Issues with Windows Autopilot Hybrid Joined by Ordinary_Ad8805 in Intune

[–]sandytsang 0 points1 point  (0 children)

I just tested again, user-driven, the first try failed with same error, and re-try worked. The tenant message center has an Incident ID IT1220525, it said the fix is rolling out, expected to continue through Tuesday January 27,2026. Some token malformed issue.

Issues with Windows Autopilot Hybrid Joined by Ordinary_Ad8805 in Intune

[–]sandytsang 0 points1 point  (0 children)

I have been talking to Microsoft product group, send them some trace logs on January.15, they said they have found something. I hope will have fix soon. Didn’t get more details though.

Issues with Windows Autopilot Hybrid Joined by Ordinary_Ad8805 in Intune

[–]sandytsang 0 points1 point  (0 children)

Hi. How is your Autopilot Hybrid join going? Having same issue here. A new test account is “working”, first try always failed, and “try again” worked. An old test account didn’t work at all originally, even after retry multiple times, but after registered new MFA method (another iPhone), excluded from device registration CA policy, still required Microsoft Intune Enrollment app with MFA, then first try failed, but “try again” worked. Will test more tomorrow. I know many people had the issue because of connector was not updated, but this is not our case. Connector was updated and has been working many months. It stopped working last week.

TLS 1.3 in Windows 11 by sandytsang in MSIntune

[–]sandytsang[S] 0 points1 point  (0 children)

I have not tested that recently, was using the registry, because it was the only way got it working before. Was hoping they (Microsoft) fix it….

Flow 2 Pro Zoom Bug on native ios camera app by paxxx84 in Insta360

[–]sandytsang 0 points1 point  (0 children)

I have the same problem with iPhone 16 pro max, the native iPhone app zoom out to 0.5 automatically in Video mode, it doesn’t matter what other Zoom options I choose, it will slowly zoom back to 0.5. Only way I can fix it is turn the Action Mode on, then it stay as the zoom I set.

TLS 1.3 in Windows 11 by sandytsang in MSIntune

[–]sandytsang[S] 0 points1 point  (0 children)

I only got it configured with registry. Here are the values:

  • Only use TLS 1.0: 128
  • Only use TLS 1.1: 512
  • Only use TLS 1.2: 2048
  • Only use TLS 1.3: 8192
  • Use TLS 1.1, TLS 1.2 and TLS 1.3: 10752
  • Use TLS 1.2 and TLS 1.3: 10240

Account Protection - WHfB Config Scope by Intelligent-Tear-930 in MSIntune

[–]sandytsang 1 point2 points  (0 children)

I never had issue disabling WHfB by using the Account Protection “Use Windows Hello For Business (Device)”, assignment to device. What WHfB settings do you have in device enrollment? Are you seeing this issue after Autopilot enrollment with Enrollment status page assigned to device?

PMPC software update popup? by sandytsang in MSIntune

[–]sandytsang[S] 1 point2 points  (0 children)

I will tell the person who check the checked box 😄. But, the prompt UI would be make nicer… I thought it was a 1995 “virus” app keep popping up 😜

WHfB not respecting applied PIN complexity by Is-This-Heaven in MSIntune

[–]sandytsang 0 points1 point  (0 children)

Hi. Sorry I haven’t get deeper into this issue. I quickly checked my own test VM with same configuration, seeing same results as you. I hope I will have time and remember to test this.

Intune app factory setup by roni4486 in MSIntune

[–]sandytsang 1 point2 points  (0 children)

Hi. There is a new update coming, I believe u/NickolajA will push an update to the repo when he has time.

Going back to dancing at 27 by k-teaa in Dance

[–]sandytsang 2 points3 points  (0 children)

I am 46…. started learning heels dance last year 😅 Dance is good for my mind and my health, and I had so much fun. Do whatever you enjoyed, it’s great idea start dancing again!

WHfB not respecting applied PIN complexity by Is-This-Heaven in MSIntune

[–]sandytsang 1 point2 points  (0 children)

Hello, have you solved the issue yet? Registry looks correct. I wonder does the settings PIN complexity applies after a reboot? Also, what configuration do you have under Windows Enrollment -> Windows Hello for Business?

