Today we're going to start troubleshooting some common issues with device migration, mainly looking at the bulk primary refresh token and getting access to your destination tenant.
New Azure Service Principal cmd:
New-AzureADServicePrincipal -AccountEnabled $true -AppId 00000014-0000-0000-c000-000000000000 -AppRoleAssignmentRequired $False -DisplayName Microsoft.Azure.SyncFabric -Tags {WindowsAzureActiveDirectoryIntegratedApp}
Get-AzureADServicePrincipal | Where-Object {$_.AppId -eq "00000014-0000-0000-c000-000000000000"}
Join the official Discord server
/ discord
Read more at
https://www.getrubix.com
Chapters
0:00:00 I envy the garbage man
0:01:19 Issue 1: Getting the bulk refresh token
0:04:58 Issue 2: Entra join
0:06:03 Parsing the BPRT
0:09:00 Make a package users group
0:10:05 Exclude from Conditional Access
0:10:51 Add package users to automatic enrollment
0:11:26 We're getting there
#intune #autopilot #windows10 #windows11 #microsoftgraph #azureadministrator #azure #powershellscripting #powershell #activedirectory #bitlocker #windows365 #zerotrust #certificate #entra #microsoftdefender #zerotrust #mdm