{"id":7911,"date":"2025-10-24T10:03:28","date_gmt":"2025-10-24T10:03:28","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/10\/24\/hp-oneagent-update-brokes-trust-and-disconnect-devices-from-entra-id\/"},"modified":"2025-10-24T10:03:28","modified_gmt":"2025-10-24T10:03:28","slug":"hp-oneagent-update-brokes-trust-and-disconnect-devices-from-entra-id","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/10\/24\/hp-oneagent-update-brokes-trust-and-disconnect-devices-from-entra-id\/","title":{"rendered":"HP OneAgent Update Brokes Trust And Disconnect Devices From Entra ID"},"content":{"rendered":"<p>    HP OneAgent Update Brokes Trust And Disconnect Devices From Entra ID<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The HP OneAgent software update has disconnected Windows devices from Microsoft Entra ID. As a result, users can no longer access their corporate identities.<\/p>\n<p>Version 1.2.50.9581 of the agent, pushed silently to HP\u2019s Next Gen AI systems like the EliteBook X Flip G1i, deleted critical certificates, causing devices to drop their Entra join status overnight. <\/p>\n<p>Reports surfaced last week when a wave of <a href=\"https:\/\/cybersecuritynews.com\/tag\/windows-11\/\" target=\"_blank\" rel=\"noreferrer noopener\">Windows 11<\/a> users faced login screens showing only local LAPS accounts, no Entra credentials in sight.<\/p>\n<p>Diagnostics via dsregcmd \/status confirmed the nightmare: the cloud trust was gone, devices isolated as if they\u2019d never been part of the organization\u2019s Azure ecosystem.<\/p>\n<p>Patch My PC observed that the issue zeroed in on HP\u2019s OneAgent, a telemetry and management tool that registers devices with HP\u2019s AWS IoT Core for automated updates.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-hp-oneagent-update-brokes-trust\"><strong>HP OneAgent Update Brokes Trust<\/strong><\/h2>\n<p>Affected systems had all received the update in the background, while non-AI HP models running older versions escaped unscathed. <\/p>\n<p>No other changes to <a href=\"https:\/\/cybersecuritynews.com\/microsoft-patches-wormable-rce-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Windows patches<\/a>, policies, or drivers were in play. Digging into the package revealed it bundled SoftPaq SP161710, which executed an install.cmd script meant to purge the obsolete HP 1E Performance Assist component.<\/p>\n<p>The script\u2019s PowerShell logic turned fatal. Aimed at removing 1E-related certificates, it broadly targeted any cert with \u201c1E\u201d in the subject, issuer, or friendly name.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgUl2ba2Xl09cCD7011AZZfnfRaQTDzGqNVBZwY1uc6qo0yutkdmJCkaNphX8qdD4dAHQhnOq34ccb6gT-klkmWIVZinSU9IEbo5edw8c4eb364qo1TcZ2f37v6dR-PMLcMaF1khx3D3oc8vX91SJ5ISr9LYXUrvvlrqVdpatJG4fERQp8wAL5aywwJ9MET\/s16000\/Broken%2520script.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">PowerShell commands that Brokes trust (Source: Patch My PC )<\/figcaption><\/figure>\n<p>This inadvertently nuked the MS-Organization-Access certificate, the cornerstone of Entra ID <a href=\"https:\/\/cybersecuritynews.com\/authentication\/\">authentication<\/a>, and in some cases, the Microsoft Intune MDM Device CA cert.<\/p>\n<p>Logs from HP OneAgent identified the cause: a \u201cjob-hponeagent-update\u201d command from HP\u2019s AWS IoT backend. This command downloaded and ran the package quickly, without proper testing, similar to the rushed approach seen in the CrowdStrike incident.<\/p>\n<p>HP swiftly yanked the faulty SoftPaq, halting further distribution, but impacted devices demanded hands-on repair.<\/p>\n<p>Locally, admins log in via LAPS, run a cleanup script to scrub stale Entra and Intune registry keys (under HKLM:SOFTWAREMicrosoftEnrollments and related paths), then reconnect via Settings &gt; Accounts. <\/p>\n<p>Remotely, <a href=\"https:\/\/cybersecuritynews.com\/tag\/microsoft-defender\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Defender<\/a> for Endpoint\u2019s Live Response enables uploading a PowerShell wipe script to trigger a device reset, assuming WinRE is enabled.<\/p>\n<p>This incident underscores OEM update risks on managed devices. HP OneAgent\u2019s silent, SYSTEM-level execution bypassed Intune oversight, turning routine maintenance into a trust-shattering event. <\/p>\n<p>While Intune might auto-recover MDM certs, losing MS-Organization-Access demands a full rejoin. Organizations should audit HP agents and enforce stricter update controls to prevent such quiet catastrophes.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/hp-oneagent-update-brokes-trust\/\">HP OneAgent Update Brokes Trust And Disconnect Devices From Entra ID<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/hp-oneagent-update-brokes-trust\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>HP OneAgent Update Brokes Trust And Disconnect Devices From Entra ID The HP OneAgent software update has disconnected Windows devices from Microsoft Entra ID. As a result, users can no longer access their corporate identities. Version 1.2.50.9581 of the agent, pushed silently to HP\u2019s Next Gen AI systems like the EliteBook X Flip G1i, deleted [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648],"tags":[130],"class_list":["post-7911","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7911"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7911"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7911\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7911"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7911"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7911"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}