Jump to content

thesandwichman

Members
  • Posts

    2
  • Joined

  • Last visited

Reputation

1 Neutral

About thesandwichman

Personal Information

  • Biography
    Troublemaker. Returning to Edugeek after being black balled..
  • Occupation
    IT Manager
  • Interests
    Boats.. boats and more boats.
  • Location
    Northampton
  • LinkedIn

Recent Profile Visitors

70 profile views
  1. I suspect the ease (or otherwise) of this transition is heavily dependent on the hardware manufacturer and firmware quality rather than the Windows side of things. We're an almost exclusively Lenovo estate and our experience has been much more mixed than some of the "turn on the Intune policy and forget about it" reports above. The Windows updates themselves have generally behaved as expected, but we've found BIOS/UEFI support to be quite patchy across different Lenovo generations and models. On some devices the Secure Boot certificate updates went through automatically with no intervention. On others, even with the latest available BIOS installed, the certificates either refused to update or remained stuck in an incomplete state. In quite a few cases the limiting factor wasn't Windows, Intune or policy configuration - it was simply that the firmware wasn't correctly handling the Secure Boot variable updates. Looking at the new Intune Secure Boot Status report and Microsoft's detection scripts, most of our remaining non-compliant devices correlate strongly with specific Lenovo models rather than any particular Windows build or management method. Reading through the replies here, it sounds like HP and some other vendors may have had a smoother path, whereas older Lenovo hardware seems to be a bit more hit-and-miss. I'd be interested to know whether others are seeing the same pattern, or whether we've just been unlucky with our device mix. The good news is that Microsoft now appears to be continuing to deploy the new certificates through Windows Update, so the situation feels much less urgent than it did a few months ago. We've gone from worrying about a hard deadline to mostly monitoring the stragglers and identifying the handful of devices that are genuinely limited by firmware support.
  2. First of all just to say thanks very much to the admins for allowing back to Edugeek. For many years I was blackballed (presumably for upsetting someone) so it's lovely to be back here again. The transition to the Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 certificates requires Windows to update UEFI Secure Boot variables stored in the motherboard's NVRAM. Some older or buggy firmware implementations do not correctly support these runtime updates, causing the certificate update to fail until the BIOS/UEFI firmware is updated. Despite diligently searching for and installing the latest UEFI BIOS firmware (mostly Lenovo) this has been a considerable nuisance. I have been using this detect script on InTune to find the problems. If anyone can suggest improvements would be interested to know $RegPath = "HKLM:\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing" $ValueName = "UEFICA2023Status" # Helper function function Write-Result { param( [string]$Assessment, [string]$Reason ) Write-Output "Assessment : $Assessment" Write-Output "Reason : $Reason" try { $bios = Get-CimInstance Win32_BIOS Write-Output "BIOS : $($bios.SMBIOSBIOSVersion)" } catch {} exit $(if ($Assessment -eq "Compliant") {0} else {1}) } # Secure Boot enabled? try { if (-not (Confirm-SecureBootUEFI)) { Write-Result "Not Compliant" "Secure Boot is disabled." } Write-Output "Secure Boot : Enabled" } catch { Write-Result "Not Compliant" "Unable to determine Secure Boot status." } # Read servicing status try { $status = (Get-ItemProperty -Path $RegPath -Name $ValueName -ErrorAction Stop).$ValueName } catch { Write-Result "Not Compliant" "UEFICA2023Status registry value not found." } Write-Output "UEFICA2023Status : $status" switch ($status) { "Updated" { Write-Result "Compliant" "UEFI CA 2023 servicing completed." } "InProgress" { Write-Result "Not Compliant" "UEFI CA 2023 servicing is still in progress." } "NotStarted" { Write-Result "Not Compliant" "UEFI CA 2023 servicing has not started." } default { Write-Result "Not Compliant" "Unexpected servicing state: $status" } }
×
×
  • Create New...