Jan

83 posts

Jan banner
Jan

Jan

@dobrigod

Enterprise Mobility | #MSIntune #EMS #MEM #Intune #Autopilot #AzureAD #ConfigMgr #Windows10

Bern/Switzerland Katılım Kasım 2011
277 Takip Edilen53 Takipçiler
Sabitlenmiş Tweet
Jan
Jan@dobrigod·
@IntuneSuppTeam Have you heard any reports of required Win32 apps not installing during the Autopilot ESP? We are seeing this intermittently in various countries. #Autopilot #Intune
English
2
0
1
116
Jan
Jan@dobrigod·
@IntuneSuppTeam @Mister_MDM Microsoft has apparently 'fixed' the problem in the service. You may want to retry now if you did experience the issue.
English
1
0
1
193
Jan
Jan@dobrigod·
@IntuneSuppTeam something seems broken (intermittently) with Autopilot. The profiles are not reliably delivered at OOBE. A restart often times seems to help. Anything you can share on this please? @Mister_MDM, maybe you have some valuable insights? :-)
English
5
1
2
233
Jan
Jan@dobrigod·
@Mister_MDM @RoyTrizzle Exactly. But having to reprovision devices because of 1 missing/corrupted cert would be a pain.
English
2
0
1
212
Rudy Ooms
Rudy Ooms@Mister_MDM·
@dobrigod @RoyTrizzle Well if that cert is gone the entra join is gone… i know the intune mdm crrt has a built in recovery… but entra … not
English
2
0
0
222
Rudy Ooms
Rudy Ooms@Mister_MDM·
⚠️ Heads up!!! Big warning for HP AI Devices! ⚠️ Some of HP’s latest Next Gen AI PCs, including the EliteBook X Flip G1i, are getting the updated OneAgent 1.2.50.9581 build. That version seems to run a cleanup script removing any certificate containing “1E” in its subject .... which can delete the MS-Organization-Access cert. Once that happens, your device is no longer Entra joined or Intune Enrolled!. #Intune #MSIntune #Windows #Windows11 #Entra
Rudy Ooms tweet media
English
25
75
301
127.4K
Jan
Jan@dobrigod·
@Mister_MDM @RoyTrizzle Curious to see if you have any suggestions how to a) prevent Entra ID join certificate modifications by rogue processes b) if that cert gets deleted, can you gracefully recover from that without needing to reprovision the device.
English
1
0
0
228
Rudy Ooms
Rudy Ooms@Mister_MDM·
@RoyTrizzle Nope and the best thing if it only removed the intune cert… thst wouldnt be a problem :)… it will come back automaticallt (writing the blog post now)
English
1
0
0
287
Jan
Jan@dobrigod·
@Mister_MDM @h1ghju1ce The BitLocker issue seems to have been resolved for us. No action required on our end, they fixed it (rolled back something?) in the service. Not sure how GA'ing 'Windows Backup for Organizations' would be related to this though.
Jan tweet media
English
1
0
1
104
Rudy Ooms
Rudy Ooms@Mister_MDM·
Important: Update on the Intune Service Side Issues UPDATE: A temporary workaround, creating a new group and moving users from the existing group to the new one... which "could" fix it :) UPDATE 2: Issue seems to be ack by Intune… with it, a message will be posted in the message center (soon … I hope :) )🤞🏽 UPDATE 3: Having as well Autopilot Issues and you are in those tenants... upgrade to the Windows August build before enrollment.... (and if you are running into #WindowsAutopilot issues... please reach out... I want to check something) Read more in the post below @IntuneSuppTeam #Intune #MSIntune #WindowsAutopilot
Rudy Ooms@Mister_MDM

Is your Intune tenant location in Europe, and to be precise, in Azure Scale Unit 0101/0202 or 0301.... You could be experiencing some issues.. 1. Available apps are not showing up in the company portal 2. Policy delivery could be delayed 3. Overall slowness. @IntuneSuppTeam .. The number of topics on reddit/discord/teams MCCP channels are obvious... Feel free to leave a comment if you are experiencing the same thing. Let's see if we can create some traction. #Intune #MSIntune #Azure #Windows #Windows11 #Microsoft

