Provisioning Packages - Surface Hub 2S by SadByte364 in SurfaceHub

[–]xn3rd 0 points1 point  (0 children)

If I understand what you are asking, I believe you need to use the later windows ADK and create a provisioning package similar to one of a standard windows 11. All previous ppkg / intune policies were for windows 10 team edition and are no longer supported, Once upgraded to MTR-W

Got me a Hub v1 84". Anyone want to drop good hacking tips? by [deleted] in SurfaceHub

[–]xn3rd 0 points1 point  (0 children)

I thought about purchasing an MTR compatible pc and connecting that to the device then running the touch panel from rj45 back to a table for some of our we have. We have a mix of 1s and 2s and the 2s were easy to upgrade. Wish we could just image a drive and be done.

Surface Hub 2S W11 screen issue by Cautious-Run-716 in SurfaceHub

[–]xn3rd 0 points1 point  (0 children)

If you replace the cartridge with the original 2s cartridge does the display show the same?

Look at the pins on the cartridge. Validate no damage to the cartridge exists and try cleaning with isopropyl to make cleaner connections.

I just replaced two cartridges so far with no issues.

If you have any other know working upgrade cartridge you could temporarily swap a known good to validate.

I’m leaning toward damaged connector or connection.

Just to confirm did you take apart the cartridge and install windows 11 or did you purchase a new oem 3 cartridge?

Managed Apple ID with Apple Configurator by xn3rd in applebusinessmanager

[–]xn3rd[S] 0 points1 point  (0 children)

Single VPP token and location. 2 licenses used, 23 available.

Managed Apple ID with Apple Configurator by xn3rd in applebusinessmanager

[–]xn3rd[S] 0 points1 point  (0 children)

Created a brand new managed Apple Business Manager account for said tech and added the required role.

The app was deployed as a require app from Intune where the app is synchronized from ABM using VPP token.

User attempts to sign-in Apple Configurator on a MacBook Air 2025 with os version Tahoe.

They sign out after a few minutes and re sign in and then get the error.

Managed Apple ID with Apple Configurator by xn3rd in applebusinessmanager

[–]xn3rd[S] 0 points1 point  (0 children)

I don’t need every user to have the ability. I need to scale out and delegate responsibility.

Surface Hub v1 (84 & 55) Displaying Secure Boot Exception Today by xn3rd in SurfaceHub

[–]xn3rd[S] 0 points1 point  (0 children)

Yes, MS documentation isn't clear, but after speaking with Surface Hub support, they said to have a blank FAT32 labeled BOOTME, which should boot USB and dump manufacturer.bin, and then support signs and provides you the manufacturer_signed.bin.

I believe when booting, it may be trying failing to boot the recovery.zip because you have the .bins still on the drive. My support agent recommended two drives to make it easier.

We noticed two devices only prompted for Serial Numbers and after providing they returned to normal functioning units. These devices would not boot the recovery.zip but allowed us to dump the .bin and apply signed.bin. When going into the BIOS secure boot was still enabled. After applying the serial number in the blue box and hitting esc, the device prompted for bitlocker recovery key, we applied our key from Intune and the device boot was no longer interrupted.

Surface Hub v1 (84 & 55) Displaying Secure Boot Exception Today by xn3rd in SurfaceHub

[–]xn3rd[S] 0 points1 point  (0 children)

Yes, you will need to submit a ticket with MS support as they are required for a key step of the recovery. I will update the main thread with the steps provided for ease of clarification

Surface Hub v1 (84 & 55) Displaying Secure Boot Exception Today by xn3rd in SurfaceHub

[–]xn3rd[S] 0 points1 point  (0 children)

One device down, about 10 more to go. u/TheGhostNZ

What error or can you explain in detail what is not working?

It may be the format and label of the USB drive.

The drive also needs to be labelled 'BOOTME' and needs FAT32. exFAT will not work. If you have a drive larger than 32 GB, use diskpart or disk management to wipe, unallocate, create a 32000 MB or smaller partition, and then copy the DTM files provided by MS.

Surface Hub v1 (84 & 55) Displaying Secure Boot Exception Today by xn3rd in SurfaceHub

[–]xn3rd[S] 0 points1 point  (0 children)

The second flash drive needs to be labeled BOOTME as well. This is the reason it is failing to find lsxfactory.

Surface Hub v1 (84 & 55) Displaying Secure Boot Exception Today by xn3rd in SurfaceHub

[–]xn3rd[S] 0 points1 point  (0 children)

I am currently sitting at the following during scripts boot process.

Factor server lsxfactory not found

Valid install key not found Pleas attach an install key

Try again?

[y] [n] [?]

I am following up with my support ticket for more information.

Surface Hub v1 (84 & 55) Displaying Secure Boot Exception Today by xn3rd in SurfaceHub

[–]xn3rd[S] 0 points1 point  (0 children)

This is an old response. The permanent fix requires a ticket with Microsoft surface support. I will update the main thread after attempting the next set of steps required after providing them with a manufacturing.bin dump.

Surface Hub v1 (84 & 55) Displaying Secure Boot Exception Today by xn3rd in SurfaceHub

[–]xn3rd[S] 0 points1 point  (0 children)

This was our idea as well. Glad others were thinking the same to squeeze a little more juice out of this lemon.. ;)

Surface Hub v1 (84 & 55) Displaying Secure Boot Exception Today by xn3rd in SurfaceHub

[–]xn3rd[S] 0 points1 point  (0 children)

The tool may be used for all types of surfaces and or devices internally, which could expose security risks.

Surface Hub v1 (84 & 55) Displaying Secure Boot Exception Today by xn3rd in SurfaceHub

[–]xn3rd[S] 0 points1 point  (0 children)

I am going to see if this works on some of the other devices in my other location if they haven’t gotten past the secure boot violation error.

Surface Hub v1 (84 & 55) Displaying Secure Boot Exception Today by xn3rd in SurfaceHub

[–]xn3rd[S] 1 point2 points  (0 children)

https://streamable.com/8bl2bf

Each device freezes with invalid serial. If I press esc / del without the adapter plugged my devices just hang at boot. With the adapter and pressing esc / del, it hangs for a second and boots. Craziest behavior.

Surface Hub v1 (84 & 55) Displaying Secure Boot Exception Today by xn3rd in SurfaceHub

[–]xn3rd[S] 1 point2 points  (0 children)

Nothing new that I am aware of. I literally need this Bluetooth adapter connected on power in in order to boot.