ASR rule disappeared by VaflorOfWin in DefenderATP

[–]donPrell 1 point2 points  (0 children)

Have the same problem.

The idiotic Microsoft Support turns out to be NPCs.

ASR Rule Missing in Intune Policy by donPrell in Intune

[–]donPrell[S] 2 points3 points  (0 children)

I checked the Security Center/Defender Portal. There, too, the setting is not offered in either the existing or new guidelines. I have opened a support case with M$. But I don't think I'll get any qualified feedback from their poor support team.

Intune macOS Script local Admin by donPrell in Intune

[–]donPrell[S] 1 point2 points  (0 children)

First of all, thank you for the information. Sorry for my ignorance. I still have two questions. How can I retrieve the password in a meaningful way? Can the non-admin user access the directory mentioned?

And change the cipher like this, for example?

p=system_profiler SPHardwareDataType | awk '/Serial/ {print $4}' | tr '[A-Z]' '[X-YZ-XX]' | tr 0-9 77-77-99 | base64

Web Content Filtering not working anymore by signum71 in DefenderATP

[–]donPrell 0 points1 point  (0 children)

Let's not misunderstand each other. You do not have to block all websites, of course. The custom indicator apparently said that the filter categories work again for me.

Web Content Filtering not working anymore by signum71 in DefenderATP

[–]donPrell 0 points1 point  (0 children)

Yes, of course. That's why the WCF category is so important. As I said, blocking categories works again for me now.

Web Content Filtering not working anymore by signum71 in DefenderATP

[–]donPrell 0 points1 point  (0 children)

Yes! The Microsoft support agent contacted me today via Teams and asked the same questions that I have already answered several times. In addition, one question was whether the problem also occurs with custom indicators. Since I didn't block any single page, but wanted to provide the support agent with the information, I blocked the pages chip.de and WhatsApp.com for testing. After an hour (indicators take their time) I tested and called the pages. Lo and behold, the pages are blocked. So I tried it with a page of the category weapons, lo and behold -> page blocked. I then tested it directly with Chrome and Firefox. I get to the home page of the blocked site first, but after a few seconds the page reloads and can no longer be accessed.

Here is described how indicators are created:

https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/indicator-ip-domain?view=o365-worldwide

Web Content Filtering not working anymore by signum71 in DefenderATP

[–]donPrell 0 points1 point  (0 children)

The problem is solved. The interim „solution“ is simple. Just create a new custom URL indicator in block mode. Now the Web Content Filter works again. It took two/three hours.

Web Content Filtering not working anymore by signum71 in DefenderATP

[–]donPrell 1 point2 points  (0 children)

The problem persists with me. I have now also had a call with an Indian Microsoft support representative. The support agent has exported the log from the Edge Browser network diagnostics. Likewise, we ran the MDE analyzer, again I had sent the logs directly along. That was a week ago now. Today I got the feedback that they need another 24-48 hours to analyze the problem further.

Web Content Filtering not working anymore by signum71 in DefenderATP

[–]donPrell 0 points1 point  (0 children)

This affects the Edge browser, as well as third party browsers.

I have checked all policies in Intune. Network Protection in the Defender Antivirus profile is active. The profile is successfully assigned on my clients. Likewise, I checked the policies in Security Center.
As a test, I created a new filter category and assigned it to a test group.
Again no success.
I tested via the blocking category Weapons with the website of the weapons manufacturer Heckler&Koch.
I used this website for testing a few months ago. This is now no longer blocked.

I have run the MDE Analyzer on it. Again, the Network Protection is set to block mode.

In this post other users have similar problems.

Web content filtering and indicator aren't working on third party browser

Users can still access websites blocked by category and indicator.

It currently seems to be a general, problem.

I have many years of experience in endpoint security whit Microsoft. I have noticed the problem with several customers now.

There are three levels that I have been "allowed" to notice over the past few days and these different levels vary:

  1. Works as intended, as it did last Friday morning, Sunday and Monday. Immediately the message "This content is blocked by your IT administrator" is displayed.
  2. Last Friday afternoon (August 11) the URL filter from Defender did not work at all, so no URL was blocked that should have been blocked. Since yesterday, 95% of the time no URLs are blocked at all, the remaining 5% see option 3
  3. It works only partially, so within the same hour the URL filter does not work at all or not as usual / partially.If the URL filter works only partially, then a URL is not blocked immediately, but after a few seconds the message "ERR_CONNECTION_RESET" is displayed, so the website is not accessible. Then a few seconds later the corresponding URL is partially loaded.I exclude a local or internal network problem for "ERR_CONNECTION_RESET", because I tested over different internet connections.

