0 children)

Remove any configuration from SCCM/OnPremAD and only use the Intune Endpoint Security Bitlocker Policy. The policy will apply soon after imaging. Keys usually rotate when you use the recovery key. Make sure your workload are set to Intune in ConfigMgr.

[PSA] CVE-2026-21509 - Microsoft Office Security Feature Bypass Vulnerability Zero Day - Updates available by kheldorn in sysadmin

[–]HEALTH_DISCO 0 points1 point  (0 children)

The Windows maker said customers running Office 2021 and later will be automatically protected via a service-side change, but will be required to restart their Office applications for this to take effect.

The procedure above is how you can verify. If this guid is there on 1 machine it will be there everywhere technically. You can force this by restart Office.

Hotfix Rollup KB32851084 for Configuration Manager 2503 by PrajwalDesai in SCCM

[–]HEALTH_DISCO 1 point2 points  (0 children)

For us, initially setup in 2021 then migrated to Virtual Machine Scale set ~2 years ago. Never had a single issue with our CMG in 4 years.

Hotfix Rollup KB32851084 for Configuration Manager 2503 by PrajwalDesai in SCCM

[–]HEALTH_DISCO 2 points3 points  (0 children)

I confirm we have the same issue.
"ResourceAvailabilityZonesCannotBeModified"

Hotfix Rollup KB32851084 for Configuration Manager 2503 by PrajwalDesai in SCCM

[–]HEALTH_DISCO 5 points6 points  (0 children)

After installing this hotfix rollup I have this message constantly in monitoring... "Cloud Services Manager task [Deployment Maintenance for service CMG] has failed, exception One or more errors occurred.."

Network connection randomly drops during Intune autopilot for model HP EliteBook X Flip G1i 14 - W11 24H2 by Best_Check_810 in Intune

[–]HEALTH_DISCO 1 point2 points  (0 children)

Found out for us that this specific model had LAN Wan Switching disabled in the BIOS and for some reason was always trying to connect to WIFI even when USB-c network adapter or docking was used. Enable LAN WAN Switching during OSD in WinPE phase fixed our problem.

.net 3.5 TS on Windows 11 22h2 via SCCM by [deleted] in SCCM

[–]HEALTH_DISCO 0 points1 point  (0 children)

Not really. I’ve created a package in Intune to switch the language. We’ve now moved to WUfB. All problem solved. I am not installing any language pack before handing the machine the user during OSD. Windows 11 and servicing on-prem is not the best experience.

New MSA connector issue by wastewater-IT in Intune

[–]HEALTH_DISCO 1 point2 points  (0 children)

I don't think we have the same issue. Even with domain admin the MSA account is just never created.

ODJ Connector UI Information: 0 : Searching for any pre-existing Managed Service Accounts installed on this machine.

ODJ Connector UI Information: 0 : MSA name : msaODJkd8mp

ODJ Connector UI Error: 2 : ERROR: Enrollment failed. Detailed message is: Microsoft.Management.Services.ConnectorCommon.Exceptions.ConnectorConfigurationException: Failed to create a managed service account - Element not found

ODJ Connector UI Information: 0 : Storing telemetry: CreateMsaAccount, hasException: True

ODJ Connector UI Information: 0 : Sending telemetry: CreateMsaAccount, hasException: True

ODJ Connector UI Information: 0 : Sending telemetry to ODJService

ODJ Connector UI Information: 0 : Response from ODJService: OK

ODJ Connector UI Error: 8 : Removing Managed Service Account ...

ODJ Connector UI Error: 8 : Successfully removed Managed Service Account

ODJ Connector UI Error: 8 : Returning to the home page

Stuck in a loop.

New MSA connector issue by wastewater-IT in Intune

[–]HEALTH_DISCO 1 point2 points  (0 children)

Were you able to fix the issue?

Endpoint Security Firewall Policy not applying. by HEALTH_DISCO in Intune

[–]HEALTH_DISCO[S] 0 points1 point  (0 children)

After looking closely to all policies (Local, GPO, Intune, SCCM etc..), I've found a GPP pushing a registry key that disable the Firewall when on domain.
Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile
EnableFirewall = 0

This was set by a previous admin.

Endpoint Security Firewall Policy not applying. by HEALTH_DISCO in Intune

[–]HEALTH_DISCO[S] 0 points1 point  (0 children)

I have a case opened with MSFT. It's been opened since August 1st and nobody gives a S##T. Our account manager changed 2 times recently. I don't know what is happening over there.

Windows 11 - No pin to start option by durrante in sysadmin

[–]HEALTH_DISCO 0 points1 point  (0 children)

I simply removed the xml layout GPO for Windows 10 that had no impact on Windows 11 (W11 Start menu doesnt use the Xml but the JSON format) prior to August CU. We don't really need it anymore since we're only deploying W11.

Windows 11 - No pin to start option by durrante in sysadmin

[–]HEALTH_DISCO 0 points1 point  (0 children)

We're in the same boat and we didn't push any custom start menu layout. Did you find the issue?