Jump to content


All Activity

This stream auto-updates

  1. Today
  2. did the exported XLS reveal anything interesting ? when did you deploy this to those devices ? and are you sure users are actively logged on to the devices to receive policy updates
  3. Yes, I've enrolled every user in with their work emails in Settings>Accounts>Access work or school. When I look at my own VM, it's still saying connected to the domain Entra ID with my work email. It's syncing too.
  4. ok interesting, and are users actually logged on to those VM's ? could the VM's have been reverted ?
  5. I appreciate your response. It's been deployed to users. Also, not sure if this has anything to do with the issue, but it seems like only the Parallels Windows VM are stuck in pending status. I'll try to export the data and see if I can find out more.
  6. how are you deploying this SCEP certificate ? is it to users or devices ? if you want to get more details you could try clicking on Export, and open the exported data in XL, sometimes that reveals information that is missing in the report above
  7. Yesterday
  8. Hi all, I've been having this issue with SCEP cert not recognizing the users and going by system account, and that will cause the device show as "Not managed" in Okta. Could anyone point me to the right direction on how to resolve this problem? I've tried working with Intune Support but not help there. Any help would be appreciated since we've been stuck on this for a couple of months now. Thanks, Alex
  9. Earlier
  10. the only way you'll be able to 'shim' the computer name into thinking it's the serial number, is if you know exactly what method (or methods) the medical software uses to determine the computer name, do you know how they are doing this ? modern applications often don't just call GetComputerName(). They may query: WMI (Win32_ComputerSystem) Environment variables (COMPUTERNAME) Registry values Active Directory attributes Their own licensing service If that's the case, a simple shim won't help. You could try this easier alternative depending on the architecture: Run the software in a VM whose hostname remains the serial number. Ask the vendor for a revised license tied to a hardware ID instead of hostname. Use a license server if the product supports one.
  11. I work for the medical company, as stated earlier... I can't believe a simple DLL hook or shim can't be explained here... that's all I'm asking, like many of the other forums on here... I'll just look elsewhere. Thanks...
  12. Introduction In previous blog posts I took a look at Windows 365 Reserve, explained what it was and shared my thoughts about how to implement it and configuring it for use as a disaster recovery method in your organization. In this post, I wanted to address some additional items that did not show themselves clearly until after provisioning and using Windows 365 Reserve Cloud PC’s for some days, as this will help you plan accordingly. You can review the other posts in this mini-series below. First looks at Windows 365 Reserve Following up on Windows 365 Reserve Final thoughts on Windows 365 Reserve <- you are here Imagine the scenario, your sales workers are somehow hit with malware or a cyber attack, or some other disaster leaving their physical laptops rendered unusable. Luckily, you had some Windows 365 Reserve licenses purchased in advance and assigned them to those very same workers before the incident occurred. So far, so good. Once the incident occurred, you informed those sales workers to connect to their Windows 365 Reserve Cloud PC’s via the Windows app from any device that supported it. This allowed them to continue working until the damage from the Cyberattack was resolved and they could utilize their physical laptops again. Those sales workers logged back on to their physical laptops and completely forgot about their Windows 365 Reserve Cloud PC’s. What happens to those reserve Cloud PC’s and the 10 day window of opportunity that they are entitled to ? That’s what this blog post will focus on. 3 days remaining If you as the Intune admin fail to do anything about the Windows 365 Reserve Cloud PC’s after they did their job, then the clock will keep ticking and even if they are not in use, the 10 days left will expire, rendering them unusable. This becomes apparent in the Intune console, by locating the Windows 365 Reserve provisioning policy, and selecting the devices tab. Look at the Days left column, in the example below, it states only 3 out of 10. In addition, the end user will be notified in the Windows app, via the Windows 365 Reserve Cloud PC title itself, and via a notification (shown below) in the Windows app. This of course assumes that they are still using the Windows app, and assumes that the Windows 365 Reserve Cloud PC is