A faulty cleanup script in HP OneAgent 1.2.50.9581 deleted the MS-Organization-Access certificate, disconnecting devices from Entra ID.

A faulty HP OneAgent update (version 1.2.50.9581) silently deleted Microsoft Entra ID certificates on HP’s AI-enabled devices, breaking cloud authentication for affected organizations[1]. The issue stemmed from a cleanup script in package SP161710 that indiscriminately removed certificates containing “1E” in their identifiers, inadvertently deleting critical MS-Organization-Access certificates needed for Entra ID authentication[1:1].

The problem specifically affected HP’s Next Gen AI models like the EliteBook X Flip G1i, with the update pushed through HP’s AWS IoT backend without proper testing[1:2]. While HP has pulled the problematic update, affected devices require manual intervention - either logging in with local admin credentials to rejoin Entra ID or using Microsoft Defender’s Live Response for remote fixes[1:3][2].

According to HP, “The update is no longer available and will not affect more AI PCs. We’re investigating the issue and working closely with impacted customers on mitigation”[3].


  1. PatchMyPC - HP OneAgent Update Broke Entra Trust on HP AI Devices ↩︎ ↩︎ ↩︎ ↩︎

  2. CyberSecurityNews - HP OneAgent Update Brokes Trust And Disconnect Devices From Entra ID ↩︎

  3. BleepingComputer - HP pulls update that broke Microsoft Entra ID auth on some AI PCs ↩︎

Create a post

This is the official technology community of Lemmy.ml for all news related to creation and use of technology, and to facilitate civil, meaningful discussion around it.


Ask in DM before posting product reviews or ads. All such posts otherwise are subject to removal.


Rules:

1: All Lemmy rules apply

2: Do not post low effort posts

3: NEVER post naziped*gore stuff

4: Always post article URLs or their archived version URLs as sources, NOT screenshots. Help the blind users.

5: personal rants of Big Tech CEOs like Elon Musk are unwelcome (does not include posts about their companies affecting wide range of people)

6: no advertisement posts unless verified as legitimate and non-exploitative/non-consumerist

7: crypto related posts, unless essential, are disallowed

  • 1 user online
  • 34 users / day
  • 86 users / week
  • 332 users / month
  • 1.48K users / 6 months
  • 1 subscriber
  • 4.29K Posts
  • 49.3K Comments
  • Modlog