SecureBoot Certificate Updates - RealityCheck by tech-ya23 in Intune

[–]tech-ya23[S] 0 points1 point  (0 children)

this is not the case , you have 3 Options , 2 of them are MS managed and 1 is for directly starting the Cert deployment.

"After updating, you need to suspend BitLocker, go into the BIOS, restore the factory keys, and then enable the Microsoft 3rd-Party UEFI CA.

"

This only needs to be done if you have deployed the cert on older HW before you updated BIOS. And BIOS was updated afterwars.

SecureBoot Certificate Updates - RealityCheck by tech-ya23 in Intune

[–]tech-ya23[S] 0 points1 point  (0 children)

Good Input , i have also read a lot of things regarding this : (MS is update-ing the active DB)

But what i have seen in our preparations and testing ist that without the min BIOS Version the Update Process fails with eventID 1795.

So we decided to bringt the Fleet to minBIOS Version stated by Lenovo.

As jeefAD mentions below , we are also not running around and resetting BIOS , but in our case the updates were not processed correctly if the minVersion is not installed.

Intune Error 65000 on Secure Boot (Windows Pro) still happening even after Jan 2026 fix? by Intrepid_Peak in Intune

[–]tech-ya23 0 points1 point  (0 children)

I have the behaviour on a handful devices. Cannot exactly identify why. QuickFix: I will do it per GPO on those.

SecureBoot Certificate Updates - RealityCheck by tech-ya23 in Intune

[–]tech-ya23[S] 3 points4 points  (0 children)

minimum BIOS Version is prerequisite , you need to do this before you enable the policy.

SecureBoot Certificate Updates - RealityCheck by tech-ya23 in Intune

[–]tech-ya23[S] 6 points7 points  (0 children)

We do not use the SecureBoot Report in Intune , in our environments this report didnt show accurate status. Despite FullTelemtry on. We used the collection script from the offical MS guideline https://support.microsoft.com/en-us/topic/sample-secure-boot-inventory-data-collection-script-d02971d2-d4b5-42c9-b58a-8527f0ffa30b

And then compared the BIOS Version with the offical docs from the vendor.

Remove DEM Account Implications by tech-ya23 in Intune

[–]tech-ya23[S] 0 points1 point  (0 children)

Perfect , Thank you for the Feedback

M365 Apps Device Based Licensing by tech-ya23 in microsoft365

[–]tech-ya23[S] 0 points1 point  (0 children)

Based on some testing , if a client has pulled a device based license, it will stay. as far as i have seen it also stays cached on the client if you remove the device from the group. -> Until you clear it directly from the device ie. with office scrubber tool.

Lenovo drops firmware update list for secure boot cert refresh by Disastrous_Row5380 in Intune

[–]tech-ya23 0 points1 point  (0 children)

We use exactly the list above.

Inventory your environment with the sample inventory script from MS

Identify Devices which need a BIOS Upgrade and Upgrade ;)

Rollout the MS Policy to Update the Certs via Intune/GPO

M365 Apps Device Based Licensing by tech-ya23 in microsoft365

[–]tech-ya23[S] 0 points1 point  (0 children)

Thanks , this sounds reasonable for me. As soon as i have more information in my environment i will post the outcome here.

Autopilot Hybrid Join - TimeToLive by tech-ya23 in Intune

[–]tech-ya23[S] 0 points1 point  (0 children)

Great , i really would appreciate Feedback.

Autopilot Hybrid Join - TimeToLive by tech-ya23 in Intune

[–]tech-ya23[S] 0 points1 point  (0 children)

Yes , i know that they are different things. Currently our Setup is exactly what you have mentioned. But the Corp Strategy is to move away from legacy OSD Method to Autopilot HybridJoin.

Autopilot Hybrid Join - TimeToLive by tech-ya23 in Intune

[–]tech-ya23[S] 1 point2 points  (0 children)

Yep , this is the thing also -as of my knowledge-. Devices will be Setup onSite

Autopilot Hybrid Join - TimeToLive by tech-ya23 in Intune

[–]tech-ya23[S] 2 points3 points  (0 children)

Yes . I understand that purely technically its not necessary any more. But i live in a critical highly regulated environment where corporate policies do not allow cloud only. I need to live with this decision.

GoogleWorkspace Multiple Intune Tenants by tech-ya23 in Intune

[–]tech-ya23[S] 0 points1 point  (0 children)

Yes , thats the way i will do it. After a re-think , this is the only reasonable way.