still in use. Here’s the message in the Windows app, shown below. Keep in mind that they may no longer be using the Windows app as the disaster that forced them to use their Windows 365 Reserve Cloud PC may have been solved after a few days, allowing them to re-use their physical laptop, so you cannot guarantee that the end user will even see this warning in the Windows app, and thus, if the admin does not deprovision the Windows 365 Reserve Cloud PC, it will expire. Stopping the clock As an Intune admin, to stop the clock from using up more of these 10 days, you would need to select each of the Windows 365 Reserve Cloud PC’s that are provisioned and in use, and deprovision them. Below is an example of the action on one of the Reserve Cloud PC’s. After doing this action, the 10 day clock will stop ticking, meaning that you’ll still have usable days on that Windows 365 Reserve license for future needs in that time period (10 days per calendar year). Licenses allow up to 10 days of Cloud PC access per year for one user. Note: In case it’s not clear, if you do NOT deprovision your provisioned Windows 365 Reserve Cloud PC’s then they will keep running and use up all of those assigned 10 days. The only warning you’ll get is if you happen to be in the the Intune console looking at the Windows 365 Reserve provisioned Cloud PC’s, you’ll notice the 3 out of 10 days left warning. After deprovisioning the Windows 365 Reserve Cloud PC, the provisioning status will change to Not provisioned and the days left will stay at what days you have left. In previous posts on this subject I pointed out that you as the admin can allow the end user to provision, or even deprovision their Windows 365 Reserve Cloud PC by configuring settings in Intune to allow the end user to do these actions themselves (self-service) via the Windows app. But you should be aware that if an end user wants to start deprovisioning their Windows 365 Reserve Cloud PC, the action to do so isn’t as straight forward as provisioning it (set up your cloud pc). To illustrate this, look at the self service actions below for an end user to begin provisioning their own Windows 365 Reserve Cloud PC via the Windows app. End user provisioning action The end user provisioning action for a Windows 365 Reserve Cloud PC is referred to as Set up your Cloud PC and shown below. followed by once done, the Windows 365 Reserve Cloud PC will be available for use after the provisioning process is complete. End user deprovisioning action If you want your end users to also deprovision their Windows 365 Reserve Cloud PC after the disaster is over, then you’ll have to inform them to return it via the actions below. First, the user needs to locate their Windows 365 Reserve cloud pc in the Windows app, and then click on the … (elipsees) settings icon. From there, click on Return as shown below. This will prompt for confirmation, they need to agree to Delete all my saved data and return this Cloud PC. Once confirmed, the returning process will begin (or deprovisioning). This is a great way of empowering your end users to do the provisioning and deprovisioning actions themselves, but assumes that the users would actually be technically competent enough to do both. And to be honest, after whatever disaster prompted you to issue them these Reserve licenses in the first place is over, do you really think they’ll remember to deprovision (return) their Windows 365 Reserve Cloud PC ? Summary In the final part I took a closer look at what happens after the disaster is over and your users can begin using their physical devices again. You as the admin must remember to deprovision the provisioned Windows 365 Reserve Cloud PC’s when no longer in use otherwise you’ll lose out on remaining days available for the next disaster. It would be great if there was a reminder (Alert) that you could configure to remind the admin and/or Reserve users to deprovision (return) their Cloud PC’s after usage to save those unused days. There is an alert related to deprovisioning Windows 365 Reserve Cloud PC’s but it only covers the eventuality of deprovisioning failing on the Reserve Cloud PC, not actually reminding you to deprovision them once not in use. Your users can be educated to do this themselves but I would doubt that they’d remember to do so, once they regain access to their physical computer. Therefore it’s up to you the Intune admin to not only be proactive in selecting, provisioning and assigning Windows 365 reserve licenses in advance of a disaster scenario, but also to be reactive after the event and ‘clean up’ or deprovision the used Windows 365 Reserve Cloud PC’s. Failure to do so will mean that you’ll lose out on the remaining days and won’t have any reserve left for the next disaster scenario. See you in the next one!