English
3
3
22
5K
Jan
Jan@dobrigod·
@IntuneSuppTeam, are you aware of any issues where MDM BitLocker policies are not honored in time, leading to devices encrypted at the wrong level? Anything in the Intune August release that may have introduced an issue (RACE condition) in MDM policy delivery? #MDM #Autopilot
English
1
0
1
841
Jan
Jan@dobrigod·
@RoyTrizzle @IntuneSuppTeam You can see this in the IME log file. Compare one from today to one from a few weeks ago and you should see the same.
English
1
0
0
38
Jan
Jan@dobrigod·
@IntuneSuppTeam Intune PowerShell scripts are no longer getting delivered in our tenant. I hear that other customers are reporting the same issue. Do you have any Information that you can share about this?
English
2
0
0
313
Jan
Jan@dobrigod·
@IntuneSuppTeam @RoyTrizzle It appears that the sudden increase in the size of the payload is due to the fact that the 'EncryptedPolicyBody' property is now populated with a long base64 value, pretty much doubling the size of the payload. Why are those type of changes not properly tested/communicated?
English
1
0
0
41
Jan
Jan@dobrigod·
@IntuneSuppTeam @RoyTrizzle Apparently there is a 2MB overall payload limit for #Intune #Powershell scripts. This is different from the 200KB per script. Would be good to know if that has always been there or if that was recently introduced. I don't recall seeing anything about that in the documentation.
English
4
0
1
120
Jan
Jan@dobrigod·
@IntuneSuppTeam Hi team, just to clarify. The issue is not that the scripts are not showing in the Intune console. The issue is that the script are not delivered to endpoints. Are we talking about the same issue?
English
1
0
0
78
Intune Support Team
Intune Support Team@IntuneSuppTeam·
@dobrigod Hi Jan, thanks for flagging! We are aware of the issue, and it is being looked into internally. In the interim, can you remove the status column, and let us know if this helps to load the scripts? Thanks! ^IH
English
1
0
0
70
Jan
Jan@dobrigod·
@SteffenAtCloud @IntuneSuppTeam Manually triggering the Tpm-HASCertRetr scheduled task seems to help in many cases. Are you still seeing the issue?
English
2
0
1
189
Steffen Schwerdtfeger
Steffen Schwerdtfeger@SteffenAtCloud·
@IntuneSuppTeam Seeing multiple #Intune tenants where #BitLocker compliance is not give for newly enrolled devices (no error shown). Multiple restarts and syncs do not help. Issue persists - even after multiple hours. Encryption report is looking good.
Steffen Schwerdtfeger tweet media
English
3
0
3
331
Jan
Jan@dobrigod·
@IntuneSuppTeam, I've noticed a lot of [AgentCommon] messages in the IME log file during Autopilot. It seems to prolong the duration of the ESP Account phase, adding a number of minutes to the overall process. Any idea if this was a recent addition to the IME?
Jan tweet media
English
1
0
2
148
Jan
Jan@dobrigod·
@IntuneSuppTeam, do you have any additional information that you can share about Intune Service Degradation Advisory IT867628: 'Some users can't check in devices managed through Microsoft Intune'?
English
1
0
0
52
Intune Support Team
Intune Support Team@IntuneSuppTeam·
@banterci Hi, Josh! We had a look and nothing currently flagged on our end around this behavior. We were also unable to repro this behavior on our end. If you're still encountering further issues with this, could you DM us with more info, so we can look further into this? Thanks! ^MS
English
1
0
0
402
Jan
Jan@dobrigod·
@IntuneSuppTeam we are seeing issues with Autopilot getting stuck on the ESP page during the Account phase. Have you heard anything to that extend?
English
2
0
2
175
Jan
Jan@dobrigod·
@mniehaus Looks like it's working for me now. I believe the issue was that I wasn't 'Internet connected' during the initial boot to OOBE. That's when the AUTOPILOT_MARKER seems to get created. Thanks for your help with this, much appreciated!
English
0
0
1
38
Michael Niehaus
Michael Niehaus@mniehaus·
@dobrigod I believe so, yes. I didn't verify the exact point (start of OOBE vs. running the script), but it seems logical that grabbing the hash would do it.
English
1
0
2
62