Forum Discussion
Cannot Reseal Windows 11 device while pre-provisioning
Using security baselines is great, but in my humble opinion split them up with your own policies… so you know what you are configuring on thise devices…
Enabling virtual based securitu with the sec baselines is almost 99% an issue with prepro..
But it also depends on the windows build as the wufb managebuild i mentioned was fixed and with win11 it was introduced again 🙂
last week I have opened a premier case at Microsoft. They engineer who is helping me could directly tell me that this is a know bug in Windows 11. He is also aware about a possible fix in the latest Windows 11 insider build and is trying to get a possible ETA for the fix so we will know when the issue is going te be resolved. As soon as I have a confirmation about the ETA, I will post it here.
- BHAug 17, 2022Brass Contributor
Another Update. Microsoft got back to me and are achiving my support ticket. This issue is under "High Level" investigation by MS Engineers and as soon as a solution is available, I will be notified. In the meanwhile there are no further troubleshooting options available and either I autopilot enroll windows 11 devices without pre-provisioning or go back to Windows 10. My query as to why this is not noted as an "outage" on the admin portal, was not answered.
- BHAug 15, 2022Brass Contributor
Update on this saga. I successfully resealed a couple of Windows 11 devices, but now the issue has returned - same thing - device reboots and does not return to reseal screen, Very weird.
Microsoft have notified me that they are still reviewing the diag logs I sent them.
What I dont understand is how come Microsoft have not announced a "Health notification - under investigation" on this issue as they usually do in ther service alerts. Are we in this forum the only few actually pre-provisioning Windows 11?
- Aug 15, 2022Wooop Wooop 🙂
- BHAug 15, 2022Brass Contributorbefore you install the image, You will need to mount your image file with Dism and then load the registry hive and take ownership of the permissions. Rudy has a very good step by step explanation in his blog: https://call4cloud.nl/2022/04/dont-be-a-menace-to-autopilot-while-configuring-your-wufb-in-the-hood/
- Petteri LaineAug 15, 2022Copper Contributor
Hi,
We are facing same problems.
How can you remove that regkey from the client machine?
When I'm opening regedit in client machine (before going to pre-provisioning) i cannot remove or edit anything under HKLM\Software\Microsoft\Provisioning\SyncML\RebootRequiredURIs
- Thilo LangbeinAug 15, 2022Iron ContributorToday I saw a bitlocker recovery on a Surface Latop 4 (AMD). There was a event id 4122: "The following DMA capable devices are not declared as protected from external acces,, which can block features such as BitLocker automatic drive encryption:..."
And only the Surfaces 4 (AMD) had the Pre Prov issues. - BHAug 15, 2022Brass Contributor
Rudy_Ooms_MVP I tested by removing the regkey ./Device/Vendor/MSFT/Policy/Config/DmaGuard/DeviceEnumerationPolicy and have succesfully arrived at reseal screen. Obviously this is not a full time solution, but an easy workaround. I have updated my Microsoft Case # with this information. Thank you for your blog on that.
- Aug 14, 2022Nope we dont, but it helps to give them as much information as possible…
- Thilo LangbeinAug 14, 2022Iron ContributorMsft has to solve the issue. Not we as Customers. 🫤
- Aug 14, 2022Hehe i am not saying “all users” just a test group with your test user in it :)… if you know what is causing it, the informstion you could share with ms is better
- BHAug 14, 2022Brass ContributorI have not tried that as this is testing on production environment. Changing wufb to "all Users" is probably not a good idea. I will test it on my test lab when I have a chance - was hoping that Microsoft would provide a "fix" before I got to that
- Aug 14, 2022And when assinging that config to users instead of devices?
- BHAug 14, 2022Brass ContributorHaving the same issue with Windows 11 (Currently using latest Windows 11 release 21h2.9) Windows 10 on same device gets to reseal screen. I have tried all options mentioned except for key delete. ./Device/Vendor/MSFT/Policy/Config/DmaGuard/DeviceEnumerationPolicy . I will test that shortly. I do have an open ticket with MS Support, still waiting on them to offer some suggestion. Really dont want to have to go back to deploying Windows 10.
- Aug 12, 2022Most of the times you could resolve this issue by changing the assignment to users instead of devices.. just the same as with WUFB targetted at devices... it caused a reboot back in the win 11 days that would give you a nice login screen with no ability to login ;)...
The same goes for device config profiles that could trigger such weird behavior..,. - RonaldBe21Aug 12, 2022Copper Contributor
The cause of this issue is not very clear te me. At one customer I had this issue and changed all the assignments (including security baselines and update ring policy) from "all devices" to a device group instead. But this didn't work when I tested at another customer.
One test I did there is to remove all the configuration profiles en security baselines, including the update ring policy. So nothing was applied to the device but still I did not get the reseal button.
On other forums I also see that people are having different results. Maybe this could be when testing with different update levels of Windows, I am not sure.
So the only thing I can be sure of is that Microsoft told me it is a know bug and they are working on it. I can not get with 100% certainty a configuration which will always work. Microsoft also told me that they cannot provide me with a workarround, because they just don't have one.
They also told me that removing the mentioned register key(s) also do not work (always) as expected so that is also not a good workarround.
I guess we can only wait to make sure that the issue is resolved by Microsoft. I will not advice to use Pre-Provisioning with Windows 11 for now, because I cannot find a working (workarround) solution which I am sure it will keep working and not have to worry that it stops working with different conditions.
I also tested with a colleague and we did have just good results with the latest insider build of Windows 11. Not something to use in a production environment for our customers, but at least we have good fate that Microsoft will be able to help us soon.
As mentioned before, as soon as I get a confirmed ETA for the fix from Microsoft, I will let you all know.
- jebuzAug 11, 2022Copper ContributorFor me it is a security baseline conflict with Autopilot pre-provisioning, DMA-Guard specifically.
- Thilo LangbeinAug 11, 2022Iron ContributorWe're affected too.
Is it really a general bug in Win 11? Or has it to do with config policies/baselines? - jebuzAug 11, 2022Copper ContributorThanks for the info Ronald, hoping Microsoft will provide a ETA for releasing the fix asap.
- RonaldBe21Aug 10, 2022Copper ContributorThe bug is related to Windows 11 en Pre-provisioning and that the reseal button will not appear.
- Aug 10, 2022Hi,
Could you share the information about which bug exactly? to be sure we are talking about the same issue 🙂