  13. Introduction In a previous blog post, First looks at Windows 365 Reserve, I explained what this new offering was, how to enable it and the expected outcome. However, I also pointed out the odd choice of having to wait 7 days after adding users to a AAD group targeted with a provisioning policy, prior to being able to provision or use the Windows 365 Reserve Cloud PC. Note: The 7 days delay is the initial delay that you the admin must wait BEFORE you can provision a Windows 365 Reserve Cloud PC for any of the assigned users. In other words, it’s forcing you the Admin, to be proactive, and I discussed that at length in the previous blog post on this subject. If you look at the Can be provisioned after column in the Cloud PC users tab of the provisioning policy, it will list Ready for Provisioning once that initial 7 days delay has passed. You can review the other posts in this mini-series below. First looks at Windows 365 Reserve Following up on Windows 365 Reserve <- you are here Final thoughts on Windows 365 Reserve In this post, I’ll take a look at what additional options are available after those initial 7 days delay have passed, and look at the Windows 365 Reserve Cloud PC itself. So let’s get started. First, let’s find the Windows 365 Reserve provisioning policy in Intune. It’s listed below with a Name of Windows 365 Reserve in the list of Provisioning policies that I’ve previously configured in my tenant. Interestingly, the Image for it is listed as Automatic, and the License type is Reserve. After clicking on that Windows 365 Reserve provisioning policy, we can see all the users that are assigned to that policy (they are in a group that the policy was assigned to) by clicking on the Cloud PC users tab. This is where the action happens with Windows 365 Reserve. But before we do, let’s also remind ourselves what the Windows 365 Reserve Cloud PC assigned to this user looks like in the Windows app. As you can see, it has a ‘Set up your Cloud PC’ clearly visible in the Reserve Cloud PC. This is because we enabled a setting in the previous blog post allowing the user to provision their Reserve Cloud PC themselves if desired (after the initial 7 days delay of course). Here’s that setting. So technically speaking, we could provision the Windows 365 Reserve Cloud PC as an admin via the Cloud PC users tab in the Windows 365 Reserve provisioning policy, or we could ask the end user to set it up via the Set up your Cloud PC option in the Windows app. Provisioning a Windows 365 Reserve Cloud PC as an admin For now, let’s see what happens when we select a user targeted by the previously created policy as an admin in Intune, via the Cloud PC users tab. Doing the above, after the 7 days License ‘wait or delay’ has passed, now allows you to select an available option for that user, and the option is Provision. Previously (before those 7 days wait pass) this option was greyed out (not available). Deprovision is not yet available as we have not yet provisioned a Windows 365 Reserve Cloud PC. Note: You can also select multiple users to provision them in bulk for those users at the same time. So let’s click on Provision. Once done, you get a popup telling you that users will be able to use their Cloud PC via the Windows app once it is fully provisioned. Clicking Provision again, starts that process and the provisioning status for that user, should change to Provisioning. Now in the Windows app, after clicking the Refresh icon (top right), we can see that the Windows 365 Reserve Cloud PC has changed colour, and has a spinning Windows circle to indicate that it is provisioning. After some time the Cloud PC is provisioned and the Provisioning status changes to Provisioned in Intune. Interestingly, the Days left column, shows 9 out of 10 for the newly provisioned Windows 365 Reserve Cloud PC, which means that the user only has 9 more days of usage of this disaster recovery Cloud PC. Additionally, in the Windows app, the spinning circle to indicate it’s provisioning, is no longer present, and the Windows 365 Reserve Cloud PC looks like any other that is made available to that user. If we go back to Intune, we can now see the Deprovision option is available for that selected user as the Cloud PC has been provisioned. Using the Windows 365 Reserve Cloud PC Now that the Windows 365 Reserve Cloud PC is provisioned for my user, I tried to launch it via the Windows app, but got an error. So I did that, I restarted the Windows app and it informed me twice (two popups which I didn’t get time to screenshot) that the Windows 365 Reserve Cloud PC was ready. And now, when clicking on that Cloud PC I’m prompted for credentials like any other Cloud PC. And after some time the desktop appeared. Success. So this means that your users targeted with this provisioning policy, and after the initial 7 day ‘wait’, will be able to self provision or and Intune Admin can provision a Windows 365 Reserve Cloud PC for them, allowing them to work for up to 10 days per year in a disaster recovery scenario. That is excellent. Summary I’m glad I returned to Windows 365 Reserve to see what additional options were available after the enforced initial 7 day delay after creating and assigning the initial provisioning policy. I also was pleasantly surprised with how easy it was to get going once the additional steps were done in the console. However, I find it odd that the Windows app itself couldn’t launch the Windows 365 Reserve Cloud PC after it was successfully provisioned, but instead gave the user an error telling them to restart the app. To me, that needs to be fixed and I’ll pass that info directly back to Microsoft. I hope this post helps you to understand more about Windows 365 Reserve and helps you to use it in your organization, any questions, post them below.
