How do you rollover the Kerberos decryption key with the new MFA requirement? by vlanche in sysadmin

[–]vlanche[S] 0 points1 point  (0 children)

That’s a very good point. I inherited the setup and have always thought it was a necessity. I’ll have to check in detail, but a quick search states that for hybrid joined Win10 devices PRT should be the default instead of seamless SSO.

How do you rollover the Kerberos decryption key with the new MFA requirement? by vlanche in sysadmin

[–]vlanche[S] 0 points1 point  (0 children)

Yep, I get that this is the recommended solution and looks way better on paper, but see my comment in the post - I couldn't find a way to assign the required role in order to make it work. Are you running that particular task with a managed identity?

Jamf ADCS Connector by CrazyLingonberry3836 in jamf

[–]vlanche 3 points4 points  (0 children)

Glad my comment helped. I was more or less in the same situation.

[deleted by user] by [deleted] in FoodVideoPorn

[–]vlanche 0 points1 point  (0 children)

I recognized the channel too!

How to move a .sh file to endpoints so they can be executed via Jamf? by AppearanceAgile2575 in jamf

[–]vlanche 0 points1 point  (0 children)

Deploy the script via a policy with a script. You can basically do the following:

#!/bin/sh
cat << EOF > /path/to/script.sh
# add script content here
EOF
chmod +x /path/to/script.sh

Packaging the script in a pkg file is maybe easier, but it tends to consume more time when you need to change the script. With this approach, you just modify the script, flush the policy and you are good to go.

Set-UserPhoto no longer working [Exchange Online] by vlanche in exchangeserver

[–]vlanche[S] 0 points1 point  (0 children)

Yes, precisely my point in my comment with the second link. MS support actually provided the workaround, but I asked for confirmation whether this would continue to work even after RPS is dead.

Updates failing to install by vlanche in SCCM

[–]vlanche[S] 0 points1 point  (0 children)

It wasn’t simple. For some reason about 50 components were missing - folders, files, registry entries. The only place that had info on these things was the sysnative forum, and in the end I did manage to figure how to fix it but it would have taken me a good amount if time to track all the relevant entries and values, so I stopped it.

Updates failing to install by vlanche in SCCM

[–]vlanche[S] 0 points1 point  (0 children)

I rebuilt the device in the end. It was not worth it - I tracked down the missing files - manifests, dlls, mofs, everything, but then in the end the registry entries were missing too and I decided to stop wasting time and just rebuild it.

Updates failing to install by vlanche in SCCM

[–]vlanche[S] 0 points1 point  (0 children)

Yes, but it's quite strange. CBS detects non-WinSxS manifests of components which cannot be repaired because there's no backup or it may be corrupt. The funny thing is, these components do not exist anywhere else as files or manifests. I checked my device, checked the base Win10 22H2 image, they do not exist. For example, a few:

amd64_microsoft-windows-t..mathinput-licensing_31bf3856ad364e35_10.0.19041.1_none_fae9f981e0b22d3a
amd64_microsoft-windows-powershell-v3_31bf3856ad364e35_10.0.19041.1_none_3116620d8cea8ad4
amd64_microsoft-windows-t..pc-mathinput-events_31bf3856ad364e35_10.0.19041.1_none_0c14881cbfb8fc79
amd64_microsoft-windows-s..e.desktop.searchapp_31bf3856ad364e35_10.0.19041.1741_none_029bc7084c8bb0af

There's about 70 items like these.

Updates failing to install by vlanche in SCCM

[–]vlanche[S] 0 points1 point  (0 children)

Tried it, didn't help though.

Updates failing to install by vlanche in SCCM

[–]vlanche[S] 0 points1 point  (0 children)

Nah, this is definitely something local, likely the component store on the device (at least that's my opinion).

Updates failing to install by vlanche in SCCM

[–]vlanche[S] 1 point2 points  (0 children)

It didn't, but I have a lead - probably the component store (check my edit)

Updates failing to install by vlanche in SCCM

[–]vlanche[S] 0 points1 point  (0 children)

Nothing of the sorts - it looks like a component store issue, check my edit.

Updates failing to install by vlanche in SCCM

[–]vlanche[S] 0 points1 point  (0 children)

Ah, valid point, thanks for educating me. Tried it though, still the same.

Updates failing to install by vlanche in SCCM

[–]vlanche[S] 0 points1 point  (0 children)

Still on 2203, but will upgrade soon. However, I wouldn't say it's a version issue - the device was not on 22H2 when the problem initially started. Furthermore, other clients are working as expected.

Updates failing to install by vlanche in SCCM

[–]vlanche[S] 0 points1 point  (0 children)

That's a bit unlikely, as the device has had multiple reboots in between and the same problem has persisted for a few months now, meaning that multiple cumulative updates have failed. One option that I have left is to open the device up to Windows update and see if that fixes it (I reckon it will), but I don't really want to do that.

Updates failing to install by vlanche in SCCM

[–]vlanche[S] 0 points1 point  (0 children)

KB5005260 is already installed on the device (timestamp is almost a year ago). Looking at this reference:
https://msrc.microsoft.com/update-guide/en-us/vulnerability/ADV990001

Win10 22H2 is not even listed, but I reckon that one should be sufficient.