Skip to content

fix(harness): the stored-password task is registered for the account's Windows name - #11

Merged
fadwen merged 1 commit into
mainfrom
fix/harness-password-task-account
Oct 6, 2026
Merged

fadwen merged 1 commit into
mainfrom
fix/harness-password-task-account

Conversation

@fadwen

@fadwen fadwen commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

Summary

The stored-password task, the path -Credential takes when the account holds no session, was registered with the credential's user name as given. For a Microsoft Entra account's sign-in name the scheduler refuses that with "No mapping between account names and security IDs was done". The task is now registered for the name Windows gives the account, as the interactive task has been since #6.

Measured on the lab device while there: a stored-password task for an Entra account never starts on it, with or without the "Log on as a batch job" right, so the launcher's refusal for such an account now says that instead of pointing at the right.

Stacked on #10: this pull request's base is that branch, so its diff is its own change only. Merge #10 first; GitHub then retargets this one to main and its checks run.

What was measured

VM 125, the Entra test user signed out, Register-ScheduledTask -User <name> -Password <the account's password>:

Name Registration Run
user@domain Refused: "No mapping between account names and security IDs was done"
AzureAD\user@domain Registered Sat Ready, 0x00041303 ("has not run yet"), LastRunTime unset
AzureAD\IslVerylongdisplayna Registered Same

With the account granted SeBatchLogonRight for the length of the test through secedit (taken away again afterwards), both registered names gave the same result. A local standard user without the right behaves the same way (Findings, "The harness as another account", 2026-09-29).

Changes

  • Invoke-IslProcess. The stored-password task's -User is the resolved Windows name when Resolve-IslAccount resolves the credential's name, the name as given otherwise. For a resolved AzureAD\ account the refusal reads "a stored-password task did not start for a Microsoft Entra account on the lab device, with or without the "Log on as a batch job" right; sign the account in and run while it holds a session"; the hint about the right stays for every other account.
  • Help and README. The -Credential description of the five harness commands and the README's account section say an Entra account has to hold a session. MAML rebuilt.
  • Findings. The table above under "The harness as another account".
  • Tests. The task registered for the Windows name with the credential's password; the Entra refusal text, and the right's hint absent from it.

Verification

  • Unit and integration suites: 929 pass on PowerShell 7.6.6 (8 skipped: elevation, lab credential); 879 pass on Windows PowerShell 5.1 for the unit suites and two integration files (33 skipped). PSScriptAnalyzer (Error and Warning) is clean; no line over 115 characters; help Markdown validates.
  • Lab device, the module run as SYSTEM with the user signed out and its real password: -Credential with the sign-in name no longer fails at registration and reports the Entra refusal after 11 seconds; the Windows name reports the same after 9 seconds. No task and no run folder left behind. Before this change the sign-in name failed with "No mapping" at once (Harness: -Credential finds a Microsoft Entra account's session #6).

Notes

  • The password used for the measurement was placed on the lab device for the test and removed afterwards.
  • Whether an Entra account can run a stored-password task on any device is not established; only that it did not on this one, joined and enrolled, with the right and without.

@fadwen fadwen left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Notes on the lines whose reason the diff does not show.

$code = '0x{0:X8}' -f $launchFailure
$never = if ($code -eq '0x00041303') { 'the scheduler never launched it: ' } else { '' }
$hint = if ($code -eq '0x80070569' -or ($code -eq '0x00041303' -and $logon -eq 'Password')) {
$hint = if ($resolved -and $resolved.Name -like 'AzureAD\*' -and $logon -eq 'Password') {

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Placed before the generic clause, and keyed on the account rather than on the failure code, so an Entra account never receives the hint about the "Log on as a batch job" right: on the lab device granting the right changed nothing, and the hint would send someone the wrong way.

}
Mock Get-IslLogonSession -ModuleName IntuneScriptLab { @() }
Mock Start-ScheduledTask -ModuleName IntuneScriptLab { }
Mock Get-ScheduledTaskInfo -ModuleName IntuneScriptLab { [pscustomobject]@{ LastTaskResult = 267011 } }

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

267011 is 0x00041303, "the task has not run yet", as Get-ScheduledTaskInfo reports it: in decimal.

@fadwen
fadwen added this pull request to stack #15 October 6, 2026 06:46
Base automatically changed from fix/harness-session-by-sid to main October 6, 2026 06:52
…s Windows name

The scheduler refuses an Entra account's sign-in name at registration ('No mapping between account names and security IDs'); the task is registered for the name Windows gives the account, as the interactive task is. On the lab device such a task never starts for an Entra account, with or without the 'Log on as a batch job' right, so the refusal says that for an Entra account instead of pointing at the right.
@fadwen
fadwen force-pushed the fix/harness-password-task-account branch from 111634a to bbdff1e Compare October 6, 2026 06:52
@fadwen
fadwen merged commit f20cfe5 into main Oct 6, 2026
4 checks passed
@fadwen
fadwen deleted the fix/harness-password-task-account branch October 6, 2026 06:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant