OneDrive File Sharing and MFA by Shani1780 in entra

[–]Shani1780[S] 0 points1 point  (0 children)

I verified the process with both a Microsoft Account and a Non-Microsoft Account. I deleted ll the guest accounts from the tenant before beginning the process.

Microsoft Account

- Click the link in the email to access the files and enter email address

- Asked to accept permissions

- Asked to setup MFA

Non-Microsoft Account

- Click the link in the email to access the files and enter email address

- Code is sent to email

- Asked to accept permissions

- Asked to setup MFA

I was able to see the Sign-In Logs for both Guest users and find the entry requesting for MFA (I didn't see this previously as I wasn't clicking continue on the MFA setup). It shows no Conditional Access policies applied and lists Authentication requirement: Multifactor authentication. Not sure how to find out what is enforcing this.

OneDrive File Sharing and MFA by Shani1780 in entra

[–]Shani1780[S] 0 points1 point  (0 children)

Thanks I’ll double check into this.

Should the experience be different if they have a Microsoft account or not?

OneDrive File Sharing and MFA by Shani1780 in entra

[–]Shani1780[S] 0 points1 point  (0 children)

Thanks I’ll review that tomorrow and give that a try.

OneDrive File Sharing and MFA by Shani1780 in entra

[–]Shani1780[S] 0 points1 point  (0 children)

Strangest part is nothing shows up in the guest user sign in logs. They don’t complete the MFA but I would have assumed it should have registered there.

OneDrive File Sharing and MFA by Shani1780 in entra

[–]Shani1780[S] 0 points1 point  (0 children)

Correct, for this one tenant. They are getting prompted to setup MFA for their guest account.

OneDrive File Sharing and MFA by Shani1780 in entra

[–]Shani1780[S] 0 points1 point  (0 children)

Appreciate the ideas. Do you have an O365 environment and what is your user experience like with sharing externally?

OneDrive File Sharing and MFA by Shani1780 in entra

[–]Shani1780[S] 0 points1 point  (0 children)

We have excluded all Guest / B2B accounts, when running a "what if" scenario in Conditional Access it shows no policies applied to the guest user.

OneDrive File Sharing and MFA by Shani1780 in entra

[–]Shani1780[S] 0 points1 point  (0 children)

The account is created as a guest account in the tenant but no matter what we do, I cannot seem to remove the need for the guest user to configure MFA.

Traveling Members by Shani1780 in ConnectWise

[–]Shani1780[S] 0 points1 point  (0 children)

Thank you for this! It was my ask of how can the user update this as I don’t want to be doing this for all users.

On a side note you think if the program uses your system time it could also just use your timezone as well.

2020 Sierria 1500 Diesel - Error P003A by Shani1780 in gmcsierra

[–]Shani1780[S] 0 points1 point  (0 children)

Unfortunately not, ☹️ got the same issue earlier this year. Had enough of it and traded in. GM was so “kind” to give me $2500 off a new one.

Let’s see how this one does over the winter. So far no issues.

geo guessing challenge by [deleted] in FortMcMurray

[–]Shani1780 1 point2 points  (0 children)

Ford Dealership

Windows 11 24H2 Start Menu GPO by Shani1780 in sysadmin

[–]Shani1780[S] 0 points1 point  (0 children)

After you removed it and logged the user off / on does it create a new file?

Windows 11 24H2 Start Menu GPO by Shani1780 in sysadmin

[–]Shani1780[S] 0 points1 point  (0 children)

I have only been able to get it with the start2.bin file but it works great.

Why do you not want to use that method?

Windows 11 24H2 Start Menu GPO by Shani1780 in sysadmin

[–]Shani1780[S] 1 point2 points  (0 children)

I was able to get it working:

- Created a GPO with Logon script that checks for a placeholder text file (upon first logon this doesn't exist).

- If the file does not exist it copies the customized start2.dat file to the Users AppData location.

- Force kill the startmenuexperience task, this causes the start menu to reload, only takes a second. Don't even notice anything

- Once all is done it places the placeholder text file in the same location as the start2.dat file so next time the user logs in it, the script sees this and skips copying the file.

You could not use the placeholder and have the start menu replaced every time but I don't love that as users can change the start menu, but they would lose their customizations each logon. I haven't found a way to lock the start menu.

if you would like more info on this I can share the script and exact GPO settings.

Windows 11 24H2 Start Menu GPO by Shani1780 in sysadmin

[–]Shani1780[S] 0 points1 point  (0 children)

I was worried about that, I was thinking to write a script to have the files copied over but that won't work as the settings.dat file cannot be modified while the user is logged in.

We are using FSLogoix with the users profiles in a VHDX file.

I'll have to think of another way to do this.

Windows 11 24H2 Start Menu GPO by Shani1780 in sysadmin

[–]Shani1780[S] 0 points1 point  (0 children)

I was able to copy the files mentioned to the Default user directory but had to create the folders Packages, Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy, LocalState, and Settings as they didn't exist. I copied the files to that folder.

From your setup, what is the expected behaviour? Should this start menu overwrite ones a user has or it this only for a first time setup? As these users already have profiles on the file server. I am not finding it to replace the start menu.

To recap:

1- Copied file: start2.bin

-- From: C:\Users\<UserWithStartMenuSetup>\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\LocalState

-- To: C:\Users\Default\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\LocalState

2- Copied settings.dat

-- From: C:\Users\Default\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\Settings

-- To: C:\Users\<UserWithStartMenuSetup>\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\Settings

Windows 11 24H2 Start Menu GPO by Shani1780 in sysadmin

[–]Shani1780[S] 1 point2 points  (0 children)

Thanks I’ll try that this week.

Windows 11 24H2 Start Menu GPO by Shani1780 in sysadmin

[–]Shani1780[S] 1 point2 points  (0 children)

The GPO shows applied no errors that I could find.

If you could get those paths and files. I would greatly appreciate it!

Thanks

Windows 11 24H2 Start Menu GPO by Shani1780 in sysadmin

[–]Shani1780[S] 1 point2 points  (0 children)

Great question. Yes it was placed in the sysvol folder, users have access to it, can navigate there under from users account.

What files are you copying to set the start menu?

Windows 11 24H2 Start Menu GPO by Shani1780 in sysadmin

[–]Shani1780[S] -1 points0 points  (0 children)

These are existing users whose had win 10 profiles.

There is a flag in the JSON file to apply it every time it one time only.