  14. Any chance I could get a copy of these, @anyweb?
  15. honestly, i think you'll need to go to the team that are in control of the ad naming scheme and get an exception for these devices OR contact the medical software manufacturer and ask them to modify their software to work with the companies AD naming scheme anything else will ultimately fail
  16. Well, I work for the software vendor... so my software engineers aren't "reachable" to ask such questions, and probably wouldn't tell anyway (I.P., secret recipes, etc...) I'm not worried about other software, being this is a medical device running windows, and other software isn't supposed to be on there. I did ask if this was an API call, or exactly how the software determines the PC name to validate it, so hoping that will help narrow an answer, but any other input on how to get started is appreciated. The customer wants to add our product to their domain for medical records, but since our name can't deviate, it's causing a major problem. I'm hoping this "shim" is a possible path to a solution... Thanks for any guidance or starting points
  17. you need to contact that software vendor and explain your customers computer naming standards/requirements and ask for assistance, have you tried that ? any hack you do to convince that software that the hostname or registry key pointing to the computer name may cause other issues with lots more software, so i'd start with the software vendor first
  18. So, I have a piece of medical software that needs to be a specific Windows PC name (a serial number) in order to make purchased options within that software be activated. If you change the PC name to anything other than the serial number, the options cease to work. I'm not sure if this is a registry or API call, but it doesn't work if the Windows PC name changes to anything else but the serial number of the product. The issue is, my customer, a large hospital system, per their corporate IT naming convention, MUST change the name of the unit to match their AD setup. I'm trying to find a way to shim the PC name to the .exe or program file to "believe" the PC computer name is still the serial number, but the customer can change the REAL PC name to conform to their policies. I'm no expert in this at ALL, so I'd really need someone to 2nd grade explain this. I've tried the latest ADK download with the compatibility feature enabled, and some searches say to "fix" the software using GetComputerName or SetEnvironmentVars, but none of those seem to exist or work... If someone has a better program or method, I'm attempting to get in front of this medical device to test with soon, and would love to try any/all suggestions. Again, I don't write code, scripts, or dlls, so I'd need some hand holding on this if it can be done. Thank you!
  19. Could I please get the Prerequisites for 2012 R2 SP1?
  20. Version 2603 with KB38232642 and KB37942646. Running in EHTTP. Servers also have web certificates bound on HTTPS issued by our domain certificate authority server.
  21. what version of sccm is it and are you running in HTTP mode ?
  22. I've reinstalled the MP on one server and the Critical error 0mb appears straight away. Firewalls are disabled on the servers. There no errors showing in the message log for the MP, no errors on the MP log files, mpmsi.log and mpsetup.log On the site server, there's no errors in sitecomp.log or statmgr.log,. sms_site_system_status_summarizer.log doesn't exist. hman.log shows Error: Could not create certificate binary Failed to sign User Service Certificate for <server> of site There's no errors in the mpcontrol.log. Http test request succeeded. There's no Https test and SSL is showing in the log not enabled.
