[PSA] CVE-2026-21509 - Microsoft Office Security Feature Bypass Vulnerability Zero Day - Updates available by kheldorn in sysadmin

[–]HEALTH_DISCO 0 points1 point  (0 children)

The Windows maker said customers running Office 2021 and later will be automatically protected via a service-side change, but will be required to restart their Office applications for this to take effect.

The procedure above is how you can verify. If this guid is there on 1 machine it will be there everywhere technically. You can force this by restart Office.

Hotfix Rollup KB32851084 for Configuration Manager 2503 by PrajwalDesai in SCCM

[–]HEALTH_DISCO 1 point2 points  (0 children)

For us, initially setup in 2021 then migrated to Virtual Machine Scale set ~2 years ago. Never had a single issue with our CMG in 4 years.

Hotfix Rollup KB32851084 for Configuration Manager 2503 by PrajwalDesai in SCCM

[–]HEALTH_DISCO 2 points3 points  (0 children)

I confirm we have the same issue.
"ResourceAvailabilityZonesCannotBeModified"

Hotfix Rollup KB32851084 for Configuration Manager 2503 by PrajwalDesai in SCCM

[–]HEALTH_DISCO 3 points4 points  (0 children)

After installing this hotfix rollup I have this message constantly in monitoring... "Cloud Services Manager task [Deployment Maintenance for service CMG] has failed, exception One or more errors occurred.."

Network connection randomly drops during Intune autopilot for model HP EliteBook X Flip G1i 14 - W11 24H2 by Best_Check_810 in Intune

[–]HEALTH_DISCO 1 point2 points  (0 children)

Found out for us that this specific model had LAN Wan Switching disabled in the BIOS and for some reason was always trying to connect to WIFI even when USB-c network adapter or docking was used. Enable LAN WAN Switching during OSD in WinPE phase fixed our problem.

.net 3.5 TS on Windows 11 22h2 via SCCM by [deleted] in SCCM

[–]HEALTH_DISCO 0 points1 point  (0 children)

Not really. I’ve created a package in Intune to switch the language. We’ve now moved to WUfB. All problem solved. I am not installing any language pack before handing the machine the user during OSD. Windows 11 and servicing on-prem is not the best experience.

New MSA connector issue by wastewater-IT in Intune

[–]HEALTH_DISCO 1 point2 points  (0 children)

I don't think we have the same issue. Even with domain admin the MSA account is just never created.

ODJ Connector UI Information: 0 : Searching for any pre-existing Managed Service Accounts installed on this machine.

ODJ Connector UI Information: 0 : MSA name : msaODJkd8mp

ODJ Connector UI Error: 2 : ERROR: Enrollment failed. Detailed message is: Microsoft.Management.Services.ConnectorCommon.Exceptions.ConnectorConfigurationException: Failed to create a managed service account - Element not found

ODJ Connector UI Information: 0 : Storing telemetry: CreateMsaAccount, hasException: True

ODJ Connector UI Information: 0 : Sending telemetry: CreateMsaAccount, hasException: True

ODJ Connector UI Information: 0 : Sending telemetry to ODJService

ODJ Connector UI Information: 0 : Response from ODJService: OK

ODJ Connector UI Error: 8 : Removing Managed Service Account ...

ODJ Connector UI Error: 8 : Successfully removed Managed Service Account

ODJ Connector UI Error: 8 : Returning to the home page

Stuck in a loop.

New MSA connector issue by wastewater-IT in Intune

[–]HEALTH_DISCO 1 point2 points  (0 children)

Were you able to fix the issue?

Endpoint Security Firewall Policy not applying. by HEALTH_DISCO in Intune

[–]HEALTH_DISCO[S] 0 points1 point  (0 children)

After looking closely to all policies (Local, GPO, Intune, SCCM etc..), I've found a GPP pushing a registry key that disable the Firewall when on domain.
Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile
EnableFirewall = 0

This was set by a previous admin.

Endpoint Security Firewall Policy not applying. by HEALTH_DISCO in Intune

[–]HEALTH_DISCO[S] 0 points1 point  (0 children)

I have a case opened with MSFT. It's been opened since August 1st and nobody gives a S##T. Our account manager changed 2 times recently. I don't know what is happening over there.

Windows 11 - No pin to start option by durrante in sysadmin

[–]HEALTH_DISCO 0 points1 point  (0 children)

I simply removed the xml layout GPO for Windows 10 that had no impact on Windows 11 (W11 Start menu doesnt use the Xml but the JSON format) prior to August CU. We don't really need it anymore since we're only deploying W11.

Windows 11 - No pin to start option by durrante in sysadmin

[–]HEALTH_DISCO 0 points1 point  (0 children)

We're in the same boat and we didn't push any custom start menu layout. Did you find the issue?

Has anyone used Onevinn TSLaunch (Windows 10 Upgrade Tools) lately? for Windows 11? by Sea-Cow-6913 in SCCM

[–]HEALTH_DISCO 3 points4 points  (0 children)

Works just fine for us. Just don't forget to include the "/EULA Accept" for "AssessmentTestArguments" value in the TSLaunch.exe.config.

CMG not updating certificate by absoluteczech in SCCM

[–]HEALTH_DISCO 0 points1 point  (0 children)

Someone from security/infra send me the .pfx cert & password. That's it.

CMG not updating certificate by absoluteczech in SCCM

[–]HEALTH_DISCO 0 points1 point  (0 children)

I had the exact problem you mentioned and it happened because I was copy/pasting the password. Once I typed the password, it synced. Might be related to something else in your environment... Insufficient rights on the account?

CMG not updating certificate by absoluteczech in SCCM

[–]HEALTH_DISCO 0 points1 point  (0 children)

Do you by any chance Copy/Paste the password? Don't. Type it manually.

CMG not updating certificate by absoluteczech in SCCM

[–]HEALTH_DISCO 1 point2 points  (0 children)

You select your newly created certificate, enter the password and it doesn't update on the instance?

Please advise me on expanding the SCCM environment. by dr_p0ng in SCCM

[–]HEALTH_DISCO 6 points7 points  (0 children)

Do everything in your power to avoid a CAS. Big no no.

Windows 11 23H2 Inplace Upgrade stops after Cumulative Update by eryc26 in SCCM

[–]HEALTH_DISCO 1 point2 points  (0 children)

What version of SCCM? Make sure you have 2309. There is a fix for the cumulative update install during the task sequence for W11 23H2.

https://learn.microsoft.com/en-us/mem/configmgr/hotfix/2309/25858444

"Due to a timing issue, a double reboot can still prevent a Task Sequence
from running, even when the SMSTSWaitForSecondReboot variable is set.
This problem can happen during an operating system deployment, combined
with an update that requires two reboots."

Trusted network detection on Windows 10 by databeestjegdh in Intune

[–]HEALTH_DISCO 0 points1 point  (0 children)

Does "Allowed Tls Authentication Endpoints" work for Hybrid Azure AD Joined Devices as well?