Repository navigation
fix(harness): the stored-password task is registered for the account's Windows name - #11
Merged
Merged
Conversation
fadwen
force-pushed
the
fix/harness-password-task-account
branch
from
October 6, 2026 06:03
94cf71e to
111634a
Compare
fadwen
commented
Oct 6, 2026
fadwen
left a comment
Owner
Author
There was a problem hiding this comment.
Notes on the lines whose reason the diff does not show.
| $code = '0x{0:X8}' -f $launchFailure | ||
| $never = if ($code -eq '0x00041303') { 'the scheduler never launched it: ' } else { '' } | ||
| $hint = if ($code -eq '0x80070569' -or ($code -eq '0x00041303' -and $logon -eq 'Password')) { | ||
| $hint = if ($resolved -and $resolved.Name -like 'AzureAD\*' -and $logon -eq 'Password') { |
Owner
Author
There was a problem hiding this comment.
Placed before the generic clause, and keyed on the account rather than on the failure code, so an Entra account never receives the hint about the "Log on as a batch job" right: on the lab device granting the right changed nothing, and the hint would send someone the wrong way.
| } | ||
| Mock Get-IslLogonSession -ModuleName IntuneScriptLab { @() } | ||
| Mock Start-ScheduledTask -ModuleName IntuneScriptLab { } | ||
| Mock Get-ScheduledTaskInfo -ModuleName IntuneScriptLab { [pscustomobject]@{ LastTaskResult = 267011 } } |
Owner
Author
There was a problem hiding this comment.
267011 is 0x00041303, "the task has not run yet", as Get-ScheduledTaskInfo reports it: in decimal.
fadwen
added this pull request to stack #15
October 6, 2026 06:46
…s Windows name
The scheduler refuses an Entra account's sign-in name at registration ('No mapping between account names and security IDs'); the task is registered for the name Windows gives the account, as the interactive task is. On the lab device such a task never starts for an Entra account, with or without the 'Log on as a batch job' right, so the refusal says that for an Entra account instead of pointing at the right.
fadwen
force-pushed
the
fix/harness-password-task-account
branch
from
October 6, 2026 06:52
111634a to
bbdff1e
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The stored-password task, the path
-Credentialtakes when the account holds no session, was registered with the credential's user name as given. For a Microsoft Entra account's sign-in name the scheduler refuses that with "No mapping between account names and security IDs was done". The task is now registered for the name Windows gives the account, as the interactive task has been since #6.Measured on the lab device while there: a stored-password task for an Entra account never starts on it, with or without the "Log on as a batch job" right, so the launcher's refusal for such an account now says that instead of pointing at the right.
Stacked on #10: this pull request's base is that branch, so its diff is its own change only. Merge #10 first; GitHub then retargets this one to
mainand its checks run.What was measured
VM 125, the Entra test user signed out,
Register-ScheduledTask -User <name> -Password <the account's password>:user@domainAzureAD\user@domain0x00041303("has not run yet"),LastRunTimeunsetAzureAD\IslVerylongdisplaynaWith the account granted
SeBatchLogonRightfor the length of the test throughsecedit(taken away again afterwards), both registered names gave the same result. A local standard user without the right behaves the same way (Findings, "The harness as another account", 2026-09-29).Changes
Invoke-IslProcess. The stored-password task's-Useris the resolved Windows name whenResolve-IslAccountresolves the credential's name, the name as given otherwise. For a resolvedAzureAD\account the refusal reads "a stored-password task did not start for a Microsoft Entra account on the lab device, with or without the "Log on as a batch job" right; sign the account in and run while it holds a session"; the hint about the right stays for every other account.-Credentialdescription of the five harness commands and the README's account section say an Entra account has to hold a session. MAML rebuilt.Verification
-Credentialwith the sign-in name no longer fails at registration and reports the Entra refusal after 11 seconds; the Windows name reports the same after 9 seconds. No task and no run folder left behind. Before this change the sign-in name failed with "No mapping" at once (Harness: -Credential finds a Microsoft Entra account's session #6).Notes