Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,12 @@ release notes.
its SID when Windows resolves the credential's name, by the owner's name otherwise. Verified on
this Home machine and on the joined lab device with the Entra user signed in.

- **The stored-password task was registered with the credential's name as given**, which the
scheduler refuses for an Entra account's sign-in name ("No mapping between account names and
security IDs"). It is registered for the name Windows gives the account. On the lab device such
a task then never starts for an Entra account, with or without the "Log on as a batch job"
right, so the refusal names that instead of the right.

### Changed

- Validation kit: `Collect` moves its payload through the guest agent's file-read call in one
Expand Down
13 changes: 11 additions & 2 deletions Private/Invoke-IslProcess.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -161,7 +161,8 @@
$registerTaskSplat.Principal = New-ScheduledTaskPrincipal @principalSplat
}
else {
$registerTaskSplat.User = $userName
# The scheduler takes an Entra account by its Windows name only, here too
$registerTaskSplat.User = if ($resolved) { $resolved.Name } else { $userName }
$registerTaskSplat.Password = $Credential.GetNetworkCredential().Password
$registerTaskSplat.RunLevel = 'Limited'
}
Expand Down Expand Up @@ -206,7 +207,15 @@
if ($launchFailure) {
$code = '0x{0:X8}' -f $launchFailure
$never = if ($code -eq '0x00041303') { 'the scheduler never launched it: ' } else { '' }
$hint = if ($code -eq '0x80070569' -or ($code -eq '0x00041303' -and $logon -eq 'Password')) {
$hint = if ($resolved -and $resolved.Name -like 'AzureAD\*' -and $logon -eq 'Password') {

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Placed before the generic clause, and keyed on the account rather than on the failure code, so an Entra account never receives the hint about the "Log on as a batch job" right: on the lab device granting the right changed nothing, and the hint would send someone the wrong way.

# On the lab device the right made no difference for an Entra account: the task
# sat Ready, "has not run yet", with the right granted (Findings, "The harness
# as another account")
" ($($never)a stored-password task did not start for a Microsoft Entra account " +
'on the lab device, with or without the "Log on as a batch job" right; sign the ' +
'account in and run while it holds a session)'
}
elseif ($code -eq '0x80070569' -or ($code -eq '0x00041303' -and $logon -eq 'Password')) {
" ($($never)the account is not granted the ""Log on as a batch job"" right a " +
'stored-password task needs; grant it in the local security policy, or run while the ' +
'account holds a session)'
Expand Down
5 changes: 3 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -254,8 +254,9 @@ simply never starts the task (`0x00041303`, "has not run yet", which is what the
today). Needs an elevated session. A Microsoft Entra account can be named by its sign-in name
(`user@domain`) or by the name Windows gives it: Windows calls such an account
`AzureAD\<display name without spaces, cut at 20 characters>`, which is neither the sign-in name nor
a part of it, so the launcher asks Windows which account the credential means and looks for its
session under that name. On
a part of it, so the launcher asks Windows which account the credential means and matches its
session by SID. A stored-password task did not start for such an account on the lab device, with
or without the batch logon right, so an Entra account has to hold a session. On
the lab device the interactive path reproduced the agent's launch point for point (console session,
`UserInteractive` true, the account's profile paths, system32; `Validation/Findings.md`, "The
harness as another account"). The script copy and its output live under `ProgramData\IntuneScriptLab\Runs` with the
Expand Down
39 changes: 39 additions & 0 deletions Tests/Unit/Private/Invoke-IslProcess.Tests.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -269,6 +269,45 @@ Describe 'Invoke-IslProcess' -Tag 'Unit', 'Private' {
}
}

It 'registers the stored-password task for an Entra account by its Windows name (VM 125)' {
# The scheduler refuses the sign-in name with "No mapping between account names and
# security IDs"; AzureAD\<Windows name> registers
Mock Resolve-IslAccount -ModuleName IntuneScriptLab {
[pscustomobject]@{
Name = 'AzureAD\IslVerylongdisplayna'
Sid = 'S-1-12-1-1497552185-1263987200-3276725654-805488699'
}
}
Mock Get-IslLogonSession -ModuleName IntuneScriptLab { @() }
$launchSplat = $script:LaunchSplat.Clone()
$signInName = 'isl-verylongusername-test01@4nlnm3.onmicrosoft.com'
$launchSplat.Credential = [pscredential]::new($signInName, $script:Credential.Password)
$result = Invoke-Process $launchSplat
$result.LogonType | Should-Be 'Password'
$result.UserName | Should-Be $signInName
Should-Invoke Register-ScheduledTask -ModuleName IntuneScriptLab -Exactly -Times 1 -ParameterFilter {
$User -eq 'AzureAD\IslVerylongdisplayna' -and $Password -eq 'pw' -and $null -eq $Principal
}
}

