Share via

Baseline blocks settings

andreas bright 581 Reputation points
2020-12-15T14:14:29.097+00:00

Hi,

We are testing Endpoint Manager, and we have applied MS Windows 10 Security Baseline for some test users. Now suddenly they have problems with some applications, and we believe it is related to some settings in the Baseline.

Problem 1:
The application works as follow… we use MS chrome and connect to a website where we login. Here we have a published application (I guess from a MS terminal server) and this application starts just fine. We edit some “documents” in this application, and then we want to save a copy. The save as windows appear and we can see our own local disk, and we can browse to this one, but we cannot save to it. So I guess some RDP settings are blocked.

Problem 2:
We connect to an application with Remote Desktop App from Microsoft and that works just fine, but when we try to print it does not work. We don’t get any error messages, and the printer is mapped correctly in the application at the other end, but it’s not coming through correctly. If we check the printer que, we can see the jobs “Remote Desktop Redirected Printer Doc” status error.

We don’t have access to the other end, so we cannot check the Terminal servers log files. And this was working before these test clients implemented Endpoint Manager. Any suggestions ? ... or could it be bitlocker policy ?

The Json file can be found here https://filebin.net/ajvdn4hyn0vcivjq

Thanks for answers.

/R
Andy

Microsoft Security | Intune | Configuration
Microsoft Security | Intune | Other
0 comments No comments

3 answers

Sort by: Most helpful
  1. andreas bright 581 Reputation points
    2020-12-16T05:41:50.247+00:00

    Hi,

    Thanks for reply, the Block drive redirection setting we have disabled but that didn't help, we do get the mapping, so its not that setting.
    I was hoping that someone have had the same problem, so they knew exactly which setting that is causing this.... but I guess we will just have to use the one-by-one elimination method.

    /R
    Andy

    Was this answer helpful?


  2. Crystal-MSFT 54,311 Reputation points Microsoft External Staff
    2020-12-16T01:40:55.397+00:00

    @andreas bright , Agree with Nick, to know which setting can be affected. We can prepare a test machine, create a group and assign this policy to this group. Then try to remove the setting one by one to find out what is the affected one.

    Hope it can help.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    Was this answer helpful?

    0 comments No comments

  3. NickH 3,526 Reputation points Volunteer Moderator
    2020-12-15T20:34:03.127+00:00

    Have you tried creating a new profile (Security Baseline) and assigning it to an Azure AD Group that contains 1 test device, and modifying the Security Baseline Settings? For example under Remote Desktop Services the Block drive redirection setting could cause some issues. I haven't tested the exact setting, but you could change the settings and see which one it is.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.