{"id":23470,"date":"2022-02-26T00:20:00","date_gmt":"2022-02-25T23:20:00","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=23470"},"modified":"2022-02-26T00:33:31","modified_gmt":"2022-02-25T23:33:31","slug":"windows-10-20h2-january-2022-updates-breaks-agpm-server","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2022\/02\/26\/windows-10-20h2-january-2022-updates-breaks-agpm-server\/","title":{"rendered":"Windows 10 20H2: January 2022 Updates breaks AGPM-Server"},"content":{"rendered":"<p><img decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" title=\"Windows\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2021\/04\/Windows-klein.jpg\" alt=\"Windows\" width=\"200\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2022\/01\/21\/windows-10-20h2-zerschiet-das-jan-2022-update-den-agpm-server\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]Microsoft's fix for vulnerability CVE-2022-21920 may block NTLM authentication if Kerberos authentication is not successful. A German blog reader has notified me in January 2022 about issues with <em>Advanced Group Policy Management<\/em> (<em>AGPM<\/em>). After installing January 2022 security updates , there are problems to reach the AGPM server. Microsoft has now confirmed these issues and a workaround is possible.<\/p>\n<p><!--more--><\/p>\n<h2>Issues with AGPM Server<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg04.met.vgwort.de\/na\/76050a779fe84a85b82b414562534441\" alt=\"\" width=\"1\" height=\"1\" \/>Austrian blog reader Markus K. uses AGPM in a larger network environment in a university. He has already emailed me as of 1\/23\/2022 about a problem he posted on the patchmanagement.org mailing list under the title <em><a href=\"https:\/\/groups.google.com\/g\/patchmanagement\/c\/ATPmv-fS6lY\/m\/83TOOKYXAwAJ?pli=1\" target=\"_blank\" rel=\"noopener\">AGPM client fails to connect with 2022-01 CU<\/a><\/em>. There he wrote:<\/p>\n<blockquote><p>Dear all,<\/p>\n<p>just a heads up cause it might concern you.<\/p>\n<p>We have a 20H2 machine with an AGPM client installed.<br \/>\nAfter installing 2022-01 CU the connection to the AGPM server failed.<br \/>\nAfter uninstalling the patch the connection to the server works again.<br \/>\nThe 2019 server has the 2022-01 CU installed though.<\/p>\n<p>The error on the clients log:<br \/>\n2022-01-13 10:21:23:1869726 [pid=8016,tid=3] [Error] Error in AgpmClient.Reconnect() System.ServiceModel.Security.SecurityNegotiationException: Either the target name is incorrect or the server has rejected the client credentials. \u2014&gt; System.Security.Authentication.InvalidCredentialException: Either the target name is incorrect or the server has rejected the client credentials. \u2014&gt; System.ComponentModel.Win32Exception: The logon attempt failed<br \/>\n\u2014 End of inner exception stack trace \u2014<br \/>\nat System.Net.Security.NegoState.ProcessAuthentication(LazyAsyncResult lazyResult)<br \/>\nat System.Net.Security.NegotiateStream.AuthenticateAsClient(NetworkCredential credential, String targetName, ProtectionLevel requiredProtectionLevel, TokenImpersonationLevel allowedImpersonationLevel)<br \/>\nat System.ServiceModel.Channels.WindowsStreamSecurityUpgradeProvider.WindowsStreamSecurityUpgradeInitiator.OnInitiateUpgrade(Stream stream, SecurityMessageProperty&amp; remoteSecurity)<br \/>\n\u2014 End of inner exception stack trace \u2014<\/p>\n<p>Seems the patch breaks the auth process. Not much we can do except waiting for a fix I guess.<\/p><\/blockquote>\n<p>However, in the discussion it turned out that hardly anyone on the list uses AGPM and others are not affected either. Markus was able to provoke this issue on a freshly installed Windows 10 20H2 client in a virtual machine.<\/p>\n<p><a href=\"https:\/\/i.imgur.com\/DKr7MCp.png\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/i.imgur.com\/DKr7MCp.png\" width=\"633\" height=\"297\" \/><\/a><\/p>\n<h2>What is AGPM?<\/h2>\n<p>AGPM stands for Microsoft's <em>Advanced Group Policy Management<\/em>. According to <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-desktop-optimization-pack\/agpm\/\">this Microsoft document<\/a>, Microsoft Advanced Group Policy Management (AGPM) extends the capabilities of the Group Policy Management Console (GPMC). It will provide comprehensive change control and improved management for Group Policy Objects (GPOs). AGPM is available as part of the Microsoft Desktop Optimization Pack (MDOP) for Software Assurance. There are several versions available.<\/p>\n<h2>Microsoft's explanation<\/h2>\n<p>Blog reader Markus K. emailed me again on February 25, 2022 and wrote:<\/p>\n<blockquote><p>Hello,<\/p>\n<p>Problem solved myself, because the ticket at MS is a farce.<br \/>\nA few people on the NTSysadmin list should also be happy about this, as they are also affected.<\/p>\n<p>We had entered the IP of the AGPM server. Split-DNS therefore delivers a FQDN outside the domain. Kerberos does not work then of course, so fallback to NTLM.<\/p><\/blockquote>\n<p>Microsoft released an update on January 11, 2022 to close the vulnerability <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-21920\" target=\"_blank\" rel=\"noopener\">CVE-2022-21920<\/a>, which triggered the above effect. Markus K. pointed me to the Microsoft support article <a href=\"https:\/\/support.microsoft.com\/en-us\/topic\/kb5011233-protections-in-cve-2022-21920-may-block-ntlm-authentication-if-kerberos-authentication-is-not-successful-dd415f99-a30c-4664-ba37-83d33fb071f4\" target=\"_blank\" rel=\"noopener\">KB5011233: Protections in CVE-2022-21920 may block NTLM authentication if Kerberos authentication is not successful<\/a>, where this is discussed. According to the support article, it affects all supported Windows versions.<\/p>\n<p>Windows Server 2008<br \/>\nWindows 7 Service Pack 1<br \/>\nWindows Server 2008 R2 Service Pack 1<br \/>\nWindows Server 2012<br \/>\nWindows 8.1 Windows Server 2012 R2<br \/>\nWindows 10 Windows 10, version 1607,<br \/>\nall editions Windows 10, version 1809,<br \/>\nall editions Windows Server 2016<br \/>\nWindows 10, version 1909,<br \/>\nall editions Windows Server 2019<br \/>\nWindows 10, version 20H2,<br \/>\nall editions Windows 10, version 21H1,<br \/>\nall editions Windows 10, version 21H2,<br \/>\nall editions Windows 11 Windows Server 2022<\/p>\n<p>Markus wrote: <em>If you replace the IP with the correct FQDN of the domain, everything works again. <\/em>Perhaps this is helpful for some affected administrators.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Microsoft's fix for vulnerability CVE-2022-21920 may block NTLM authentication if Kerberos authentication is not successful. A German blog reader has notified me in January 2022 about issues with Advanced Group Policy Management (AGPM). After installing January 2022 security updates , &hellip; <a href=\"https:\/\/borncity.com\/win\/2022\/02\/26\/windows-10-20h2-january-2022-updates-breaks-agpm-server\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[463,22,2],"tags":[166,195,194],"class_list":["post-23470","post","type-post","status-publish","format-standard","hentry","category-issue","category-update","category-windows","tag-issues","tag-update","tag-windows"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/23470","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=23470"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/23470\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=23470"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=23470"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=23470"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}