It 'says that a stored-password task does not start for an Entra account, right or no right (VM 125)' {
# With the account granted "Log on as a batch job" for the test, the task still sat
# Ready with 0x00041303, so the usual hint about the right would send someone the wrong way
Mock Resolve-IslAccount -ModuleName IntuneScriptLab {
[pscustomobject]@{ Name = 'AzureAD\IslVerylongdisplayna'; Sid = 'S-1-12-1-1-2-3-4' }
}
Mock Get-IslLogonSession -ModuleName IntuneScriptLab { @() }
Mock Start-ScheduledTask -ModuleName IntuneScriptLab { }
Mock Get-ScheduledTaskInfo -ModuleName IntuneScriptLab { [pscustomobject]@{ LastTaskResult = 267011 } }

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

267011 is 0x00041303, "the task has not run yet", as Get-ScheduledTaskInfo reports it: in decimal.

$launchSplat = $script:LaunchSplat.Clone()
$launchSplat.Credential = [pscredential]::new('someone@contoso.com', $script:Credential.Password)
$failure = { Invoke-Process $launchSplat } | Should-Throw
$failure.Exception.Message | Should-BeLikeString ('*someone@contoso.com did not start: 0x00041303 ' +
'(the scheduler never launched it: a stored-password task did not start for a Microsoft Entra ' +
'account*sign the account in and run while it holds a session)')
$failure.Exception.Message | Should-NotBeLikeString '*grant it in the local security policy*'
}

It 'does not take another account''s session for a sign-in name that only looks like it' {
# The part before the @ of one account can be the Windows name of another
Mock Resolve-IslAccount -ModuleName IntuneScriptLab {
Expand Down
10 changes: 10 additions & 0 deletions Validation/Findings.md
Original file line number Diff line number Diff line change
Expand Up @@ -403,6 +403,16 @@ SYSTEM the device listed one session, `AzureAD\IslVerylongdisplayna`,
script inside session 2 (`interactive=True`) and left no task or run folder behind. On a Windows
11 Home machine without `query.exe` the same list named its one console session.

The stored-password path for the same Entra account, signed out, `Register-ScheduledTask -User
<name> -Password <password>` with the account's real password: the sign-in name is refused at
registration ("No mapping between account names and security IDs was done"); `AzureAD\<sign-in
name>` and `AzureAD\IslVerylongdisplayna` register, and the task then sits Ready with
`0x00041303` ("has not run yet"), `LastRunTime` unset, as the local standard user's did. With the
account granted `SeBatchLogonRight` for the length of the test (`secedit`, the right taken away
again afterwards) the result was the same for both names. An Entra account on this device
therefore runs through the harness only while it holds a session; the launcher registers the task
for the Windows name and, for an Entra account, says so instead of pointing at the right.

### Reporting latency, re-measured (2026-09-29)

| Kind | Device (log line, converted to UTC) | Graph | Lag |
Expand Down
2 changes: 1 addition & 1 deletion docs/IntuneScriptLab/Invoke-IntuneDetectionTest.md
Original file line number Diff line number Diff line change
Expand Up @@ -115,7 +115,7 @@ HelpMessage: ''