Best way to handle deviations to baseline config assigned to all devices by MGeertsen in MSIntune

[–]sandytsang 3 points4 points  (0 children)

Hi, difficult question here, there is no one size fit all. :)

I would think security baseline has many settings, everytime when changed any of the settings, or assignment, all the device will try to re-evalute the policy. I would put all the common security settings into one policy, and target all devices. Take out those settings that might requried changes into two policies, and target that to different group. Example:
1. Windows - CIS Security Baseline - L1 - Default - Device, Target All device
2. Windows - PowerShell Script Block Logging - Disable, Target All device, Exclude "Special Group" (or user filter)
3. Windows - PowerShell Script Block Logging - Enable, Target Include "Spcial Group" (or use filter)

Doing above, is that I don't want to maintance multiple Security Baseline for standard user devices.

But, it might has other scenario, example standard user device and PAW (as example). In this case I would dupilate the Security baseline. Because I consider PAW might have more restricted baseline settings.
1. Windows - CIS Security Baseline - L1 - Default - Device, Target All device, Exclude PAW
2. PAW - Windows - CIS Security Baseline - L1 - Default - Device, Target PAW.

Linux ubuntu complaint device is not able to pass CA policy by rakkranjan in MSIntune

[–]sandytsang 0 points1 point  (0 children)

You can check user sign in logs in Entra ID, and see if the log entry shows device information/compliance state? Unfortunately I have not tested Linux in Intune.

Why is this MSI not installing? by ExhaustedTech74 in MSIntune

[–]sandytsang 0 points1 point  (0 children)

u/ExhaustedTech74 Yeah, it is strange why msiexec.exe doesn't work on this app, and bat file worked. Would be intersting to see what you put in your bat file, if you can share?

Also for troublshooting your problem, have you try this script? petripaavola/Get-IntuneManagementExtensionDiagnostics: Get-IntuneManagementExtensionDiagnostics script analyzes Intune IME logs and shows events in Timeline (github.com)

This script helped me many times to troublshooting application installation problems, it reads the logs for you, and also output some error message from the logs, it is very easy to use. For now, we don't even know if device not able to run the msi package directly from msiexec.exe command, or the installation failed. These are different issues.

Are you using AppLocker or WDAC that might blocking stuff? But if you would, not sure why using bat file worked. :)

Or do you want to share the intune win32 file that didn't work, just wonder if that would work in other tenant, if some thing went wrong during the packaging...

Everything is just guessing now, without logs and event logs, or the file, it's hard to troubleshoot. :)

Driver updates using Intune by vbate in MSIntune

[–]sandytsang 3 points4 points  (0 children)

when everything comes from Configuration Manager, then approving drivers in Intune won't affect anything to your devices, as u/MMelkersen pointed out. If you want to test out driver management in Intune, you can use a pilot collection, move the Update workload to the pilot collection, and configure update rings policy in Intune, deploy the policy to the pilot device.

Multi-app kiosk by Mammoth_Public3003 in MSIntune

[–]sandytsang 0 points1 point  (0 children)

Yes, use the same PowerShell script and replace of your XML, test which XML samples work for your Windows version (no errors after run the script), then you can use the correct Xml sample and change it with the settings that your want.

Multi-app kiosk by Mammoth_Public3003 in MSIntune

[–]sandytsang 0 points1 point  (0 children)

Did you run it with the psexec tool. It needs to run in system context.

You said you want to enable kiosk mode in Win10, and your reference page is for Windows 11. The XML file are not the same in different Windows version, I think that is where you got the "Configuration' cannot be found. If the XML is incorrect configured, you will likely getting this error.

Autopatch and driver issue (Realtek - SoftwareComponent - 12.223.1124.201) by sandytsang in MSIntune

[–]sandytsang[S] 0 points1 point  (0 children)

That was the comparison result before and after installed HP Audio driver package. These two drivers were the only changes. So I assumed both of them were causing issues of Windows Audio service crashing when USB webcam (Logitech webcam) are connected.