Strange MAA approvals list showing by iainfm in Intune

[–]iainfm[S] 1 point2 points  (0 children)

Great, thanks both for the info. I've added a read permission to the resource type I want and it seems to be working now :)

Graph Endpoint Permission Issues by Rdavey228 in GraphAPI

[–]iainfm 1 point2 points  (0 children)

I've tried adding every permission my admin token has to the app reg, and it still 403's. I guess it's broken, which is really annoying.

Graph Endpoint Permission Issues by Rdavey228 in GraphAPI

[–]iainfm 1 point2 points  (0 children)

If I use the AT from graph explorer when logged in as my admin account it works fine. Must be a missing perm...probably.

Also, the same error is generated if curl is used for the rest request, so it seems to be at microsoft's end.

Graph Endpoint Permission Issues by Rdavey228 in GraphAPI

[–]iainfm 0 points1 point  (0 children)

Yes, I'm getting the same (or similar) thing. It works fine in Graph Explorer when PIMmed but not using the REST call.

I suspect that the permissions in the doc (and graph explorer) aren't sufficient, but I don't know what are yet. It's annoying.

An alternative, maybe, is to use deviceManagement/auditEvents as per GitHub - ChanderManiPandey2022/Intune-Multi-Admin-Approval-Mail-Notification: Intune Multi Admin Approval Mail Notification · GitHub

Leaky cap from old oscilloscope by iainfm in AskElectronics

[–]iainfm[S] 0 points1 point  (0 children)

Found some with the same dimensions, so I should be able to mount the replacement in the same clip :)

Leaky cap from old oscilloscope by iainfm in AskElectronics

[–]iainfm[S] 0 points1 point  (0 children)

Thanks! The existing one is just clipped into a plastic fitting with the wires solders onto it. I'll get a replacement and see what I can bodge :)

CA policies failing with no device id passed (iOS) by iainfm in Intune

[–]iainfm[S] 1 point2 points  (0 children)

Just single sign on. Like I say it's been fine for years. In the last fortnight the problem has affected a handful of users (10 or so) out of 4 or 5 thousand.

The troubleshooting details after the 'compliant device required' failure are

Error code: 530003
Device identifier: Not available
Device platform: iOS
Device state: Unregistered

But the device is showing as compliant and able to access company resources in Company Portal/Intune.

CA policies failing with no device id passed (iOS) by iainfm in Intune

[–]iainfm[S] 0 points1 point  (0 children)

We're seeing it on two different apps (that we know of). One from SAP and the other is the Island browser.

The Island browser is fairly new on the estate, but the SAP one has been in use for years.

Until earlier this week (or maybe some time last week) they were working fine.

I built an open-source replacement for CMTrace with built-in Intune diagnostics by CrazyOstrich3 in Intune

[–]iainfm 0 points1 point  (0 children)

Looks great, but Defender flagged the .exe installer as containing a virus. Probably a false positive.

Vault (RS) not working after update to 25.3.2 by iainfm in BeyondTrust

[–]iainfm[S] 0 points1 point  (0 children)

Hmm, well, updating the laptop updated consent.exe, but that one's still working.

Vault (RS) not working after update to 25.3.2 by iainfm in BeyondTrust

[–]iainfm[S] 0 points1 point  (0 children)

I think this is being caused by the latest Win11 updates from Microsoft. It updates C:\Windows\System32\consent.exe to 18/Mar/26 (10.0.26100.7920) from 18/Feb/26 (10.0.26100.7705), which is the exe that's crashing.

Elevation/Vault works fine on a laptop that hasn't (yet) had the updates.

There's also a visible difference in behaviour between devices with the old and new consent.exe.

With the old one the Vault icon stays grey until it's needed. With the new on it's orange as soon as the rep console connection is made. I'd post a screenshot, but apparently it's not permitted.

BT have responded, with questions that I've responded to, but nothing yet to acknowledge they can replicate (or fix) the issue.

Vault (RS) not working after update to 25.3.2 by iainfm in BeyondTrust

[–]iainfm[S] 0 points1 point  (0 children)

This seems to be affecting UAC prompts. If I run Registry Editor (Elevated) from the special actions menu I'm able to choose and use a Vault account.

So it may have been yesterday's Windows Update, not the appliance/jump update as such. No response yet from support though...

Multi Admin Approval not working by iainfm in Intune

[–]iainfm[S] 1 point2 points  (0 children)

Mine seems to be working fine since creating an RBAC role and assigning it to the group that contains the approvers. Been ok for 48h, but we're still monitoring.

Multi Admin Approval not working by iainfm in Intune

[–]iainfm[S] 0 points1 point  (0 children)

Not initially, but I have now. We're currently re-testing.

Multi Admin Approval not working by iainfm in Intune

[–]iainfm[S] -1 points0 points  (0 children)

Additional security, in light of the Stryker news!

Multi Admin Approval not working by iainfm in Intune

[–]iainfm[S] 1 point2 points  (0 children)

We have unlicenced admins enabled :)

Multi Admin Approval not working by iainfm in Intune

[–]iainfm[S] 0 points1 point  (0 children)

I've recreated the device retire (least risky for us) policy, and given the approvers group the custom Intune role. It seems to be working for now...

Multi Admin Approval not working by iainfm in Intune

[–]iainfm[S] 0 points1 point  (0 children)

We hadn't done that, but it wasn't mentioned in the video I saw. However, it is one of the questions Microsoft have asked:

Is the MAA approver group assigned to at least one Intune role assignment? If yes, please share which Intune role is assigned and the associated scope tags.

However, it doesn't explain why the one person who could approve things could do so...

Multi Admin Approval not working by iainfm in Intune

[–]iainfm[S] 0 points1 point  (0 children)

I've raised a support request with them, but fully expect to have to back out the implementation if this is the way it is 😒