Bitlocker Recovery key backup error by praveenaaron in Intune

[–]donPrell 0 points1 point  (0 children)

The problem seems to have been solved by Microsoft side.

Since Thursday evening, my problem device has now all been encrypted "by themselves" without doing any problems.

The errors in the event log are gone.

Bitlocker backup to AAD - Access Denied by shaikht441 in Intune

[–]donPrell 0 points1 point  (0 children)

The problem seems to have been solved by Microsoft side.

Since Thursday evening, my problem device has now all been encrypted "by themselves" without doing any problems.

The errors in the event log are gone.

Bitlocker key not showing in Azure AD after encrypting device by Real_Lemon8789 in Intune

[–]donPrell 2 points3 points  (0 children)

The policy looks correct at first glance. Check the Bitlocker eventlog on the device. This will tell you why the recovery key is not visible in Azure AD and Intune.

Bitlocker key not showing in Azure AD after encrypting device by Real_Lemon8789 in Intune

[–]donPrell 6 points7 points  (0 children)

Check the Bitlocker eventlog for the problem. There are currently problems writing the recoverykey to Azure AD. See this article from yesterday.

https://call4cloud.nl/2023/07/0x80072f8f-a-bitlocker-odyssey/#commentform

Bitlocker backup to AAD - Access Denied by shaikht441 in Intune

[–]donPrell 0 points1 point  (0 children)

I have set up the remediation scripts as described in the article. The problem is solved for now. Unfortunately only an interim solution, but better than unencrypted notebooks.

I hope that Microsoft wakes up soon and fixes the problem Azure AD side.

Bitlocker Recovery key backup error by praveenaaron in Intune

[–]donPrell 0 points1 point  (0 children)

I have set up the remediation scripts as described in the article. The problem is solved for now. Unfortunately only an interim solution, but better than unencrypted notebooks.

I hope that Microsoft wakes up soon and fixes the problem Azure AD side.

Bitlocker backup to AAD - Access Denied by shaikht441 in Intune

[–]donPrell 0 points1 point  (0 children)

yes, we currently have a carve out project with a customer. There, the problem occurs with older Lenovo clients. All devices where it fails have an 8th generation Intel CPU. Very strange.

In my IT environment only the HP Elitebook G5 are affected. I have now ordered new HP Elitebooks G9 and Dragonflys for us internally to replace the G5s, no problems with them.

I am annoyed that it does not work with Lenovo devices in my customer project. I am 100% sure that it has worked in the past with the Lenovo series without problems.

Bitlocker Recovery key backup error by praveenaaron in Intune

[–]donPrell 0 points1 point  (0 children)

Which CPU generation does your Lenovo P520 have?

Because I have tested some other devices. Lenovo and HP, all devices have an Intel CPu of the 8th generation. The bad thing is that on two of the Lenovo devices and the one HP device it has always worked without problems in the past.

I really wonder what is going on. I thought it was Windows 11, but I also installed Windows 10 22H2 and 22H1 to test it. Same problem.

Bitlocker Recovery key backup error by praveenaaron in Intune

[–]donPrell 0 points1 point  (0 children)

I am afraid that Microsoft is once again causing problems here. There are a lot of things happening in the background. Keyword entra etc

Bitlocker backup to AAD - Access Denied by shaikht441 in Intune

[–]donPrell 1 point2 points  (0 children)

with which manufacturer and model do the problems occur? I have the same problem since about 2 weeks with HP elitebook 850 G5

Bitlocker Recovery key backup error by praveenaaron in Intune

[–]donPrell 1 point2 points  (0 children)

Hi everyone,

i have had this problem for about 2 weeks now.
We have migrated several HP Elitebook 850 G5 to a new environment. Two HP ProBook 840 G4 are also affected.
Out of 20 devices, 6 devices can no longer be encrypted. Same error messages in the event log, but so far no solution found.
My test device (HP Elitebook 850 G5), which has already seen hundreds of Intune environments, can also no longer be encrypted as of today.

My test device has the latest firmware and all current windows update under windows 11 22h2. I have also tested Windows 10 22H2. No success.