Sonos app cannot find Sonos speaker when PC is Intune Managed on Domain Network

MKinOZ 31 Reputation points
2022-07-04T05:24:46.67+00:00

Hi,

we are about to roll out Intune on our devices.

We have the small but annoying problem that as soon as a Windows PC has been enrolled, the Sonos app stops finding/ communicating with the Speaker ("Sorry, we can't connect to Sonos.").
Our PCs are all on the Domain Network via Ethernet, so is the Sonos speaker.
The strange thing is, that if I take an enrolled PC to my home, where I have a range of Sonos speakers, the Sonos app can find those speakers.
The home networks is set as "Private" network. The domain network is set as "Domain" network.

In Intune, we have the Microsoft Defender for Endpoint Baseline applied.

Any ideas?

thanks
Jonas

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,746 questions
0 comments No comments
{count} votes

4 answers

Sort by: Most helpful
  1. Crystal-MSFT 43,996 Reputation points Microsoft Vendor
    2022-07-04T08:54:10.147+00:00

    @MKinOZ , From your description, it seems when the Intune managed device is in Domain Network, the Sonos speaker is failed to find. But in Private network, it is working. If there's any misunderstanding, feel free to let us know.

    To clarify our issue, please help to do the following tests:

    1. In the domain network, find a device which is not enrolled into Intune and check if the Sonos speaker can be found.
    2. Try to enroll one device without applying the Microsoft Defender for Endpoint Baseline to see if it works on it.

    Please try the above tests and if there's any update, feel free to let us know.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  2. MKinOZ 31 Reputation points
    2022-07-05T02:59:09.723+00:00

    Thanks @Crystal-MSFT , correct.

    I have added a machine and will report back when this is done.


  3. MKinOZ 31 Reputation points
    2022-07-06T00:29:16.167+00:00

    HI @Crystal-MSFT ,

    the machine has been enrolled and Sonos is now not working anymore. I have blocked onboarding of Defender for Endpoint, so it is just some policies that have been applied. I have narrowed it down to my "Endpoint Protection policy for Windows 10 devices", which was acting from before I considered going with Defender for Endpoint.

    I will probable remove this policy as it will be handled by the Defender for endpoint. However, I will still need to understand the base issue.

    I have the following settings in that policy:

    Attack Surface Reduction:
    Flag credential stealing from the Windows local security authority subsystem - Enable
    Process creation from Adobe Reader (beta) - Enable
    Office apps injecting into other processes (no exceptions) - Block
    Office apps/macros creating executable content - Block
    Office apps launching child processes - Block
    Win32 imports from Office macro code - Block
    Process creation from Office communication products (beta) - Enable
    Obfuscated js/vbs/ps/macro code - Block
    js/vbs executing payload downloaded from Internet (no exceptions) - Block
    Process creation from PSExec and WMI commands - Block
    Untrusted and unsigned processes that run from USB - Block
    Executables that don’t meet a prevalence, age, or trusted list criteria - Audit only
    Execution of executable content (exe, dll, ps, js, vbs, etc.) dropped from email (webmail/mail client) (no exceptions) - Block
    Advanced ransomware protection - Enable

    I have now added an exception for the Sonos app to try out.

    Network filtering:
    Network protection - Enable -> I now changed to Audit

    Any ideas what setting could cause the issue?


  4. MKinOZ 31 Reputation points
    2022-07-08T01:22:05.213+00:00

    @Crystal-MSFT I have been working on this, but have not yet had any success. I changed all to AUDIT, but this has not made a difference. So I took the machine off all configuration profiles, but I think this does then not change the settings on the machine. ¯(°_o)/¯