  23. I asked copilot about this and it replied as below: Yes. Based on similar SCCM/MECM cases, the**"Management Point = Critical, Size = 0 MB / 0 KB free space"** symptom is usually not an actual disk space problem, but a failure in the Management Point health check or status reporting. [windows-noob.com], [forums.pra...ldesai.com] For the specific post you linked, the key clues are: The issue started immediately after an OS upgrade from Server 2019 to 2022. Distribution Points report storage correctly. Only Management Points show 0 MB. Reinstalling the MP role did not help. [windows-noob.com] Known causes seen in the field MP Control Manager communication failures A remote MP can install successfully but still show 0 Bytes / Critical if the MP health checks fail. One documented case was caused by blocked ports (135/445), resulting in MP health failures until connectivity was restored. [forums.pra...ldesai.com] Status Summarizer reporting issues The "0 KB free storage space" message is generated by the Site System Status Summarizer. Sometimes the summarizer data becomes stale or invalid after site/system changes and may need re-evaluation or resetting after the underlying issue is fixed. [learn.microsoft.com], [anoopcnair.com] Permissions changes after OS upgrade Server upgrades can alter local group memberships, WMI permissions, firewall rules, IIS configuration, or ConfigMgr service permissions, causing the site server to fail retrieving status information from remote MPs. This is a common post-upgrade symptom reported for MP health issues. [learn.microsoft.com], [learn.microsoft.com] Firewall / RPC / SMB access Since the site server gathers status information remotely, blocked RPC or file-sharing communications can cause the console to show 0 MB even when the disks have plenty of space. [forums.pra...ldesai.com] Logs I would check first On the site server: mpcontrol.log sitecomp.log hman.log statmgr.log sms_site_system_status_summarizer.log On the affected MP servers: mpmsi.log mpsetup.log IIS logs Things I'd verify Can the site server access \\MPServer\admin$? Are RPC (135) and SMB (445) reachable? Does mpcontrol.log show successful HTTP/HTTPS tests? Is the SMS Executive service healthy? Are the MPs running the same supported ConfigMgr version after the Server 2022 upgrade? Does reinstalling the MP role recreate the issue immediately or only after status summarization runs? My suspicion, given the upgrade scenario and the fact that DPs report storage correctly, is that this is more likely a Management Point status collection/communication issue than actual storage detection, with mpcontrol.log and sms_site_system_status_summarizer.log being the most important logs to review. [windows-noob.com], [forums.pra...ldesai.com], [learn.microsoft.com] If you can provide excerpts from mpcontrol.log and sms_site_system_status_summarizer.log, I can help pinpoint the exact failure.
  24. I've upgraded our configuration manager server OS from 2019 to 2022 and after running the CM reset and reinstalling wsus the main server and distribution points are all working, however all the management points apart from the CM server are showing critical and 0mb under Site Status. The message log is showing Site System Status Summarizer detected that the storage object on site system has 0 KB of free storage space, which is less than or equal to the Critical Free Space Threshold of 5242880 KB. The error only occurred after the OS upgrade, there's space on the servers which also act as distributions points which show the correct space in the site status. Removing and reinstalling the MP role hasn't made a difference. Currently the MP role has been removed from the servers so the clients can communicate.
  25. Hi, I am using SCCM on Prem and not Cloud I have created an ADR for Windows 11 monthly update. Some Clients machine does not get any Windows updates. I have checked all log files, UpdatesDeployment.log, ScanAgent.log,UpdatesStore.log,UpdatesDeploymentAgent.log, It display the updates is "not Applicable" even the build version on the client is from may and I have deployed the KB5101650 from JULY. What is if I check the following options on the "download setting" does it mean, the client will download the update from internet? Or does it means the SCCM Client download from internet immediately and ignore the ADR from SCCM and Software Center? does display the Windows update on the Software Center or not any more? because I have checked that options? Thank for help
  26. I'm still working on it, but what I can say so far is that after I deleted the policies under System32\GroupPolicy and requested the policies via the Configuration Manager, the software was recognized, downloaded and installed.
  27. Is there any update on this? Have you solved the problem? We're currently having the same issue and would really appreciate it if you could share your experience with us.
  1. Load more activity
×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.