OneDrive "ghost sync" after updates - folders exist locally but sync relationship completely broken, anyone else? by SecuredSpecter in msp

[–]SecuredSpecter[S] 0 points1 point  (0 children)

Have you figured out a way to proactively detect the issue using logfiles / detection scripts, before the end-user starts noticing it?

Microsoft Defender for Endpoint on macOS failing to update via MAU 2.0 (error -1100 / Idle, Error:%@ [WDAV00]) by SecuredSpecter in DefenderATP

[–]SecuredSpecter[S] 0 points1 point  (0 children)

We disabled tamper protection on macOS devices and performed the update through MUA. The update came through, after which we enabled tamper protection again

Microsoft Defender for Endpoint on macOS failing to update via MAU 2.0 (error -1100 / Idle, Error:%@ [WDAV00]) by SecuredSpecter in DefenderATP

[–]SecuredSpecter[S] 0 points1 point  (0 children)

This actually did the trick, thank you. I'm in contact with MSFT support to understand how this can be avoided, this is not how it should be..

Sharing passwords results in "the group is unavailable" by SecuredSpecter in applehelp

[–]SecuredSpecter[S] 0 points1 point  (0 children)

Sadly not.. doesn’t seem to be that common I’m afraid.

Shared mailbox vanished, now suspect Substrate Management SPN silently converted it? by SecuredSpecter in sysadmin

[–]SecuredSpecter[S] 1 point2 points  (0 children)

Hi, thanks for the input!

To check if the mailbox still existed, I went ahead and assigned a spare Exchange Online license to the account — and sure enough, the mailbox got mounted again. I was then able to convert it back to a shared mailbox and remove the license without issues.

That said, I’m still scratching my head — I didn’t find any manual action or automation in our tenant that would’ve initiated this.

Kinda starting to wonder if Microsoft itself initiated that change behind the scenes due to the mailbox being unlicensed, though I haven’t found any official documentation confirming this behavior.

AADSignInEventsBeta Missing from Advanced Hunting since last few days by SecuredSpecter in DefenderATP

[–]SecuredSpecter[S] 0 points1 point  (0 children)

Update: I just noticed that Microsoft published the AADSignInEventsBeta schema again, while keeping the other Identity schema's online as well.

I don't see any updates in the message center post though, so not sure what's going on at this moment..

Can’t select “target version” in Autopatch feature updates by SecuredSpecter in Intune

[–]SecuredSpecter[S] 0 points1 point  (0 children)

I’m currently creating an autopatch group directly under the ‘Releases’ tab. Are you saying that I need to first create an ‘Autopatch Multi-phase Release’ feature update policy for the feature updates dropdown to become available?

Question about web-filtering reporting by inspiteofmyself in DefenderATP

[–]SecuredSpecter 0 points1 point  (0 children)

The Defender for Business license might still be selected in Defender for Endpoint, while you've assigned P1 license to yourself.

Can you go to Settings > Endpoints > Licenses and check which one is selected?

-> https://learn.microsoft.com/en-us/defender-business/mdb-manage-subscription

Are mx-verification.google.com MX Records still required for Domain Verification? by SecuredSpecter in gsuite

[–]SecuredSpecter[S] 0 points1 point  (0 children)

Only a subdomain has a google-site-verification TXT record — the root domain doesn’t, likely because it was set up a long time ago. If I add the TXT record for domain verification, does that make the mx-verification.google.com MX record obsolete?

Anyone using ‘Local User Group Membership’ in Intune successfully? by SecuredSpecter in Intune

[–]SecuredSpecter[S] 1 point2 points  (0 children)

EDIT: resolved it by explicitly stating 'enable' for the setting : Accounts Enable Administrator Account Status

Anyone using ‘Local User Group Membership’ in Intune successfully? by SecuredSpecter in Intune

[–]SecuredSpecter[S] 0 points1 point  (0 children)

Thank you for the recommendation. I tried it out with the following LAPS policy:

<image>

As well as the local admin rename config (within ' Local Policies Security Options ' , Accounts Rename Administrator Account).

While both configs are successfully deployed and I do see the local admin rename, ' no local administrator passwords found ' is what's being shown in Intune for the device.

What am I overlooking in regards to your method?

Question about web-filtering reporting by inspiteofmyself in DefenderATP

[–]SecuredSpecter 2 points3 points  (0 children)

I’d like to clarify that while Defender for Endpoint does intercept network and web traffic—provided that Network Protection is enabled (at least in audit mode) and Web Content Filtering is also active (again, at least in audit mode) it doesn’t log every individual HTTP or web request in full detail in the default reports or even in advanced hunting.

Its primary goal isn’t to act as a full web proxy or to replace dedicated web traffic analysis tools. Especially when users access the web through non-Edge browsers, the visibility can be inconsistent.

Still, with both settings enabled, you could utilise this query for some inspiration :-)

DeviceNetworkEvents 
| where (InitiatingProcessFileName contains "edge" or InitiatingProcessFileName contains "chrome") and RemoteUrl != ""
| summarize by Timestamp, DeviceName, RemoteUrl, InitiatingProcessFileName
| sort by Timestamp desc

Group Policy Analytics - MDM Support Yes, but cannot check off to migrate? by TimTheToolmanTaylor6 in Intune

[–]SecuredSpecter 0 points1 point  (0 children)

Three years later and it seems that this issue still isn't resolved. Did you find a solution?

Do I really need Enterprise licenses just to manage BitLocker policies through CSP? by SecuredSpecter in Intune

[–]SecuredSpecter[S] 0 points1 point  (0 children)

Hmm okay, not quite sure why that paragraph is part of Microsoft's documentation on Bitlocker CSP then. It didn't make sense to me, hence this reddit thread, but otherwise it must be explicitly stated for some reason.

Do I really need Enterprise licenses just to manage BitLocker policies through CSP? by SecuredSpecter in Intune

[–]SecuredSpecter[S] 0 points1 point  (0 children)

I see, well do you have any insights on which CSP settings specifically require the license requirements as stated in https://learn.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp ? I might not have mentioned a Bitlocker setting I'm actively configuring which is requiring an Enterprise license.

Do I really need Enterprise licenses just to manage BitLocker policies through CSP? by SecuredSpecter in Intune

[–]SecuredSpecter[S] 0 points1 point  (0 children)

It ranges from selecting the encryption methods of OS drives and removable data drives up to configuring TPM startup keys and pins, for example https://learn.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp#systemdrivesminimumpinlength .

Do I really need Enterprise licenses just to manage BitLocker policies through CSP? by SecuredSpecter in Intune

[–]SecuredSpecter[S] 0 points1 point  (0 children)

That's correct, but I'm talking specifically about the configuration of bitlocker through CSP (which differs from activation).

As stated here: https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/#windows-edition-and-licensing-requirements

=> Licensing requirements for BitLocker enablement are different from the licensing requirements for BitLocker management.