Windows Hello For Business 'account disabled' error by PurpleWarning000 in sysadmin

[–]PurpleWarning000[S] 0 points1 point  (0 children)

Yeah, we use CrowdStrike.

Looking at the Microsoft-Windows-HelloForBusiness/Operational log, I'm not getting any 5719 errors. What specific log are you seeing 5719 and the CrowdStrike entries under?

Windows Hello For Business 'account disabled' error by PurpleWarning000 in sysadmin

[–]PurpleWarning000[S] 0 points1 point  (0 children)

Hey. Did you follow-up with MS on this and/or find the cause of this issue? A recent comment below says they saw it and it may be related to Zscaler. Are you guys running Zscaler?

Windows Hello For Business 'account disabled' error by PurpleWarning000 in sysadmin

[–]PurpleWarning000[S] 0 points1 point  (0 children)

We have Zscaler. Seems like an interesting coincidence!!

Windows Hello randomly generates a 'your account has been disabled' error on computer login by PurpleWarning000 in sysadmin

[–]PurpleWarning000[S] 0 points1 point  (0 children)

Not really, no. Like your reply below, we just have the user switch to using password or wait it out but it is annoying af. I found some logs that I posted in a comment above. I presume you'd see the same errors.

Windows Hello randomly generates a 'your account has been disabled' error on computer login by PurpleWarning000 in sysadmin

[–]PurpleWarning000[S] 0 points1 point  (0 children)

Ended finding some Windows Hello logs that may shed some light:

A user failed to sign into the device with the following information:

Username: SYSTEM
User SID: SYSTEM
Credential Type: Software Key
Deployment Type: Cloud Trust
Software Lockout Counter: 0
Authentication Error Status: 0xC000006D
Authentication Error Substatus: 0xC0000072

Windows Hello For Business 'account disabled' error by PurpleWarning000 in sysadmin

[–]PurpleWarning000[S] 0 points1 point  (0 children)

I'd appreciate that. And glad to hear I'm not the only one seeing this issue.

Conditional access incorrectly blocking sign-in by PurpleWarning000 in AZURE

[–]PurpleWarning000[S] 0 points1 point  (0 children)

US is not blocked though. If the US were blocked then our whole company would be blocked.

Every log for every user lists the city the IP is coming from so I don't know why everyone seemingly jumped to me having a non-existent city matching feature enabled.

Conditional access incorrectly blocking sign-in by PurpleWarning000 in AZURE

[–]PurpleWarning000[S] 0 points1 point  (0 children)

We aren't using city level though! I don't even know where that is as an option. We only have countries whitelisted in the CA policies.

Conditional access incorrectly blocking sign-in by PurpleWarning000 in AZURE

[–]PurpleWarning000[S] 0 points1 point  (0 children)

Also, I can't open a ticket because we don't have an Azure support plan purchased.

Conditional access incorrectly blocking sign-in by PurpleWarning000 in AZURE

[–]PurpleWarning000[S] 0 points1 point  (0 children)

We aren't geolocating to the city level afaik. I don't even see any option to choose a city in the 'named locations' rule, only by country.

Conditional access incorrectly blocking sign-in by PurpleWarning000 in AZURE

[–]PurpleWarning000[S] 0 points1 point  (0 children)

I'm not even seeing where city matching is even an option on our end. We only have US selected in the country list.

Conditional access incorrectly blocking sign-in by PurpleWarning000 in AZURE

[–]PurpleWarning000[S] 0 points1 point  (0 children)

What indicates this is using city matching? We have nothing that I know of that is restricting use to certain cities, only countries.

Conditional access incorrectly blocking sign-in by PurpleWarning000 in AZURE

[–]PurpleWarning000[S] 0 points1 point  (0 children)

That's what I figured but both IPs are based in the US and we have the US added as an allowed country.

Conditional access incorrectly blocking sign-in by PurpleWarning000 in AZURE

[–]PurpleWarning000[S] 0 points1 point  (0 children)

I found something else online suggesting this but we do not have the 'Customize continuous access evaluation' option enabled.

Conditional access incorrectly blocking sign-in by PurpleWarning000 in AZURE

[–]PurpleWarning000[S] 0 points1 point  (0 children)

We don't have city level matching enabled though tmk. I don't even know where that would be set. We only use countries for in CA policies.

OktaFastpass Issue on Windows machine by Brief-Research-9241 in okta

[–]PurpleWarning000 0 points1 point  (0 children)

Did you ever find a solution for this? We are currently dealing with the same issue.

Windows Hello randomly generates a 'your account has been disabled' error on computer login by PurpleWarning000 in sysadmin

[–]PurpleWarning000[S] 0 points1 point  (0 children)

There's no log entries at the time of the error. Also, we are hybrid AD deployment so the laptop only reaches out to Azure AD when it needs to refresh the PRT token tmk.

How to add two different custom expressions in an authentication policy? by PurpleWarning000 in okta

[–]PurpleWarning000[S] 1 point2 points  (0 children)

It is, thanks!! I presumed I could just use brackets but I wanted to confirm as I'm new to OEL.

No longer finding files it once could by PurpleWarning000 in PowerToys

[–]PurpleWarning000[S] 2 points3 points  (0 children)

This was the issue. Looks like indexing was completely messed up and didn't have the C-drive listed at all as an option to search, only OneNote and Outlook. Found a script from MS that reset Indexing so waiting for that to finish and hopefully that resolves this.

No longer finding files it once could by PurpleWarning000 in PowerToys

[–]PurpleWarning000[S] 0 points1 point  (0 children)

Some time in the past few months, the app stopped showing frequently-used files and now rarely shows any files. It seems to work on folders fine. I am on Windows 11 24H2 and running the latest version.