Browsed by
Category: Azure Ad

Operation Fortune: Ruse de MFA

Operation Fortune: Ruse de MFA

This blog will be about some MFA, some Conditional Access, and some activity in the Sign-in reports that could make a fool out of you. This time it took some time before I understood the “why”. So I guess I am the fool in this blog. I will divide this blog into multiple parts Migrating from User Based MFA to Conditional Access The Conditional Access rule Long Live Compliant devices? Sign-In reports What made me look like a fool 1.Migrating…

Read More Read More

Married with System Boards’s: 976-TPM

Married with System Boards’s: 976-TPM

This blog will be about why “Things” could break with your totally TPM Protected Autopilot Azure Ad Joined device when your System board is replaced! It’s a topic that needs some more explanation. Joymalya Basu Roy put me up to it with the draft he created. So this blog is the first cooperation between me and Joymaly in writing a blog! Hopefully, there are more to come! It’s all about the Device Key (DKPriv/DKPub), the Storage / Transport key (TKPub/TKPriv),…

Read More Read More

The KB5007253 Update: The Devil Made Me Fix The TPM

The KB5007253 Update: The Devil Made Me Fix The TPM

This blog will show you how you could make sure you can still pre-provision your devices with Autopilot even when those fancy new devices have Intel Tiger lake chipsets (11th gen). PLEASE NOTE: This fix only works for the Intel Tiger lake Chipset, not for AMD!. When there is a fix for AMD I certainly will post a new blog! If you didn’t read my TPM attestation blogs, please read them first as they could give you a good understanding…

Read More Read More

The Pursuit of HAPPY…. Uhhh TPM AMD Happyness (Part 3)

The Pursuit of HAPPY…. Uhhh TPM AMD Happyness (Part 3)

This blog will hopefully show you some inside information on what issues you could run into when using AMD TPM attestation and Windows Autopilot for pre-provisioned deployments! I will divide this blog into multiple parts The famous AMD AIK does not exist error Taking a better look at the AMD EKCert Taking a better look at the Key-Id’s Taking a better look at the Certificate Flow Let me correct me something! Sources used Conclusion 1.The famous AIK does not exist…

Read More Read More