### -Credential

Run as this account instead of the current user, with -Context User: a one-shot scheduled task registered for the account, interactive inside the account's own session when it holds one (the way the agent runs user-context scripts inside the signed-in user's session, REM-PROBE-USER64), otherwise a stored-password logon in session 0, which needs the account to hold the "Log on as a batch job" right (a standard user does not; the scheduler then never starts the task, and the launcher reports that within seconds rather than at the timeout); the result's RunAs says which. Needs an elevated session, and is refused with -Context System. A Microsoft Entra account can be named by its sign-in name (user@domain, with or without AzureAD\ in front) or by the name Windows gives it (AzureAD\Name, the display name without spaces, cut at 20 characters): the launcher asks Windows which account is meant and finds its session by the Windows name. Validation\New-IslHarnessUser.ps1 creates a lab account with a stored credential to use here.
Run as this account instead of the current user, with -Context User: a one-shot scheduled task registered for the account, interactive inside the account's own session when it holds one (the way the agent runs user-context scripts inside the signed-in user's session, REM-PROBE-USER64), otherwise a stored-password logon in session 0, which needs the account to hold the "Log on as a batch job" right (a standard user does not; the scheduler then never starts the task, and the launcher reports that within seconds rather than at the timeout); the result's RunAs says which. Needs an elevated session, and is refused with -Context System. A Microsoft Entra account can be named by its sign-in name (user@domain, with or without AzureAD\ in front) or by the name Windows gives it (AzureAD\Name, the display name without spaces, cut at 20 characters): the launcher asks Windows which account is meant and finds its session by the Windows name. A stored-password task did not start for a Microsoft Entra account on the lab device, with or without the batch logon right, so such an account has to hold a session. Validation\New-IslHarnessUser.ps1 creates a lab account with a stored credential to use here.

```yaml
Type: System.Management.Automation.PSCredential
Expand Down
2 changes: 1 addition & 1 deletion docs/IntuneScriptLab/Invoke-IntunePlatformScriptTest.md
Original file line number Diff line number Diff line change
Expand Up @@ -112,7 +112,7 @@ HelpMessage: ''

### -Credential

Run as this account instead of the current user, with -Context User: a one-shot scheduled task registered for the account, interactive inside the account's own session when it holds one (the way the agent runs user-context scripts inside the signed-in user's session, REM-PROBE-USER64), otherwise a stored-password logon in session 0, which needs the account to hold the "Log on as a batch job" right (a standard user does not; the scheduler then never starts the task, and the launcher reports that within seconds rather than at the timeout); the result's RunAs says which. Needs an elevated session, and is refused with -Context System. A Microsoft Entra account can be named by its sign-in name (user@domain, with or without AzureAD\ in front) or by the name Windows gives it (AzureAD\Name, the display name without spaces, cut at 20 characters): the launcher asks Windows which account is meant and finds its session by the Windows name. Validation\New-IslHarnessUser.ps1 creates a lab account with a stored credential to use here.
Run as this account instead of the current user, with -Context User: a one-shot scheduled task registered for the account, interactive inside the account's own session when it holds one (the way the agent runs user-context scripts inside the signed-in user's session, REM-PROBE-USER64), otherwise a stored-password logon in session 0, which needs the account to hold the "Log on as a batch job" right (a standard user does not; the scheduler then never starts the task, and the launcher reports that within seconds rather than at the timeout); the result's RunAs says which. Needs an elevated session, and is refused with -Context System. A Microsoft Entra account can be named by its sign-in name (user@domain, with or without AzureAD\ in front) or by the name Windows gives it (AzureAD\Name, the display name without spaces, cut at 20 characters): the launcher asks Windows which account is meant and finds its session by the Windows name. A stored-password task did not start for a Microsoft Entra account on the lab device, with or without the batch logon right, so such an account has to hold a session. Validation\New-IslHarnessUser.ps1 creates a lab account with a stored credential to use here.

```yaml
Type: System.Management.Automation.PSCredential
Expand Down
2 changes: 1 addition & 1 deletion docs/IntuneScriptLab/Invoke-IntuneRemediationTest.md
Original file line number Diff line number Diff line change
Expand Up @@ -129,7 +129,7 @@ HelpMessage: ''

