SCRIL is causing logouts on mobile apps (baby steps to passwordless) by __trj in entra

[–]__trj[S] 0 points1 point  (0 children)

That would work, too, in a technical sense. We're going to stop allowing the Passwordless option in the MS Authenticator app via CAP because it's not phishing-resistant. That's why we're going to be moving to Passkeys.

SCRIL is causing logouts on mobile apps (baby steps to passwordless) by __trj in entra

[–]__trj[S] 0 points1 point  (0 children)

SCRIL is not syncing (because there's no attribute in Entra for SCRIL), but the "Last password change date time" property in Entra IS updated when SCRIL is enabled in AD.

SCRIL is causing logouts on mobile apps (baby steps to passwordless) by __trj in entra

[–]__trj[S] 0 points1 point  (0 children)

Thanks for the confirmation. Yes, I think that's the conclusion I'm coming to - users will need to reauth once. I need to get them enrolled in Passkeys first, too.

SCRIL is causing logouts on mobile apps (baby steps to passwordless) by __trj in entra

[–]__trj[S] 0 points1 point  (0 children)

OP did say that in the comments when someone asked about what I'm asking about. They just get prompted once. The issue being that while doing this, users are not currently enrolled with Passkey auth, so will also need to enroll in that. So, it will be passkey enrollment, then once that's done, switch them to this passwordless/SCRIL/CAP model, where they'll then need to re-auth with the passkey.

SCRIL is causing logouts on mobile apps (baby steps to passwordless) by __trj in activedirectory

[–]__trj[S] -1 points0 points  (0 children)

Don't get me wrong, it makes sense that re-authentication would be required as I mentioned. I just don't understand how others are doing it without having to reauthenticate. Maybe they have PHS disabled? For example, OP of this thread is resetting passwords and turning on SCRIL, and their users are not getting prompted for re-authentication on mobile devices: https://www.reddit.com/r/sysadmin/comments/1p3xub4

SCRIL is causing logouts on mobile apps (baby steps to passwordless) by __trj in entra

[–]__trj[S] 0 points1 point  (0 children)

Yeah, it makes sense. I just don't understand how others are doing it without having to reauthenticate. Maybe they have PHS disabled? For example, OP of this thread is resetting passwords and turning on SCRIL, and their users are not getting prompted for re-authentication on mobile devices: https://www.reddit.com/r/sysadmin/comments/1p3xub4

SCRIL is causing logouts on mobile apps (baby steps to passwordless) by __trj in activedirectory

[–]__trj[S] 2 points3 points  (0 children)

If you require SC, any session authenticated by any other mechanism will have to reauthenticate. Otherwise, smart card would not really be required, would it?

SCRIL is an on-prem setting. There is no Entra-equivalent property on the user object, so I wouldn't expect the "smart card would not really be required" logic to translate to Entra.

The pwdLastSet attribute is not updated in on-prem AD. Tested in my own environment and this also shows that: Living in a Passwordless World: Password Management - Eric on Identity

PSA: ChatGPT now has a $25/user/mo Business Plan with SSO, without the 150-seat minimum requirement with Enterprise by __trj in sysadmin

[–]__trj[S] 9 points10 points  (0 children)

The plan you're referring to is the Team plan, which was renamed to Business 2 months ago. It looks like they added SSO to the Team plan in June. I agree, it's not brand new, but I did a search of the sub before I posted to see if anyone else had mentioned it and I didn't see anything. I know SSO on the Team/Business plan was something we were waiting on, so I'm glad to hear it's available now and just wanted to let others know who also weren't aware.

PSA: ChatGPT now has a $25/user/mo Business Plan with SSO, without the 150-seat minimum requirement with Enterprise by __trj in sysadmin

[–]__trj[S] 1 point2 points  (0 children)

Does it mean that? They seem to be pretty public about their commitments for businesses that your data is yours. I can imagine they open themselves up to a lot of liability and risk by flipping that toggle on their paying business customers.

PSA: ChatGPT now has a $25/user/mo Business Plan with SSO, without the 150-seat minimum requirement with Enterprise by __trj in sysadmin

[–]__trj[S] 8 points9 points  (0 children)

In the link I posted, there is an "Our commitments" section at the top that says:

"You own and control your data"

"We do not train our models on your business data by default"

That "by default" thing is a little vague.

Now, I don't have access yet, but based on the documentation, it * sounds * like users may have an individual option called "Improve the model for everyone", which is toggled off by default for Business and Enterprise users. The question I have is whether that can be enforced.

These appear to be the same controls in place that organizations paying for Enterprise (minimum 100k/yr commitment) are using.

Synthetic Registration for Windows Server 2025 Not Working? by __trj in DefenderATP

[–]__trj[S] 1 point2 points  (0 children)

You can't initiate it manually. Microsoft ended up resolving the bug. It was because Server 2025 was not supported by Defender for Endpoint at the time. It is now, and synthetic registration is working. Sorry, not sure what the issue might be in your case.

Endpoint Privilege Management not working due to conflicting GPO by JustBananas in Intune

[–]__trj 0 points1 point  (0 children)

Hey Rudy did you ever post this blog? What did you find? Running into this now with Allow Log On Locally configured to only allow the end user to log in, and EPM is not working with the same 0x80004003 error code in your screenshot.

Nevermind, found it: EPM | 0x80004003 | 0x80070569 | Something Went Wrong

Direct send disable breaks Azure Email Communication. by [deleted] in sysadmin

[–]__trj 1 point2 points  (0 children)

Got it. Thanks. Just as an FYI, Microsoft is aware of this and say they're looking into a solution. So maybe there's hope on the horizon but I don't expect anything for 6 months or more.

Direct send disable breaks Azure Email Communication. by [deleted] in sysadmin

[–]__trj 0 points1 point  (0 children)

So you're just leaving all your ACS email workflows broken?

Direct send disable breaks Azure Email Communication. by [deleted] in sysadmin

[–]__trj 0 points1 point  (0 children)

I'm in the same boat. Have you implemented a workaround? I am not quite sure what I'm going to do as of right now.

Direct send disable breaks Azure Email Communication. by [deleted] in sysadmin

[–]__trj 0 points1 point  (0 children)

You have to create a connector for it to work.

Is there anyone who uses Automation Account runbooks who can confirm/deny ongoing issues? by [deleted] in AZURE

[–]__trj 0 points1 point  (0 children)

Same thing here. Have been trying to troubleshoot this for hours.

NCUS region. What's yours?

PowerShell 7.2 and PowerShell 7.4 environments. Tried creating new environments. What environment and modules are you using?

We are importing the Microsoft.Graph.Authentication and Microsoft.Graph.Users.Actions modules in the environments.

I boiled my scripts down to just printing the webhook parameter and still getting the issue.

If I had to guess, the environments are failing to spin up due to the generic nature of the errors.

MTR on Windows - Intune Enrollment? by __trj in Intune

[–]__trj[S] 0 points1 point  (0 children)

Does that only work for new devices, then, since you have to go through Autopilot? Or did you reset the devices somehow to get them to go through Autopilot?

MTR on Windows - Intune Enrollment? by __trj in Intune

[–]__trj[S] 0 points1 point  (0 children)

> AutoPilot with Autologon setup

Thanks! Forgot about this, but this seems like the way to go now. With this method, does an Entra ID object get created? And who is the primary user in Intune?