๐ย Secure Bitsย ๐ก
๐จ๐ฝ๐ฑ๐ฎ๐๐ถ๐ป๐ด ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ฒ ๐๐ผ๐ผ๐ ๐ฐ๐ฒ๐ฟ๐๐ถ๐ณ๐ถ๐ฐ๐ฎ๐๐ฒ๐ ๐ผ๐ป ๐ช๐ถ๐ป๐ฑ๐ผ๐๐ ๐ฆ๐ฒ๐ฟ๐๐ฒ๐ฟ ๐ฐ๐ผ๐ป๐๐ถ๐ป๐๐ฒ๐ (๐ฑ๐ต. 3)
Last puzzle in this series isย ๐บ๐ผ๐ป๐ถ๐๐ผ๐ฟ๐ถ๐ป๐ด. Because as you can see, this process is ๐ป๐ผ๐ ๐๐ฟ๐ถ๐๐ถ๐ฎ๐น ๐ผ๐ฟ ๐๐๐ฟ๐ฎ๐ถ๐ด๐ต๐๐ณ๐ผ๐ฟ๐๐ฎ๐ฟ๐ฑ. Some devices will go through smoothly, others will hit different errors depending on firmware / platform / history โ and thatโs the worst case.
Thatโs why ๐บ๐ผ๐ป๐ถ๐๐ผ๐ฟ๐ถ๐ป๐ด ๐ถ๐ ๐ฐ๐ฟ๐๐ฐ๐ถ๐ฎ๐น: you need aย central viewย of where each device is in the process.
โธป
๐งญย ๐ ๐ผ๐ป๐ถ๐๐ผ๐ฟ๐ถ๐ป๐ด ๐ฎ๐ฝ๐ฝ๐ฟ๐ผ๐ฎ๐ฐ๐ต๐ฒ๐ย (pick what fits your environment):
๐น manual checks
๐น PowerShell checks
๐น startup script that uploads status to a file share
๐น scheduled tasks / inventory tooling
๐น โฆ
In my demo ๐ ๐๐๐ฒ๐ฑ ๐๐๐ผ ๐ฎ๐ฝ๐ฝ๐ฟ๐ผ๐ฎ๐ฐ๐ต๐ฒ๐: a PowerShell status collector from my friend Andrรฉ Estรชvรฃo (thanks!) – that is the first example, and Microsoftโs sample script that writes results to a file share + GPO – that is the second example. Your โbestโ option depends on how you manage servers and how you want to store/report results.
โธป
โ ย ๐ช๐ต๐ฎ๐ ๐๐ผ ๐๐ฟ๐ฎ๐ฐ๐ธ:
1๏ธโฃ ๐๐๐ฒ๐ป๐ ๐๐ผ๐ด (๐ฆ๐๐๐๐ฒ๐บ)
1808ย โ success / device is updated (certs applied to firmware)
1801ย โ not applied to firmware (still not updated / blocked)
1795ย โ firmware handoff error (platform/firmware problem)
There are more events, but in my tests these three were the ones I ran into most often.
2๏ธโฃ ๐ฅ๐ฒ๐ด๐ถ๐๐๐ฟ๐ ๐ธ๐ฒ๐๐
๐๐๐๐ _๐๐๐๐๐_๐๐๐๐๐๐๐๐๐ ๐๐๐๐๐๐ถ๐ณ๐ณ๐ฆ๐ฏ๐ต๐๐ฐ๐ฏ๐ต๐ณ๐ฐ๐ญ๐๐ฆ๐ต๐๐ฐ๐ฏ๐ต๐ณ๐ฐ๐ญ๐๐ฆ๐ค๐ถ๐ณ๐ฆ๐๐ฐ๐ฐ๐ต
๐น AvailableUpdates
0x0ย โ nothing being performed
0x5944ย โ deploy all needed certs + boot manager update (full rollout trigger)
๐๐๐๐ _๐๐๐๐๐_๐๐๐๐๐๐๐๐๐ ๐๐๐๐๐๐ถ๐ณ๐ณ๐ฆ๐ฏ๐ต๐๐ฐ๐ฏ๐ต๐ณ๐ฐ๐ญ๐๐ฆ๐ต๐๐ฐ๐ฏ๐ต๐ณ๐ฐ๐ญ๐๐ฆ๐ค๐ถ๐ณ๐ฆ๐๐ฐ๐ฐ๐ต๐๐ฆ๐ณ๐ท๐ช๐ค๐ช๐ฏ๐จ
๐น UEFICA2023Status
NotStartedย โ update hasnโt run
InProgressย โ update running / mid-flight
Updatedย โ update completed
๐น UEFICA2023Errorย โ error code (if any)
๐น UEFICA2023ErrorEventย โ event ID tied to the error
โธป
๐๐ฟ๐ผ๐ป๐ถ๐ฐ๐ฎ๐น๐น๐, I fought the most with monitoring onย ๐๐๐๐ฟ๐ฒ ๐ฉ๐ ๐ย in my demo โ I couldnโt get reliable signals that matched what the documentation suggests. Nothing initiated, nothing done, and the MS script didnโt help me explain why. If anyone has cracked that in a clean way, Iโd love to compare notes.
These are the ๐บ๐ผ๐๐ ๐ถ๐บ๐ฝ๐ผ๐ฟ๐๐ฎ๐ป๐ ๐ฝ๐น๐ฎ๐ฐ๐ฒ๐ to look for signals/status.
โธป
๐ย ๐ช๐ต๐ฎ๐โ๐ ๐ป๐ฒ๐ ๐
Next week Iโm going to merge all three parts into a singleย field notes documentย you can follow end-to-end.
But one more time: these posts areย ๐ป๐ผ๐ ๐ผ๐ณ๐ณ๐ถ๐ฐ๐ถ๐ฎ๐น ๐ด๐๐ถ๐ฑ๐ฒ๐ย โ just field notes from admins who had to go through it in real environments, so you can be better prepared.
