Sascha Stumpler 💻 (bsky: @sastu-insights.com)
@SasStu
Followers
1K
Following
14K
Media
6K
Statuses
15K
IT Professional working with #ConfigMgr #CM #MSIntune #M365 #Windows #OSD #PowerShell #Azure #EPM #LeastPrivilege #BeyondTrust
Frankfurt
Joined January 2012
Troubleshooting and resolving Certificate Connector for #Microsoft Intune agent certificate renewal failure. #msintune #mdm #pki #mobility #security
directaccess.richardhicks.com
The Certificate Connector for Microsoft Intune is a vital component that allows administrators to issue and manage enterprise PKI certificates to endpoints managed by Microsoft Intune. The connecto…
0
2
3
@MHimken Hi Martin, 👋 Circling back to let you know our team has started rolling out a hotfix for this issue. Really appreciate you bringing this to our attention. If you notice anything else or have questions, feel free to reach out - we’re here to help! ^MM
2
1
6
Tip - if you're on Windows 11 and would like to be notified when an app sets itself to run at startup (via Settings > Apps > Startup), that's something you can enable:
20
27
252
FFS, can we have just a few days without a major issue/vulnerability… This affects every single WSUS instance, on every supported Windows Server version (and some unsupported ones)… 2012 -> 2025 Better get patching folks…
PSA: If you're running WSUS you will want to look at MC1178653 in your Message Center. The only workaround to CVE-2025-59287 is denying access to the service. If you haven't patched your Server 2025 yet (and as that update apparently was pulled) this is the replacement fix.
3
10
49
Microsoft Updated the Default Compliance Policy Documentation As we discovered and explained in the blog below, devices stayed compliant even when the enrolled user was gone. The updated documentation now confirms it The “Enrolled User Exists” check no longer verifies the
0
17
87
If you`re using @PatchMyPC PSADT, make sure to import the ADMX to @MSIntune and configure LogPath to get ALL installation logs to the proper location. Apples to new and existing packages. https://t.co/UwtaOlkPUB
0
14
74
Read the blog below how to fix it and the rudy details ..... manually... :(
patchmypc.com
A faulty cleanup script in HP OneAgent 1.2.50.9581 deleted the MS-Organization-Access certificate, disconnecting devices from Entra ID.
2
8
23
Wow... 🤯 This is even bigger than Entra/Intune btw :( Certificates issued based on serial number, GUID, lots of stuff could be affected HP's script literally just searches the LocalMachine\My cert store where Subject or FriendlyName contains "1E" and deletes the cert.....
⚠️ Heads up!!! Big warning for HP AI Devices! ⚠️ Some of HP’s latest Next Gen AI PCs, including the EliteBook X Flip G1i, are getting the updated OneAgent 1.2.50.9581 build. That version seems to run a cleanup script removing any certificate containing “1E” in its subject ....
5
56
344
⚠️ Heads up!!! Big warning for HP AI Devices! ⚠️ Some of HP’s latest Next Gen AI PCs, including the EliteBook X Flip G1i, are getting the updated OneAgent 1.2.50.9581 build. That version seems to run a cleanup script removing any certificate containing “1E” in its subject ....
26
75
302
Secure Configuration and Hardening of Active Directory Certificate Services https://t.co/BL2OwoPs6C
0
0
7
@SasStu Hi Sascha, 👋 Thanks for checking in! This setting isn’t available in the Settings Catalog just yet but good news, it’s already on our roadmap. While we don’t have an ETA to share right now, you can stay updated by keeping an eye on our What’s New page https://t.co/E2deVTVJ42 for
learn.microsoft.com
Find out what's new in Microsoft Intune.
0
2
2
Microsoft Intune Settings Catalog Updated to Support New Windows 11, version 25H2 Settings https://t.co/aElVBqDJKZ
0
5
14
Do you think Intune policies ONLY sync every eight hours? Well...They don’t. When you change a policy, Intune instantly signals the Windows Notification Service (WNS) to tell the device to check in. The catch? There’s a built-in throttle that quietly limits how often those
3
22
170
Installing a Standalone Root Certificate Authority & Web Enrollment on Windows Server 2025 https://t.co/Na0Uau77Qr
0
0
0