### -Credential

Run as this account instead of the current user, with -Context User: a one-shot scheduled task registered for the account, interactive inside the account's own session when it holds one (the way the agent runs user-context scripts inside the signed-in user's session, REM-PROBE-USER64), otherwise a stored-password logon in session 0, which needs the account to hold the "Log on as a batch job" right (a standard user does not; the scheduler then never starts the task, and the launcher reports that within seconds rather than at the timeout); the result's RunAs says which. Needs an elevated session, and is refused with -Context System. A Microsoft Entra account can be named by its sign-in name (user@domain, with or without AzureAD\ in front) or by the name Windows gives it (AzureAD\Name, the display name without spaces, cut at 20 characters): the launcher asks Windows which account is meant and finds its session by the Windows name. Validation\New-IslHarnessUser.ps1 creates a lab account with a stored credential to use here.
Run as this account instead of the current user, with -Context User: a one-shot scheduled task registered for the account, interactive inside the account's own session when it holds one (the way the agent runs user-context scripts inside the signed-in user's session, REM-PROBE-USER64), otherwise a stored-password logon in session 0, which needs the account to hold the "Log on as a batch job" right (a standard user does not; the scheduler then never starts the task, and the launcher reports that within seconds rather than at the timeout); the result's RunAs says which. Needs an elevated session, and is refused with -Context System. A Microsoft Entra account can be named by its sign-in name (user@domain, with or without AzureAD\ in front) or by the name Windows gives it (AzureAD\Name, the display name without spaces, cut at 20 characters): the launcher asks Windows which account is meant and finds its session by the Windows name. A stored-password task did not start for a Microsoft Entra account on the lab device, with or without the batch logon right, so such an account has to hold a session. Validation\New-IslHarnessUser.ps1 creates a lab account with a stored credential to use here.

```yaml
Type: System.Management.Automation.PSCredential
Expand Down
2 changes: 1 addition & 1 deletion docs/IntuneScriptLab/Invoke-IntuneRequirementTest.md
Original file line number Diff line number Diff line change
Expand Up @@ -117,7 +117,7 @@ HelpMessage: ''

### -Credential

Run as this account instead of the current user, with -Context User: a one-shot scheduled task registered for the account, interactive inside the account's own session when it holds one (the way the agent runs user-context scripts inside the signed-in user's session, REM-PROBE-USER64), otherwise a stored-password logon in session 0, which needs the account to hold the "Log on as a batch job" right (a standard user does not; the scheduler then never starts the task, and the launcher reports that within seconds rather than at the timeout); the result's RunAs says which. Needs an elevated session, and is refused with -Context System. A Microsoft Entra account can be named by its sign-in name (user@domain, with or without AzureAD\ in front) or by the name Windows gives it (AzureAD\Name, the display name without spaces, cut at 20 characters): the launcher asks Windows which account is meant and finds its session by the Windows name. Validation\New-IslHarnessUser.ps1 creates a lab account with a stored credential to use here.
Run as this account instead of the current user, with -Context User: a one-shot scheduled task registered for the account, interactive inside the account's own session when it holds one (the way the agent runs user-context scripts inside the signed-in user's session, REM-PROBE-USER64), otherwise a stored-password logon in session 0, which needs the account to hold the "Log on as a batch job" right (a standard user does not; the scheduler then never starts the task, and the launcher reports that within seconds rather than at the timeout); the result's RunAs says which. Needs an elevated session, and is refused with -Context System. A Microsoft Entra account can be named by its sign-in name (user@domain, with or without AzureAD\ in front) or by the name Windows gives it (AzureAD\Name, the display name without spaces, cut at 20 characters): the launcher asks Windows which account is meant and finds its session by the Windows name. A stored-password task did not start for a Microsoft Entra account on the lab device, with or without the batch logon right, so such an account has to hold a session. Validation\New-IslHarnessUser.ps1 creates a lab account with a stored credential to use here.

```yaml
Type: System.Management.Automation.PSCredential
Expand Down
2 changes: 1 addition & 1 deletion docs/IntuneScriptLab/Invoke-IntuneWin32AppTest.md
Original file line number Diff line number Diff line change
Expand Up @@ -210,7 +210,7 @@ HelpMessage: ''

### -Credential

Run every launch (the detection script, the related apps' detections, the install or uninstall command) as this account instead of the current user, with -Context User: a one-shot scheduled task registered for the account, interactive inside the account's own session when it holds one (the way the agent runs user-context scripts inside the signed-in user's session, REM-PROBE-USER64), otherwise a stored-password logon in session 0, which needs the account to hold the "Log on as a batch job" right (a standard user does not; the scheduler then never starts the task, and the launcher reports that within seconds rather than at the timeout); the result's RunAs says which. Needs an elevated session, and is refused with -Context System. A Microsoft Entra account can be named by its sign-in name (user@domain, with or without AzureAD\ in front) or by the name Windows gives it (AzureAD\Name, the display name without spaces, cut at 20 characters): the launcher asks Windows which account is meant and finds its session by the Windows name. Validation\New-IslHarnessUser.ps1 creates a lab account with a stored credential to use here.
Run every launch (the detection script, the related apps' detections, the install or uninstall command) as this account instead of the current user, with -Context User: a one-shot scheduled task registered for the account, interactive inside the account's own session when it holds one (the way the agent runs user-context scripts inside the signed-in user's session, REM-PROBE-USER64), otherwise a stored-password logon in session 0, which needs the account to hold the "Log on as a batch job" right (a standard user does not; the scheduler then never starts the task, and the launcher reports that within seconds rather than at the timeout); the result's RunAs says which. Needs an elevated session, and is refused with -Context System. A Microsoft Entra account can be named by its sign-in name (user@domain, with or without AzureAD\ in front) or by the name Windows gives it (AzureAD\Name, the display name without spaces, cut at 20 characters): the launcher asks Windows which account is meant and finds its session by the Windows name. A stored-password task did not start for a Microsoft Entra account on the lab device, with or without the batch logon right, so such an account has to hold a session. Validation\New-IslHarnessUser.ps1 creates a lab account with a stored credential to use here.

```yaml
Type: System.Management.Automation.PSCredential
Expand Down
Loading
Loading