From 302aa02284817b590635428fa9605dfd8cf56a86 Mon Sep 17 00:00:00 2001 From: j0eyv <41282854+j0eyv@users.noreply.github.com> Date: Fri, 27 Mar 2026 10:50:59 +0100 Subject: [PATCH] Update README with error handling details Added information about Windows sign-in restore failure and policy CA205. --- README.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/README.md b/README.md index 1dd0974..a653101 100644 --- a/README.md +++ b/README.md @@ -433,6 +433,8 @@ This policy blocks agent identities with a high risk level from accessing resour 2. Error: Policy contains invalid applications: ServicePrincipalNotFound. Some ServicePrincipals might be missing in your tenant. You can manually create these by using `New-MgServicePrincipal -AppId *****-*****-******` | +3. Windows first sign-in restore fails with error _You can’t get there from here. This application contains sensitive information and can only be accessed from devices or client applications that meet management compliance policy._. This is blocked by policy CA205 (CA205-Internals-BaseProtection-AnyApp-Windows-CompliantorAADHJ). Add an exclusion for **Microsoft Activity Feed Service** (d32c68ad-72d2-4acb-a0c7-46bb2cf93873) in this policy. + ## Importing the baseline These PowerShell scripts are using Microsoft Authentication Library (MSAL), Microsoft Graph APIs and Azure Management APIs to manage objects in Intune and Azure. The scripts has a simple WPF UI and it supports operations like Export, Import, Copy, Download, Compare etc.